# Logstash:grok:Create a single structure from multiple pattern

**URL:** <https://discuss.elastic.co/t/logstashcreate-a-single-structure-from-multiple-pattern/340098>\
**Category:** Logstash\
**Created:** [August 4, 2023, 6:15am UTC](https://discuss.elastic.co/t/logstashcreate-a-single-structure-from-multiple-pattern/340098 "2023-08-04T06:15:12Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![nehag](https://avatars.discourse-cdn.com/v4/letter/n/e79b87/32.png) [@nehag](https://discuss.elastic.co/u/nehag)\
**Post date:** [August 4, 2023, 6:15am UTC](https://discuss.elastic.co/t/logstashcreate-a-single-structure-from-multiple-pattern/340098/1 "2023-08-04T06:15:12Z")

</div>

I have logs coming in the following pattern:

```auto
================================================================================================== 
CHECK 1 : Below are the missing Components in the patch 
================================================================================================== 
Component abc.core.min missing in xyz.xml
Component abc.bali.ewt missing in pqr.xml
Component abc.bali.jewt missing in xyz.xml
================================================================================================== 
CHECK 2 : Below are the missing DOs in the patch 
================================================================================================== 
Files missing under component abc.assist.acf : emca.sbs
Files missing under component abc.assist.acf : rconfig.sbs
================================================================================================== 

```

I need to structure this unstructured data in something like the following:

```auto
{
check number: 1
check name: Below are the missing Components in the patch
    {
     componentName:
	 fileName:
	 }
	 {
     component name:
	 missing in file:
	 }
}
check number:2
check name: Below are the missing DOs in the patch
	{
	componentName:
	fileName:
    }
	{
	componentName:
	fileName:
    }
}	

```

I am trying 2 grok in the filter as follows which works in isolation but combination does not work. Also how can the result be mutated to get the output structure I am looking for ?

```auto
Component %{DATA:componentName}(missing in)\s%{GREEDYDATA:missingInFileName}
%{WORD:check} %{INT:checkNum} : %{GREEDYDATA:checkName}"

```

TIA

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2023, 6:16am UTC](https://discuss.elastic.co/t/logstashcreate-a-single-structure-from-multiple-pattern/340098/2 "2023-09-01T06:16:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
