# Logstash filter from Logstash-forwarder

**URL:** <https://discuss.elastic.co/t/logstash-filter-from-logstash-forwarder/27757>\
**Category:** Logstash\
**Created:** [August 20, 2015, 12:03pm UTC](https://discuss.elastic.co/t/logstash-filter-from-logstash-forwarder/27757 "2015-08-20T12:03:29Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![MiCR9](https://avatars.discourse-cdn.com/v4/letter/m/bcef8e/32.png) [@MiCR9](https://discuss.elastic.co/u/MiCR9)\
**Post date:** [August 20, 2015, 12:03pm UTC](https://discuss.elastic.co/t/logstash-filter-from-logstash-forwarder/27757/1 "2015-08-20T12:03:29Z")

</div>

I am trying to get my logs work right however cannot work out what I am going wrong.

```
filter{
	grok{
		match => ["message", "%{TIMESTAMP_ISO8601:timestamp}% %{LOGLEVEL:loglevel}% %{GREEDYDATA:message}"]
		overwrite => ["message"]
	}
	json{
		source => "message"
		remove_field => ["message"]
	}
}

```

My logs are

```
[2015-08-20 14:00:48.195524] [info] {"JOBID":"","USERID":"","TYPE":"","REF":"","INFO":"ps x | grep .php | awk '{print $7}'"}
[2015-08-20 14:00:48.209359] [info] {"JOBID":"","USERID":"","TYPE":"","REF":"","INFO":"Watching tube: guv"}
[2015-08-20 14:01:37.489907] [info] {"JOBID":"","USERID":"","TYPE":"","REF":"","INFO":"JobsProcessing: New tube announced (S.90.1)"}
[2015-08-20 14:01:37.493200] [info] {"JOBID":"","USERID":"","TYPE":"","REF":"","INFO":"S.90.1 TRUE Is_Worker_Needed_For_This_Tube"}
[2015-08-20 14:01:37.493978] [info] {"JOBID":"","USERID":"","TYPE":"","REF":"","INFO":"S.90.1 Match on Get_Worker_File"}
[2015-08-20 14:01:37.496040] [info] {"JOBID":"","USERID":"","TYPE":"","REF":"","INFO":"S.90.1 Match on Get_Worker_File"}
[2015-08-20 14:01:37.496711] [info] {"JOBID":"","USERID":"","TYPE":"","REF":"","INFO":"ps x | grep \"[m]ock_worker.php S.90.1\" | awk '{print $7}'"}
[2015-08-20 14:01:37.497358] [info] {"JOBID":"","USERID":"","TYPE":"","REF":"","INFO":"S.90.1 Match on Get_Worker_File"}
[2015-08-20 14:01:37.509294] [info] {"JOBID":"","USERID":"","TYPE":"","REF":"","INFO":"MakeProcess:(S.90.1)"}

```

If anyone has the time to give me some advice that would be great thank you, also note I can change the log files to what ever I thought it was easier to use JSON as this is using php klogger.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 20, 2015, 12:13pm UTC](https://discuss.elastic.co/t/logstash-filter-from-logstash-forwarder/27757/2 "2015-08-20T12:13:49Z")

</div>

There are a couple of problems here:

- It's `%{PATTERN:fieldname}`, not `%{PATTERN:fieldname}%`.
- The timestamp and log level are surrounded by square brackets but they're not included in your grok expression: Hence: `\[%{TIMESTAMP_ISO8601:timestamp}\] \[%{LOGLEVEL:loglevel}\]`.

---

<div class="post-metadata">

**Author:** ![MiCR9](https://avatars.discourse-cdn.com/v4/letter/m/bcef8e/32.png) [@MiCR9](https://discuss.elastic.co/u/MiCR9)\
**Post date:** [August 20, 2015, 12:36pm UTC](https://discuss.elastic.co/t/logstash-filter-from-logstash-forwarder/27757/3 "2015-08-20T12:36:07Z")

</div>

Your a super star thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:31am UTC](https://discuss.elastic.co/t/logstash-filter-from-logstash-forwarder/27757/4 "2017-07-06T05:31:28Z")

</div>


