As you say, multiple groks will work. Multiple match will never work, because one match overwrites the other in the final configuration of the filter.
You can get multiple field to work by adding 'break_on_match => false'. The default behaviour is for grok to work through the list until one pattern matches and then stop.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.