# How to parse log file with different types of messages

**URL:** <https://discuss.elastic.co/t/how-to-parse-log-file-with-different-types-of-messages/54910>\
**Category:** Logstash\
**Created:** [July 7, 2016, 7:39am UTC](https://discuss.elastic.co/t/how-to-parse-log-file-with-different-types-of-messages/54910 "2016-07-07T07:39:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kennedy\_Kan1](https://avatars.discourse-cdn.com/v4/letter/k/cc9497/32.png) [@Kennedy\_Kan1](https://discuss.elastic.co/u/Kennedy_Kan1)\
**Post date:** [July 7, 2016, 7:39am UTC](https://discuss.elastic.co/t/how-to-parse-log-file-with-different-types-of-messages/54910/1 "2016-07-07T07:39:34Z")

</div>

Hi everyone,

I have a log file which contains complicated message types. Here is an example:

```
2016-07-07 13:30:02 [UnzipFile] Before file collection
2016-07-07 13:30:02 [GetZipCol] Start get sorted zip file collection
2016-07-07 13:30:02 [GetZipCol] ProcessDate: 2016-07-07
2016-07-07 13:30:02 [GetZipCol] End get sorted zip file collection
2016-07-07 13:30:02 [Main] [ERROR] No unzip file

```

The following grok pattern is only suitable for first 4 lines but not last line.

```
grok{
	match => {"message" => ['%{Date:Date}%{SPACE}%{Time:Time}%{SPACE}%{WORD:Job}%{SPACE}%{GREEDYDATA:Message}']}
    	}

```

I would like to know how should I modify the grok pattern as to capture`[ERROR]` from the last message. Is there anyone know how the way to do this?

Thanks.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 7, 2016, 8:16am UTC](https://discuss.elastic.co/t/how-to-parse-log-file-with-different-types-of-messages/54910/2 "2016-07-07T08:16:35Z")

</div>

I'm surprised that WORD works for matching `[UnzipFile]`. Assuming you don't really want the square brackets in your fields, this untested example removes them and supports the optional `[ERROR]`:

```
%{Date:Date}%{SPACE}%{Time:Time}%{SPACE}\[%{WORD:Job}\](%{SPACE}\[%{WORD:whatever}\])?%{SPACE}%{GREEDYDATA:Message}

```

The key here is `(...)?` for making a group of tokens optional.

You can also list multiple grok expressions in the same filter and Logstash will try them all in order and break when it gets a match. There's an example of this in the documentation.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:49am UTC](https://discuss.elastic.co/t/how-to-parse-log-file-with-different-types-of-messages/54910/5 "2017-07-06T04:49:01Z")

</div>


