# Logstash/grok to match only first occurrence and stop parsing repeatedly for same values

**URL:** <https://discuss.elastic.co/t/logstash-grok-to-match-only-first-occurrence-and-stop-parsing-repeatedly-for-same-values/274201>\
**Category:** Logstash\
**Created:** [May 27, 2021, 11:41am UTC](https://discuss.elastic.co/t/logstash-grok-to-match-only-first-occurrence-and-stop-parsing-repeatedly-for-same-values/274201 "2021-05-27T11:41:22Z")\
**Posts on this page:** 1\
**Showing post:** 10

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 27, 2021, 11:09pm UTC](https://discuss.elastic.co/t/logstash-grok-to-match-only-first-occurrence-and-stop-parsing-repeatedly-for-same-values/274201/10 "2021-05-27T23:09:38Z")

</div>

What I would do is

```
    grok {
        pattern_definitions => { "CUSTOMTIME" => "%{DAY} %{MONTH} %{MONTHDAY} %{TIME}" }
        match => { "message" => "%{CUSTOMTIME:[@metadata][timestamp]} %{GREEDYDATA:[@metadata][restOfLine]}" }
    }
    date { match => ["[@metadata][timestamp]", "EEE MMM dd HH:mm:ss" ] }
    ruby {
        init => '@lastValue = nil'
        code => '
            now = event.get("@timestamp").to_f
            if @lastValue == nil
                @lastTime = now
            end

            value = event.get("[@metadata][restOfLine]")
            if value == @lastValue
                event.cancel
            else
                delta = now - @lastTime
                event.set("delta", delta)
                @lastTime = now
            end
            @lastValue = value
        '
    }
```

---

_[View the full topic](https://discuss.elastic.co/t/logstash-grok-to-match-only-first-occurrence-and-stop-parsing-repeatedly-for-same-values/274201)._
