# Logstash/grok patterns with ECS

**URL:** <https://discuss.elastic.co/t/logstash-grok-patterns-with-ecs/197871>\
**Category:** Logstash\
**Tags:** ecs-elastic-common-schema\
**Created:** [September 3, 2019, 1:35pm UTC](https://discuss.elastic.co/t/logstash-grok-patterns-with-ecs/197871 "2019-09-03T13:35:48Z")\
**Posts on this page:** 1\
**Showing post:** 11

<div class="post-metadata">

**Author:** ![webmat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/webmat/32/46191_2.png) [@webmat](https://discuss.elastic.co/u/webmat)\
**Post date:** [November 29, 2019, 3:31pm UTC](https://discuss.elastic.co/t/logstash-grok-patterns-with-ecs/197871/11 "2019-11-29T15:31:39Z")

</div>

Hello!

Sorry this was overlooked. We need to promote the [elastic-common-schema](https://discuss.elastic.co/tags/elastic-common-schema) tag more, it seems. Make sure you apply the tag, any time you have an ECS related question 🙂

What problems are you encountering with your grok patterns? The obvious one I could guess is about field nesting. All fields in ECS should be nested, no dots in key names. Dots are used as a shorthand to represent the nesting. So in your grok you can get nested fields using square brackets, like `%{IPORHOST:[url][domain]}`. [Here's a more fleshed out example](https://discuss.elastic.co/t/parsing-url-with-logstash-using-ecs-fields-nested/209953)

> Is ECS dead already?

Not at all 😉

---

_[View the full topic](https://discuss.elastic.co/t/logstash-grok-patterns-with-ecs/197871)._
