# Logstash Grok filter code

**URL:** <https://discuss.elastic.co/t/logstash-grok-filter-code/125418>\
**Category:** Logstash\
**Created:** [March 23, 2018, 11:06pm UTC](https://discuss.elastic.co/t/logstash-grok-filter-code/125418 "2018-03-23T23:06:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![VidyaKumar](https://avatars.discourse-cdn.com/v4/letter/v/f05b48/32.png) [@VidyaKumar](https://discuss.elastic.co/u/VidyaKumar)\
**Post date:** [March 23, 2018, 11:06pm UTC](https://discuss.elastic.co/t/logstash-grok-filter-code/125418/1 "2018-03-23T23:06:50Z")

</div>

Hi all, Need your help with grok: How do I code for the following line?

6a 00001020 m 20420 ltel2drv 18/03/14 13:12:17.422057 CC0: DlschInfo: UE=16, SFNSF=7616, cell=PCC, msgType,nRB=000004, HID=0, HARQ\_12=10, nRTX\_12=00, MCS\_12=0600, TBS\_12=00490000, padBytes\_12=00000000, Q=0

I am able to code till CC0: and after that I am able to take in as greedydata:  
match =\> ["message", "%{WORD:msgtype}%{SPACE}%{WORD:code1}%{SPACE}%{WORD:module}%{SPACE}%{WORD:code2}%{SPACE}%{WORD:type1}%{SPACE}%{DATESTAMP:timestamp}%{SPACE}\(%{WORD:method}\:%{SPACE}%{NUMBER:code3}\)%{SPACE}%{GREEDYDATA:msg}"]

But after CC0, I need it to be separate fields and not greedydata.  
Can someone help me on this?  
Thanks!

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [March 24, 2018, 7:13am UTC](https://discuss.elastic.co/t/logstash-grok-filter-code/125418/2 "2018-03-24T07:13:36Z")

</div>

It's very hard to ask someone to define a generalised pattern for something and also only provide a single example.

When I paste your single message and pattern into the [Grok Constructor](http://grokconstructor.appspot.com/do/match), I see that after the `timestamp` field, your pattern expects a space, followed by a literal open paren (`(`), but the log message does not have an open paren at this position.

Once you get the `GREEDYDATA` to capture only that which is after `DlschInfo:`, you can likely use the [kv filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-kv.html) to capture the key/value pairs in the rest.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 21, 2018, 7:13am UTC](https://discuss.elastic.co/t/logstash-grok-filter-code/125418/3 "2018-04-21T07:13:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
