# Including space / multiple entries with GROK

**URL:** <https://discuss.elastic.co/t/including-space-multiple-entries-with-grok/195217>\
**Category:** Logstash\
**Created:** [August 14, 2019, 2:16pm UTC](https://discuss.elastic.co/t/including-space-multiple-entries-with-grok/195217 "2019-08-14T14:16:17Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![cjb312](https://avatars.discourse-cdn.com/v4/letter/c/b5ac83/32.png) [@cjb312](https://discuss.elastic.co/u/cjb312)\
**Post date:** [August 14, 2019, 2:16pm UTC](https://discuss.elastic.co/t/including-space-multiple-entries-with-grok/195217/1 "2019-08-14T14:16:17Z")

</div>

So I'm using GROK to clean up some log files into Kibana but there's a couple areas im struggling with. How can get the value of to a field?:  
X-FORWARDED-FOR -\> (ip address)

Also I have another instance of multiple emails that all belong to a single field like so:  
[123@gmail.com](mailto:123@gmail.com), [antoherEmail@gmail.com](mailto:antoherEmail@gmail.com), etc

I've tried a few solutions but im fairly new to this and am very stuck. Is there perhaps a way to limit how much data greedydata gets?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 14, 2019, 3:39pm UTC](https://discuss.elastic.co/t/including-space-multiple-entries-with-grok/195217/2 "2019-08-14T15:39:55Z")

</div>

What do the log lines you want to extract data from look like and what data do you want to extract?

---

<div class="post-metadata">

**Author:** ![cjb312](https://avatars.discourse-cdn.com/v4/letter/c/b5ac83/32.png) [@cjb312](https://discuss.elastic.co/u/cjb312)\
**Post date:** [August 14, 2019, 3:58pm UTC](https://discuss.elastic.co/t/including-space-multiple-entries-with-grok/195217/3 "2019-08-14T15:58:41Z")

</div>

```
timestampHere	uidHere	IPhere	anotherIP X	X	X	x	/	-	-	0	0	-	-	-	-	-	(empty)	-	-	X-FORWARDED-FOR -> ipHere	-	-	-	-	-	-	-

```

Sorry I have to kind of censor the data I'm working with.

So each entry belongs to a field. My specific problem is getting the X-FORWARDED-FOR -\> ipHere all to a single field because the space. If I use greedydata i get that plus all the hyphens which are for other fields that i do not want.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 14, 2019, 4:25pm UTC](https://discuss.elastic.co/t/including-space-multiple-entries-with-grok/195217/4 "2019-08-14T16:25:10Z")

</div>

I get the feeling you are trying to match the whole line, but there is no need to do that. There are no implicit anchors in grok. If the [message] field of your event contains

```
blah blah blah X-FORWARDED-FOR -> 127.3.6.9 more stuff

```

then you can extract the IP address using

```
grok { match => { "message" => "X-FORWARDED-FOR -> %{IPV4:ip}" } }
```

---

<div class="post-metadata">

**Author:** ![cjb312](https://avatars.discourse-cdn.com/v4/letter/c/b5ac83/32.png) [@cjb312](https://discuss.elastic.co/u/cjb312)\
**Post date:** [August 14, 2019, 4:45pm UTC](https://discuss.elastic.co/t/including-space-multiple-entries-with-grok/195217/5 "2019-08-14T16:45:34Z")

</div>

Huh I didn't know you could do it like that. I've been using this format and couldn't find a way to do it in terms of this way.  
%{NUMBER:ts}%{SPACE}%{WORD:uid}%{SPACE}%{IP:orig\_h}%{SPACE}%{NUMBER:orig\_p}%{SPACE}%{IP:resp\_h}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 11, 2019, 4:45pm UTC](https://discuss.elastic.co/t/including-space-multiple-entries-with-grok/195217/6 "2019-09-11T16:45:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
