# How to parse single log file with multiple grok pattern

**URL:** <https://discuss.elastic.co/t/how-to-parse-single-log-file-with-multiple-grok-pattern/83053>\
**Category:** Logstash\
**Created:** [April 20, 2017, 12:28pm UTC](https://discuss.elastic.co/t/how-to-parse-single-log-file-with-multiple-grok-pattern/83053 "2017-04-20T12:28:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dbElastic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dbelastic/32/46548_2.png) [@dbElastic](https://discuss.elastic.co/u/dbElastic)\
**Post date:** [April 20, 2017, 12:28pm UTC](https://discuss.elastic.co/t/how-to-parse-single-log-file-with-multiple-grok-pattern/83053/1 "2017-04-20T12:28:45Z")

</div>

Hello,  
I am trying to parse a single log file with multiple grok pattern as below:

grok {  
break\_on\_match =\> false  
match =\> {"message" =\> ["%{TIMESTAMP\_ISO8601:timestamp\_match}%{SPACE}[%{SPACE}%{WORD:number}]%{SPACE}[[^[]]_]%{SPACE}[%{SPACE}%{WORD:demo\_no}]%{SPACE}[%{WORD:log\_level}]%{SPACE}[%{WORD:info}]", "%{TIMESTAMP\_ISO8601:timestamp\_match}%{SPACE}[%{SPACE}%{WORD:number}]%{SPACE}[[^[]]_]%{SPACE}[%{SPACE}%{WORD:demo\_no}]%{SPACE}[%{WORD:log\_level}]%{SPACE}[%{WORD:soap\_type}]%{SPACE}[%{WORD:info}]"  
]  
}

MY logs look like below:

+++ [AAANG] +++++++++++++++++++++++++++++++++++++++++  
2017-04-26 07:59:44,884 [3] [bc9d7002-775f-40ed-8322-a2e3e5rrr66e] [demo3] [DEBUG] [SoapRequest] [PW.Infrastructure.Web.Services.SoapLogExtension.WriteOutput]  
2017-04-26 07:59:44,888 [3] [bc9d7002-775f-40ed-8322-a2e3e5rrr66e] [demo3] [DEBUG] [\<?xml version="1.0" encoding="utf-8"?\>\<soap:Envelope xmlns:soap="[http://schemas.xmlsoap.org/soap/envelope/](http://schemas.xmlsoap.org/soap/envelope/)" xmlns:xsi="[http://www.w3.org/2001/XMLSchema-instance](http://www.w3.org/2001/XMLSchema-instance)" xmlns:xsd="[http://www.w3.org/2001/XMLSchema](http://www.w3.org/2001/XMLSchema)"\>soap:BodyeeeWWWW\</soap:Body\>\</soap:Envelope\>] [PW.Infrastructure.Web.Services.SoapLogExtension.WriteOutput]  
2017-04-26 07:59:45,039 [3] [bc9d7002-775f-40ed-8322-a2e3e5rrr66e] [demo3] [DEBUG] [SoapResponse] [PW.Infrastructure.Web.Services.SoapLogExtension.WriteInput]

Can u please point out what is wrong?

---

<div class="post-metadata">

**Author:** ![Nico-DF](https://avatars.discourse-cdn.com/v4/letter/n/ed8c4c/32.png) [@Nico-DF](https://discuss.elastic.co/u/Nico-DF)\
**Post date:** [May 4, 2017, 7:12am UTC](https://discuss.elastic.co/t/how-to-parse-single-log-file-with-multiple-grok-pattern/83053/2 "2017-05-04T07:12:21Z")

</div>

I don't exactly know, but I can at least tell you that if in your log you have a bracket, brace, etc., you need to escape it in your pattern:

> [%{SPACE}%{WORD:number}]  
> shall become  
> \[%{SPACE}%{WORD:number}\]

And test your pattern with [http://grokdebug.herokuapp.com/](http://grokdebug.herokuapp.com/) for exemple.  
If your pattern is correct, I think it might be OK (are you sure about break\_on\_match =\> false?)

---

<div class="post-metadata">

**Author:** ![dbElastic](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dbelastic/32/46548_2.png) [@dbElastic](https://discuss.elastic.co/u/dbElastic)\
**Post date:** [May 4, 2017, 8:28am UTC](https://discuss.elastic.co/t/how-to-parse-single-log-file-with-multiple-grok-pattern/83053/3 "2017-05-04T08:28:16Z")

</div>

I do not know why these back slashes disappeared while i posted this query but they look like below:

 ![](https://us1.discourse-cdn.com/elastic/original/3X/b/e/be6f5da5d3784923103d1dd5f289f98283af4b70.png)

I read about break\_on\_match from Grok Filter Reference document.

I need to write two patterns as the log file content are diferent for alternate line. ☹

---

<div class="post-metadata">

**Author:** ![Nico-DF](https://avatars.discourse-cdn.com/v4/letter/n/ed8c4c/32.png) [@Nico-DF](https://discuss.elastic.co/u/Nico-DF)\
**Post date:** [May 4, 2017, 11:49am UTC](https://discuss.elastic.co/t/how-to-parse-single-log-file-with-multiple-grok-pattern/83053/4 "2017-05-04T11:49:38Z")

</div>

If you're sure that both your patterns are correct, you can try to split them in two groks by doing:

```auto
if "SUCCESS" not in [tags]{
  grok {
    match => { "message" => PATTERN1}
    add_tag => ["SUCCESS"]
    remove_tag => ["_grokparsefailure"]
  }
}

if "SUCCESS" not in [tags]{
  grok {
    match => { "message" => PATTERN2}
    add_tag => ["SUCCESS"]
    remove_tag => ["_grokparsefailure"]
  }
}

```

If it does not work with this: your pattern is wrong somewhere  
If it works: keep it or continue to look for the correct way to have multiple pattern in one grok

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 1, 2017, 12:02pm UTC](https://discuss.elastic.co/t/how-to-parse-single-log-file-with-multiple-grok-pattern/83053/5 "2017-06-01T12:02:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
