# Logstash grok filter for parsing nested data?

**URL:** <https://discuss.elastic.co/t/logstash-grok-filter-for-parsing-nested-data/77732>\
**Category:** Logstash\
**Created:** [March 7, 2017, 10:19pm UTC](https://discuss.elastic.co/t/logstash-grok-filter-for-parsing-nested-data/77732 "2017-03-07T22:19:02Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![PMDubuc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pmdubuc/32/91628_2.png) [@PMDubuc](https://discuss.elastic.co/u/PMDubuc)\
**Post date:** [March 7, 2017, 10:19pm UTC](https://discuss.elastic.co/t/logstash-grok-filter-for-parsing-nested-data/77732/1 "2017-03-07T22:19:02Z")

</div>

I have log messages with field data delimited by [] characters. The problem is that sometimes the data in the field contains those characters. How do I write the grok pattern to take the nesting level into account, excluding the outer brackets?

Example, given the field data:

[aaa[bbb]ccc[ddd[14]]]

I want to parse it such that the resulting field contains

aaa[bbb]ccc[ddd[14]]

Thanks

---

<div class="post-metadata">

**Author:** ![timmy8ken](https://avatars.discourse-cdn.com/v4/letter/t/85f322/32.png) [@timmy8ken](https://discuss.elastic.co/u/timmy8ken)\
**Post date:** [March 8, 2017, 1:35am UTC](https://discuss.elastic.co/t/logstash-grok-filter-for-parsing-nested-data/77732/2 "2017-03-08T01:35:11Z")

</div>

I would say that you would need to use some regex to get this done, the following would match everything between the first and last square brackets:

`(?<YourResult>(?<=\[).*?(?=\]$))`

You can change the 'YourResult' text to name the captured results

---

<div class="post-metadata">

**Author:** ![PMDubuc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pmdubuc/32/91628_2.png) [@PMDubuc](https://discuss.elastic.co/u/PMDubuc)\
**Post date:** [March 8, 2017, 2:37pm UTC](https://discuss.elastic.co/t/logstash-grok-filter-for-parsing-nested-data/77732/3 "2017-03-08T14:37:09Z")

</div>

Thanks! What I forgot to mention is that there is another field following this one that I don't want to match. I want that to be matched separately. So, a better example would be:

... [aaa[bbb]ccc[ddd[14]]][name=zyz]

Your suggestion seems to be in the right direction but I think it will match too much in this case. I'm still working on it.

---

<div class="post-metadata">

**Author:** ![timmy8ken](https://avatars.discourse-cdn.com/v4/letter/t/85f322/32.png) [@timmy8ken](https://discuss.elastic.co/u/timmy8ken)\
**Post date:** [March 8, 2017, 10:42pm UTC](https://discuss.elastic.co/t/logstash-grok-filter-for-parsing-nested-data/77732/4 "2017-03-08T22:42:06Z")

</div>

I would suggest having a look at this site: [http://grokconstructor.appspot.com/do/construction](http://grokconstructor.appspot.com/do/construction)

It will allow you to build the grok query and capture the data you need.

Tim

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 5, 2017, 10:42pm UTC](https://discuss.elastic.co/t/logstash-grok-filter-for-parsing-nested-data/77732/5 "2017-04-05T22:42:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
