# Learning grok filter

**URL:** <https://discuss.elastic.co/t/learning-grok-filter/98670>\
**Category:** Logstash\
**Created:** [August 29, 2017, 10:40am UTC](https://discuss.elastic.co/t/learning-grok-filter/98670 "2017-08-29T10:40:00Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Xopp](https://avatars.discourse-cdn.com/v4/letter/x/ed655f/32.png) [@Xopp](https://discuss.elastic.co/u/Xopp)\
**Post date:** [August 29, 2017, 10:40am UTC](https://discuss.elastic.co/t/learning-grok-filter/98670/1 "2017-08-29T10:40:00Z")

</div>

Hi everyone, im newbie with Elastic Stack  
Following to [https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/) i can create very simple grok filter like  
2017-08-28T04:34:32.651Z ABC 123123 671 =\> %{TIMESTAMP\_ISO8601} %{WORD} %{NUMBER} %{NUMBER}  
But when i have some different kinh of log message i cant filter by my own.  
Like [2017-08-28T04:34:32.651Z][ABC][123123] 671 or many kind.  
So my question is how can i understand correctly all the syntax in Grok debugger patterns.  
I have read but not understand all of it  
Thanks

---

<div class="post-metadata">

**Author:** ![Xopp](https://avatars.discourse-cdn.com/v4/letter/x/ed655f/32.png) [@Xopp](https://discuss.elastic.co/u/Xopp)\
**Post date:** [August 30, 2017, 1:32am UTC](https://discuss.elastic.co/t/learning-grok-filter/98670/2 "2017-08-30T01:32:46Z")

</div>

Can anyone help me  
Thanks!!!!

---

<div class="post-metadata">

**Author:** ![bhatch](https://avatars.discourse-cdn.com/v4/letter/b/e95f7d/32.png) [@bhatch](https://discuss.elastic.co/u/bhatch)\
**Post date:** [August 30, 2017, 3:51pm UTC](https://discuss.elastic.co/t/learning-grok-filter/98670/3 "2017-08-30T15:51:54Z")

</div>

That is a bit of an open ended question. Are you familiar with regex? GROK is basically just a simpler way of using prebuilt regex statements. You can see the full patterns [here](https://github.com/elastic/logstash/blob/v1.4.2/patterns/grok-patterns).

The biggest thing I learned with Grok is that you are not required to have every single field be a GROK pattern.  
So look at this log line here.  
`Web01 collected 5 events`

You can use a grok pattern like this:  
`^%{WORD:serverName} collected %{INT:numberOfEvents} events$`  
This will then give you results of  
`{"serverName":"Web01","numberOfEvents":5}`  
Notice that I used a combination of standard text, grok patterns and regular regex. GROK basically just replaces the grok pattern with the corresponding regex pattern. Any part of the text that isn't explicitly named just gets ignored.

So taking that knowledge lets apply it to your test data above. Lets use this grok statement.  
`^\[%{TIMESTAMP_ISO8601:timestamp}\]\[%{WORD:word1}\]\[%{INT:number1}\] %{INT:number2}$`  
This gives a result of:  
`{"timestamp":"2017-08-28T04:34:32.651Z","word1":"ABC","number1":123123,"number2":671}`

Notice that I had to escape the brackets as brackets are a special character in REGEX.

I personally like this site for testing patterns.  
[http://grokconstructor.appspot.com/do/match](http://grokconstructor.appspot.com/do/match)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/d/2d545cacb0f7c0a633a2fdb37a7668e51f9b83ad.png)  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/8/584f7c4584f86b50e7de917b88b798bac2a768bf.png)

---

<div class="post-metadata">

**Author:** ![Xopp](https://avatars.discourse-cdn.com/v4/letter/x/ed655f/32.png) [@Xopp](https://discuss.elastic.co/u/Xopp)\
**Post date:** [August 31, 2017, 2:18am UTC](https://discuss.elastic.co/t/learning-grok-filter/98670/4 "2017-08-31T02:18:02Z")

</div>

Hi @bhatch  
Thank for reply.  
I dont know the regex, that why i cant understand the grok filter.  
Now i can create my own, Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 28, 2017, 2:18am UTC](https://discuss.elastic.co/t/learning-grok-filter/98670/5 "2017-09-28T02:18:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
