# Logstash Grok custom pattern

**URL:** <https://discuss.elastic.co/t/logstash-grok-custom-pattern/58685>\
**Category:** Logstash\
**Created:** [August 23, 2016, 1:25pm UTC](https://discuss.elastic.co/t/logstash-grok-custom-pattern/58685 "2016-08-23T13:25:57Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Abhishek](https://avatars.discourse-cdn.com/v4/letter/a/7ba0ec/32.png) [@Abhishek](https://discuss.elastic.co/u/Abhishek)\
**Post date:** [August 23, 2016, 1:25pm UTC](https://discuss.elastic.co/t/logstash-grok-custom-pattern/58685/1 "2016-08-23T13:25:57Z")

</div>

Hi All,

I want to parse following log patterns with logstash:  
2016-08-12 16:37:00,039 [8] ERROR OnlineService Object reference not set to an instance of an object.

As of now I have created following pattern:  
%{TIMESTAMP\_ISO8601:timestamp\_match} %{GREEDYDATA:logs}

I need to extract **timestamp** (2016-08-12 16:37:00), **code\_1** (039), **code\_2** (8), **log\_level** (ERROR), **message** (OnlineService Object reference not set to an instance of an object.) from log file to ingest into elasticsearch index.

Can anyone please help in above patter creation.

Regards,  
Abhishek

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 23, 2016, 1:31pm UTC](https://discuss.elastic.co/t/logstash-grok-custom-pattern/58685/2 "2016-08-23T13:31:13Z")

</div>

You want to extract the timestamp's milliseconds to a field named `code_1`?

Have you tried using [http://grokconstructor.appspot.com/](http://grokconstructor.appspot.com/) ?

---

<div class="post-metadata">

**Author:** ![Abhishek](https://avatars.discourse-cdn.com/v4/letter/a/7ba0ec/32.png) [@Abhishek](https://discuss.elastic.co/u/Abhishek)\
**Post date:** [August 23, 2016, 1:55pm UTC](https://discuss.elastic.co/t/logstash-grok-custom-pattern/58685/3 "2016-08-23T13:55:40Z")

</div>

Hi,

I've tried below pattern:  
%{TIMESTAMP\_ISO8601:timestamp},%{NUMBER:code1} [%{NUMBER:code2}] %{LOGLEVEL:log\_level} %{GREEDYDATA:message}

And it served my purpose.  
Although I will go through the link provided and explore more 🙂

Thanks,  
Abhishek

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:42am UTC](https://discuss.elastic.co/t/logstash-grok-custom-pattern/58685/4 "2017-07-06T04:42:02Z")

</div>


