# Logstash filter take everything after

**URL:** <https://discuss.elastic.co/t/logstash-filter-take-everything-after/280061>\
**Category:** Logstash\
**Created:** [July 30, 2021, 9:28am UTC](https://discuss.elastic.co/t/logstash-filter-take-everything-after/280061 "2021-07-30T09:28:32Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Betorov](https://avatars.discourse-cdn.com/v4/letter/b/ea666f/32.png) [@Betorov](https://discuss.elastic.co/u/Betorov)\
**Post date:** [July 30, 2021, 9:28am UTC](https://discuss.elastic.co/t/logstash-filter-take-everything-after/280061/1 "2021-07-30T09:28:32Z")

</div>

Hi avrey one,  
I wanted to filter this type of message:  
ip ip text  
I don't know the format of the text and what is inside of it.I only know that there is 2 ip and the text.  
How i can geto something that I don't know is structurated? (I want to take the text but i don't know how it's made (it can have number and text))

---

<div class="post-metadata">

**Author:** ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)\
**Post date:** [July 30, 2021, 9:34am UTC](https://discuss.elastic.co/t/logstash-filter-take-everything-after/280061/2 "2021-07-30T09:34:16Z")

</div>

Hi,  
I think, using the [grok](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html) plugin is the best solution available for you.  
Cad.

---

<div class="post-metadata">

**Author:** ![Betorov](https://avatars.discourse-cdn.com/v4/letter/b/ea666f/32.png) [@Betorov](https://discuss.elastic.co/u/Betorov)\
**Post date:** [July 30, 2021, 9:43am UTC](https://discuss.elastic.co/t/logstash-filter-take-everything-after/280061/3 "2021-07-30T09:43:16Z")

</div>

> [@Cad](#):
>
> availab

Thank for your reply @Cad .  
I have tried to use it but it give a \_grokparsefailure.

```auto
 grok
                {
                match => { "message"=> "%{IP:client} %{IP:destination} %{GREEDYDATA:request} " }
                }

```

---

<div class="post-metadata">

**Author:** ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)\
**Post date:** [July 30, 2021, 9:56am UTC](https://discuss.elastic.co/t/logstash-filter-take-everything-after/280061/4 "2021-07-30T09:56:21Z")

</div>

Can you give us an exemple of your data ?

> [@Betorov](#):
>
> `"%{IP:client} %{IP:destination} %{GREEDYDATA:request} "`

I think you have to remove the last space after the GREEDYDATA pattern.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 27, 2021, 9:57am UTC](https://discuss.elastic.co/t/logstash-filter-take-everything-after/280061/5 "2021-08-27T09:57:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
