# How to set start and end point of a prebuild grok pattern

**URL:** <https://discuss.elastic.co/t/how-to-set-start-and-end-point-of-a-prebuild-grok-pattern/311749>\
**Category:** Logstash\
**Created:** [August 9, 2022, 2:38pm UTC](https://discuss.elastic.co/t/how-to-set-start-and-end-point-of-a-prebuild-grok-pattern/311749 "2022-08-09T14:38:40Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![cihady](https://avatars.discourse-cdn.com/v4/letter/c/8797f3/32.png) [@cihady](https://discuss.elastic.co/u/cihady)\
**Post date:** [August 9, 2022, 2:38pm UTC](https://discuss.elastic.co/t/how-to-set-start-and-end-point-of-a-prebuild-grok-pattern/311749/1 "2022-08-09T14:38:40Z")

</div>

My grok patter broken when there is a |(pipe) in my data .  
here is my log

`> 16:29:52.143 [kafka-producer-network-thread | producer-1] INFO c.h.h.d.e.ApiMessageProducer - ==========================================================================================================`

and Here is My grok pattern

`%{TIME:timestamp}\s%{DATA:thread}\s+%{DATA:log_level}\s+%{DATA:classs_path}\s+\-`

when there is a pipe in my thread, pattern is broken and log level is become "|" rest of my pattern is miss printed so I want to escape |(pipe) in thread if there is one.

Also if there is a empty character in thread part also same thing happens, so how can I say that thread starts with [and ends with] characters

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [August 9, 2022, 3:10pm UTC](https://discuss.elastic.co/t/how-to-set-start-and-end-point-of-a-prebuild-grok-pattern/311749/2 "2022-08-09T15:10:03Z")

</div>

Think you are looking for this.

```auto
%{TIME:timestamp}\s\[%{DATA:thread}\]\s+%{DATA:log_level}\s+%{DATA:classs_path}\s+\-

```

Which gives you this.

```auto
{
  "classs_path": "c.h.h.d.e.ApiMessageProducer",
  "log_level": "INFO",
  "thread": "kafka-producer-network-thread | producer-1",
  "timestamp": "16:29:52.143"
}

```

---

<div class="post-metadata">

**Author:** ![cihady](https://avatars.discourse-cdn.com/v4/letter/c/8797f3/32.png) [@cihady](https://discuss.elastic.co/u/cihady)\
**Post date:** [August 9, 2022, 6:27pm UTC](https://discuss.elastic.co/t/how-to-set-start-and-end-point-of-a-prebuild-grok-pattern/311749/3 "2022-08-09T18:27:21Z")

</div>

I tried exact same and it was giving errors now it is working :).  
that solves my problem thanks.  
In any case how can I escape pipe character in this %{DATA:thread}  
assume pipe is in the middle of text and I want to escape it.

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [August 9, 2022, 6:41pm UTC](https://discuss.elastic.co/t/how-to-set-start-and-end-point-of-a-prebuild-grok-pattern/311749/4 "2022-08-09T18:41:36Z")

</div>

What do you mean by escape it? Using a `\` before a special character will escape it but not sure we are talking about the same thing because that character is in a field.

---

<div class="post-metadata">

**Author:** ![cihady](https://avatars.discourse-cdn.com/v4/letter/c/8797f3/32.png) [@cihady](https://discuss.elastic.co/u/cihady)\
**Post date:** [August 9, 2022, 7:27pm UTC](https://discuss.elastic.co/t/how-to-set-start-and-end-point-of-a-prebuild-grok-pattern/311749/5 "2022-08-09T19:27:37Z")

</div>

can we do something like if exist delete not continue

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [August 9, 2022, 7:57pm UTC](https://discuss.elastic.co/t/how-to-set-start-and-end-point-of-a-prebuild-grok-pattern/311749/6 "2022-08-09T19:57:54Z")

</div>

Still not sure I understand completely. If you are looking to drop the field `thread` if it contains a `|` then I would do the below.

```auto
input {
  generator {
      lines => ['{"thread" :"kafka-producer-network-thread | producer-1"}']
      codec => json
      count => 1
  }
}
filter {
  if "|" in [thread] {
    mutate { remove_field => "thread" }
  }
}
output {
  stdout { codec => json_lines }
}

```

---

<div class="post-metadata">

**Author:** ![cihady](https://avatars.discourse-cdn.com/v4/letter/c/8797f3/32.png) [@cihady](https://discuss.elastic.co/u/cihady)\
**Post date:** [August 9, 2022, 8:43pm UTC](https://discuss.elastic.co/t/how-to-set-start-and-end-point-of-a-prebuild-grok-pattern/311749/7 "2022-08-09T20:43:59Z")

</div>

thank you it is not that much important,

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 6, 2022, 8:44pm UTC](https://discuss.elastic.co/t/how-to-set-start-and-end-point-of-a-prebuild-grok-pattern/311749/8 "2022-09-06T20:44:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
