# How to repeat grok-Part n-times

**URL:** <https://discuss.elastic.co/t/how-to-repeat-grok-part-n-times/44497>\
**Category:** Logstash\
**Created:** [March 15, 2016, 10:46pm UTC](https://discuss.elastic.co/t/how-to-repeat-grok-part-n-times/44497 "2016-03-15T22:46:43Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jupp](https://avatars.discourse-cdn.com/v4/letter/j/e36b37/32.png) [@jupp](https://discuss.elastic.co/u/jupp)\
**Post date:** [March 15, 2016, 10:46pm UTC](https://discuss.elastic.co/t/how-to-repeat-grok-part-n-times/44497/1 "2016-03-15T22:46:43Z")

</div>

Hello Community !

I try to parse following:

```
-- New Customer ---------
time customerData1
time customerData2
time date id: 1
time Service: a
time OnlineRequest
time OnlineResponse
time text
time [Status] Code: Text
time date id: 2
time Service: b
time text
time text 
time text
time text
time [Status] Code: Text
....
time date id: n
time Service: xyz
time text
time text 
time text
time text
time [Status] Code: Text
time customerData4
time customerData5

-- New Customer ---------
...

```

into something like this

```
{
   "customerData1":"value",
   "customerData2":"value",
   "customerData3":"value",
   "customerData4":"value",
   "services":[
    {
      "id":"value",
      "name":"value"
      "onlineRequest":"value",
      "onlineResponse":"value",
      "text":"value",
      "statuscode":"value",
      "statustext":"value"
    },
   {
      "id":"value",
      "name":"value"
     ..
   }
  ]
}

```

Therefore i sent all Lines of a Customer (-- New Customer --- .... ) delimited with "\n" to logstash as one event.

But how can i parse the Servicepart n times with the same grok pattern?  
I thought about using the grok-filter for the customerData, then use the split-filter on the whole message an then the aggregate-filter for the service-part, but i know that the aggregate-filter can only be used with one filterworker....that would be a performancekiller.

Is there a good way to repeat a grok-pattern n-times or how can i solve my problem?

Hope someone can help 🙂

Jupp

---

<div class="post-metadata">

**Author:** ![fbaligand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fbaligand/32/5657_2.png) [@fbaligand](https://discuss.elastic.co/u/fbaligand)\
**Post date:** [April 24, 2016, 9:45pm UTC](https://discuss.elastic.co/t/how-to-repeat-grok-part-n-times/44497/2 "2016-04-24T21:45:37Z")

</div>

I understand you don't like the idea of using a single worker thread.  
Maybe you could do the job using 'ruby' filter. But I think code would be a little bit complicated...

Up to me, the only easy solution is to use aggregate filter.  
And I think it would be more efficient and simple to use aggregate filter for each customer line.  
But that's only my opinion 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:00am UTC](https://discuss.elastic.co/t/how-to-repeat-grok-part-n-times/44497/3 "2017-07-06T05:00:54Z")

</div>


