# How to match multiple field,use multiple field or multiple match or multiple grok

**URL:** <https://discuss.elastic.co/t/how-to-match-multiple-field-use-multiple-field-or-multiple-match-or-multiple-grok/164875>\
**Category:** Logstash\
**Created:** [January 19, 2019, 3:35am UTC](https://discuss.elastic.co/t/how-to-match-multiple-field-use-multiple-field-or-multiple-match-or-multiple-grok/164875 "2019-01-19T03:35:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![hjfeng1988](https://avatars.discourse-cdn.com/v4/letter/h/df788c/32.png) [@hjfeng1988](https://discuss.elastic.co/u/hjfeng1988)\
**Post date:** [January 19, 2019, 3:35am UTC](https://discuss.elastic.co/t/how-to-match-multiple-field-use-multiple-field-or-multiple-match-or-multiple-grok/164875/1 "2019-01-19T03:35:07Z")

</div>

Logs file to analyze:

> GET /login.html?user=hjfeng1988 HTTP/1.1

multiple field

```auto
filter {
  grok {
    match => {
      "message" => ["%{WORD:method} %{DATA:request_uri} HTTP/%{NUMBER:http_version}"]
      "request_uri" => ["%{DATA:uri}\?.*"]
    }
  }
}

```

multiple match

```auto
filter {
  grok {
    match => {
      "message" => ["%{WORD:method} %{DATA:request_uri} HTTP/%{NUMBER:http_version}"]
    }
    match => {
      "request_uri" => ["%{DATA:uri}\?.*"]
    }
  }
}

```

multiple grok

```auto
filter {
  grok {
    match => {
      "message" => ["%{WORD:method} %{DATA:request_uri} HTTP/%{NUMBER:http_version}"]
    }
  }
  grok {
    match => {
      "request_uri" => ["%{DATA:uri}\?.*"]
    }
  }
}

```

I try it only use multiple grok work in my case.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 19, 2019, 12:58pm UTC](https://discuss.elastic.co/t/how-to-match-multiple-field-use-multiple-field-or-multiple-match-or-multiple-grok/164875/2 "2019-01-19T12:58:28Z")

</div>

As you say, multiple groks will work. Multiple match will never work, because one match overwrites the other in the final configuration of the filter.

You can get multiple field to work by adding 'break\_on\_match =\> false'. The default behaviour is for grok to work through the list until one pattern matches and then stop.

---

<div class="post-metadata">

**Author:** ![hjfeng1988](https://avatars.discourse-cdn.com/v4/letter/h/df788c/32.png) [@hjfeng1988](https://discuss.elastic.co/u/hjfeng1988)\
**Post date:** [January 21, 2019, 2:13am UTC](https://discuss.elastic.co/t/how-to-match-multiple-field-use-multiple-field-or-multiple-match-or-multiple-grok/164875/3 "2019-01-21T02:13:02Z")

</div>

Thank you very much  
Another problem that I try few ways to get both `request_uri` and `uri`,But alway fail.  
Logs file to analyze:

> GET /login.html?user=hjfeng1988 HTTP/1.1  
> GET /login.html HTTP/1.1

When I use this method,it can't get correct value `uri`.

```auto
filter {
  grok {
    match => {
      "message" => ["%{WORD:method} %{DATA:request_uri} HTTP/%{NUMBER:http_version}"]
      "request_uri" => ["%{DATA:uri}(\?.*)?"]
    }
    break_on_match => false
    remove_field => ["message"]
  }
}

```

And this method it will replace `?` to `,` for field `request_uri`

```auto
filter {
  grok {
    match => {
      "message" => ["%{WORD:method} %{DATA:request_uri} HTTP/%{NUMBER:http_version}"]
    }
    remove_field => ["message"]
  }
  mutate {
    split => { "request_uri" => "?" }
    add_field => { "uri" => "%{request_uri[0]}" }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 18, 2019, 2:13am UTC](https://discuss.elastic.co/t/how-to-match-multiple-field-use-multiple-field-or-multiple-match-or-multiple-grok/164875/4 "2019-02-18T02:13:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
