# Logstash basic grok field types description

**URL:** <https://discuss.elastic.co/t/logstash-basic-grok-field-types-description/109690>\
**Category:** Logstash\
**Created:** [November 30, 2017, 6:24am UTC](https://discuss.elastic.co/t/logstash-basic-grok-field-types-description/109690 "2017-11-30T06:24:34Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticheart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticheart/32/65189_2.png) [@elasticheart](https://discuss.elastic.co/u/elasticheart)\
**Post date:** [November 30, 2017, 6:24am UTC](https://discuss.elastic.co/t/logstash-basic-grok-field-types-description/109690/1 "2017-11-30T06:24:34Z")

</div>

Hi,

From [this link](https://github.com/elastic/logstash/blob/v1.4.0/patterns/grok-patterns), we can have a reference at the different types supported in Logstash grok pattern. I am listing down some basic types in it;

1. USERNAME
2. USER
3. INT
4. BASE10NUM
5. NUMBER
6. BASE16NUM
7. BASE16FLOAT
8. POSINT
9. NONNEGINT
10. WORD
11. NOTSPACE
12. SPACE
13. DATA
14. GREEDYDATA
15. QUOTEDSTRING
16. UUID

from the website, it is not so easy for a beginner person to choose the correct type to use with grok in Logstash. A small description about when and where to use it will be much helpful. It will be great if one can provide an example string/data too. its really confusing sometimes whether to pick `WORD` or `SPACE`, `DATA` or `GREEDYDATA`.. etc. Can somebody help me on this?

Thanks.

---

<div class="post-metadata">

**Author:** ![lueneburger](https://avatars.discourse-cdn.com/v4/letter/l/f475e1/32.png) [@lueneburger](https://discuss.elastic.co/u/lueneburger)\
**Post date:** [November 30, 2017, 8:40am UTC](https://discuss.elastic.co/t/logstash-basic-grok-field-types-description/109690/2 "2017-11-30T08:40:39Z")

</div>

HI @elasticcloud

just try the debugger and play around -\> [link](https://grokdebug.herokuapp.com/)

there you can also see the patterns, its the best way to learn this.

Cheers

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 28, 2017, 8:40am UTC](https://discuss.elastic.co/t/logstash-basic-grok-field-types-description/109690/3 "2017-12-28T08:40:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
