# How to parse this format of log

**URL:** <https://discuss.elastic.co/t/how-to-parse-this-format-of-log/188865>\
**Category:** Logstash\
**Created:** [July 4, 2019, 8:59am UTC](https://discuss.elastic.co/t/how-to-parse-this-format-of-log/188865 "2019-07-04T08:59:04Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![deepanshu\_goel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/deepanshu_goel/32/48061_2.png) [@deepanshu\_goel](https://discuss.elastic.co/u/deepanshu_goel)\
**Post date:** [July 4, 2019, 8:59am UTC](https://discuss.elastic.co/t/how-to-parse-this-format-of-log/188865/1 "2019-07-04T08:59:04Z")

</div>

LOG WHICH I AM TRYIING TO PARSE:-  
2019-07-03 17:04:58.562 DELETE accept UDP 10.133.189.203:56897 -\> 233.79.64.194:654 678.133.200.279:56131 -\> 23.64.33.898:555 0 0  
**The grok pattern which i am trying to use:-**

filter {  
grok { match =\> { "message" =\> "%{WORD:abc} %{WORD:xyz} %{WORD:proto} %{IPV4:ip1}:%{INT:port1} -\> %{IPV4:ip2}:%{INT:port2} %{IPV4:ip3}:%{INT:port3} -\> %{IPV4:ip4}:%{INT:port4} %{INT:byte} %{INT:byte}$"}}  
date { match =\> ["[@metadata][ts]", "YYYY-MM-dd HH:mm:ss" ] }  
}  
Please,help me as I am a new in this field.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 4, 2019, 1:45pm UTC](https://discuss.elastic.co/t/how-to-parse-this-format-of-log/188865/2 "2019-07-04T13:45:36Z")

</div>

IPV4 will only match against valid IP address. For example, that grok pattern will match against

```
2019-07-03 17:04:58.562 DELETE accept UDP 10.133.189.203:56897 -> 233.79.64.194:654 78.133.200.179:56131 -> 23.64.33.198:555 0 0
```

---

<div class="post-metadata">

**Author:** ![deepanshu\_goel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/deepanshu_goel/32/48061_2.png) [@deepanshu\_goel](https://discuss.elastic.co/u/deepanshu_goel)\
**Post date:** [July 7, 2019, 5:37pm UTC](https://discuss.elastic.co/t/how-to-parse-this-format-of-log/188865/3 "2019-07-07T17:37:32Z")

</div>

Even if i use "IP" instead of "IPV4" there is an error coming which indicates the parsing is not taking place . What could be the possible reason for that.  
**Now the code i am using is :-**

filter {  
grok { match =\> { "message" =\> "%(DATESTAMP:datestamp) %{WORD:Event} %{WORD:Xevent} %{WORD:protocol} %{IP:ip1}:%{INT:port1} -\> %{IP:ip2}:%{INT:port2} %{IP:ip3}:%{INT:port3} -\> %{IP:ip4}:%{INT:port4} %{INT:Inbyte} %{INT:Outbyte}$"}}  
}  
{I EVEN TRIED CHANGING IPV4 TO IP but it DIDN'T WORK OUT }

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 7, 2019, 6:00pm UTC](https://discuss.elastic.co/t/how-to-parse-this-format-of-log/188865/4 "2019-07-07T18:00:36Z")

</div>

You haven't show us what your data looks like, so we cannot help parse it.

---

<div class="post-metadata">

**Author:** ![deepanshu\_goel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/deepanshu_goel/32/48061_2.png) [@deepanshu\_goel](https://discuss.elastic.co/u/deepanshu_goel)\
**Post date:** [July 8, 2019, 5:36am UTC](https://discuss.elastic.co/t/how-to-parse-this-format-of-log/188865/5 "2019-07-08T05:36:38Z")

</div>

I have given a log sample in the question asked :-  
**LOG WHICH I AM TRYIING TO PARSE:-**  
**2019-07-03 17:04:58.562 DELETE accept UDP 10.133.189.203:56897 -\> 233.79.64.194:654 678.133.200.279:56131 -\> 23.64.33.898:555 0 0**

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 8, 2019, 1:33pm UTC](https://discuss.elastic.co/t/how-to-parse-this-format-of-log/188865/6 "2019-07-08T13:33:54Z")

</div>

> [@deepanshu\_goel](#):
>
> 678.133.200.279

That is not a valid IP address, so neither IP nor IPV4 will match it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 5, 2019, 1:33pm UTC](https://discuss.elastic.co/t/how-to-parse-this-format-of-log/188865/7 "2019-08-05T13:33:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
