# It is possible to create multiple groks for multiple paths?

**URL:** <https://discuss.elastic.co/t/it-is-possible-to-create-multiple-groks-for-multiple-paths/87530>\
**Category:** Logstash\
**Created:** [May 30, 2017, 9:09am UTC](https://discuss.elastic.co/t/it-is-possible-to-create-multiple-groks-for-multiple-paths/87530 "2017-05-30T09:09:01Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tabs11](https://avatars.discourse-cdn.com/v4/letter/t/c0e974/32.png) [@tabs11](https://discuss.elastic.co/u/tabs11)\
**Post date:** [May 30, 2017, 9:09am UTC](https://discuss.elastic.co/t/it-is-possible-to-create-multiple-groks-for-multiple-paths/87530/1 "2017-05-30T09:09:01Z")

</div>

I mean, define two paths, which the files (csv or log) in one path have 9 columns and in other path the files have 11 columns, then apply two different groks, one for the file with 9 columns and other for the file with 11 columns...All in the same configuration file of course.

I tried two apply a grok file to both, getting parse failures (of course), so, in that case, i applied an if statement and build a new grok to it. It almost works, except the confusion with columns names. In the example a tried two different file (9 and 11 columns, in the same path, in this case). For convenience the files only have 1 row. Here it is:

input {  
file {  
path =\> "/data/Logs/csvfiles/allcols/_.csv"  
start\_position =\> "beginning"  
sincedb\_path =\> "/dev/null"  
}  
}  
filter {  
grok {  
match =\> {"message" =\> "^(?[^;]+);(?[^;]_);(?[^;]_);(?[^;]_);(?\<x\_7\>[^;]_);(?\<x\_8\>[^;]_);(?\<x\_9\>[^;]_);(?\<x\_10\>[^;]_);(?\<response\_time\>[^;]_)"  
}  
}  
if "\_grokparsefailure" in [tags] {  
grok {  
match =\> {"message" =\> "^(?[^;]_);(?[^;]_);(?[^;]_);(?[^;]_);(?[^;]_);(?[^;]_);(?\<x\_7\>[^;]_);(?\<x\_8\>[^;]_);(?\<x\_9\>[^;]_);(?\<x\_10\>[^;]_);(?\<response\_time\>[^;]_)"  
}  
}  
}  
ruby{  
code =\> "  
event.set('date', event.get('date')[0..-2])  
"  
}  
ruby {  
code =\> "  
event.set('filename', event.get('path').split('/').last)  
event.set('app\_name', event.get('filename').split('_')[1])  
event.set('host', event.get('filename').split('_').first)  
"  
}  
mutate {  
remove\_field =\> ["filename"]  
convert =\> {  
"x\_10" =\> "float"  
"response\_time" =\> "float"  
}  
}  
date {  
match =\> ["date", "yyyy-MM-dd HH:mm:ss.SSS"]  
timezone =\> "UTC"  
target =\> "date"  
}  
}  
output {  
elasticsearch {  
hosts =\> ["localhost"]  
index =\> "csv9and11-%{+YYYY-MM-dd}"  
}  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![Sylfaen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sylfaen/32/17653_2.png) [@Sylfaen](https://discuss.elastic.co/u/Sylfaen)\
**Post date:** [May 30, 2017, 9:21am UTC](https://discuss.elastic.co/t/it-is-possible-to-create-multiple-groks-for-multiple-paths/87530/2 "2017-05-30T09:21:58Z")

</div>

Yes, of course. Multiple grok is possible ([discuss](https://discuss.elastic.co/t/multiple-match-option-in-grok/83590/7)).

In your case, as the columns are the same for the 9 first ones, you can make one simple grok and adding a conditional statement :

> ^(?[^;]);(?[^;]);(?[^;]);(?[^;]);(?[^;]);(?[^;]);(?[^;]);(?[^;]);(?[^;])**(**;(?[^;]);(?[^;]\*)**)?**

Adding **()?** allows you to say that the part between () isn't always available.

---

<div class="post-metadata">

**Author:** ![tabs11](https://avatars.discourse-cdn.com/v4/letter/t/c0e974/32.png) [@tabs11](https://discuss.elastic.co/u/tabs11)\
**Post date:** [May 30, 2017, 9:48am UTC](https://discuss.elastic.co/t/it-is-possible-to-create-multiple-groks-for-multiple-paths/87530/3 "2017-05-30T09:48:17Z")

</div>

well, it seems to work. When the simple things solve the problems. 🙂 Thank you very much

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2017, 9:48am UTC](https://discuss.elastic.co/t/it-is-possible-to-create-multiple-groks-for-multiple-paths/87530/4 "2017-06-27T09:48:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
