# How To parse Multiline Message With Grok

**URL:** <https://discuss.elastic.co/t/how-to-parse-multiline-message-with-grok/276500>\
**Category:** Logstash\
**Created:** [June 21, 2021, 8:03am UTC](https://discuss.elastic.co/t/how-to-parse-multiline-message-with-grok/276500 "2021-06-21T08:03:40Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![ankitdevnalkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitdevnalkar/32/46158_2.png) [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Post date:** [June 21, 2021, 8:03am UTC](https://discuss.elastic.co/t/how-to-parse-multiline-message-with-grok/276500/1 "2021-06-21T08:03:40Z")

</div>

I am working with AWS Cloudwatchs' GuardDuty finding events, I am getting GuardDuty event in the following format :

`"message": "\n\"AWS MY_ACCOUNTID has a severity 2 GuardDuty finding type Recon:EC2/PortProbeUnprotectedPort in the ap-south-1 region.\"\n\"Finding Description:\"\n\"EC2 instance has an unprotected port which is being probed by a known malicious host.. \"\n\"For more details open the GuardDuty console at HTTPS://GUARDDUTY_FINDING_URL`

I have written Grok parser as follows :

`(?m).*AWS %{NUMBER:accountId} .*severity %{NUMBER:severity} .*GuardDuty finding type %{NOTSPACE:findingType} .*in the %{NOTSPACE:region}`

**Problem statement :** I would like to parse the entire second line(EC2 instance has an unprotected port which is being probed by a known malicious host..) in a single field. I tried with `.*EC2 %{GREEDYDATA: Interpretation}` but it parses the rest of the whole message. It should parse till `\"\n"\`.

---

<div class="post-metadata">

**Author:** ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)\
**Post date:** [June 21, 2021, 8:52am UTC](https://discuss.elastic.co/t/how-to-parse-multiline-message-with-grok/276500/2 "2021-06-21T08:52:28Z")

</div>

Hi,

I assume the log you give to us is from the stdout rubydebug so i will consider that they look like this in input :

```auto
"AWS MY_ACCOUNTID has a severity 2 GuardDuty finding type Recon:EC2/PortProbeUnprotectedPort in the ap-south-1 region."
"Finding Description:"
"EC2 instance has an unprotected port which is being probed by a known malicious host.. "
"For more details open the GuardDuty console at HTTPS://GUARDDUTY_FINDING_URL

```

In grok you have a pattern name QUOTEDSTRING to take all the values between quotes.  
So you can use it to take an entire line

Cad.

---

<div class="post-metadata">

**Author:** ![ankitdevnalkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitdevnalkar/32/46158_2.png) [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Post date:** [June 21, 2021, 9:29am UTC](https://discuss.elastic.co/t/how-to-parse-multiline-message-with-grok/276500/3 "2021-06-21T09:29:20Z")

</div>

> [@Cad](#):
>
> I assume the log you give to us is from the stdout rubydebug so i will consider that they look like this in input :
> 
> ```auto
> 
> ```

Thanks for reply @Cad , Yes that is correct, I gave it from the stdout rubydebug.

I tried with` (?m).*AWS %{NUMBER:accountId} .*severity %{NUMBER:severity} .*GuardDuty finding type %{NOTSPACE:findingType} .*in the %{NOTSPACE:region} %{QUOTEDSTRING:Interpretation}`

But it is not working !

---

<div class="post-metadata">

**Author:** ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)\
**Post date:** [June 21, 2021, 9:46am UTC](https://discuss.elastic.co/t/how-to-parse-multiline-message-with-grok/276500/4 "2021-06-21T09:46:55Z")

</div>

You can't put the pattern for `Interpretation` after the pattern `region` with a space between. Replace the space with `.*`

```auto
(?m).*AWS %{NUMBER:accountId} .*severity %{NUMBER:severity} .*GuardDuty finding type %{NOTSPACE:findingType} .*in the %{NOTSPACE:region}.*%{QUOTEDSTRING:finding}[\n]%{QUOTEDSTRING:Interpretation}[\n]%{QUOTEDSTRING:details}

```

Cad.

---

<div class="post-metadata">

**Author:** ![ankitdevnalkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitdevnalkar/32/46158_2.png) [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Post date:** [June 21, 2021, 10:22am UTC](https://discuss.elastic.co/t/how-to-parse-multiline-message-with-grok/276500/5 "2021-06-21T10:22:03Z")

</div>

hey @Cad that worked !!  
Just one more question , now parsed data coming like :  
`"EC2 instance has an unprotected port which is being probed by a known malicious host.. "` **Note : along with quotas**

But I saw it is showing in stdout rubydebug as following:  
`"\"EC2 instance has an unprotected port which is being probed by a known malicious host.. \""`

Now, to remove the quotas do I required to replace `"` and `\` or just replacing `"` will be ok. You can assume I would replace quotas after data gets parsed.

---

<div class="post-metadata">

**Author:** ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)\
**Post date:** [June 21, 2021, 10:44am UTC](https://discuss.elastic.co/t/how-to-parse-multiline-message-with-grok/276500/6 "2021-06-21T10:44:47Z")

</div>

You just have to replace the `"`. The `\` is here just to show that the quote is a part of the string.  
You can use the gsub option of the mutate filter to replace character.

---

<div class="post-metadata">

**Author:** ![ankitdevnalkar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankitdevnalkar/32/46158_2.png) [@ankitdevnalkar](https://discuss.elastic.co/u/ankitdevnalkar)\
**Post date:** [June 21, 2021, 10:47am UTC](https://discuss.elastic.co/t/how-to-parse-multiline-message-with-grok/276500/7 "2021-06-21T10:47:09Z")

</div>

Thanks @Cad ! it was very helpful ! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 19, 2021, 10:47am UTC](https://discuss.elastic.co/t/how-to-parse-multiline-message-with-grok/276500/8 "2021-07-19T10:47:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
