# @metadata and regexp named groups

**URL:** <https://discuss.elastic.co/t/metadata-and-regexp-named-groups/93237>\
**Category:** Logstash\
**Created:** [July 14, 2017, 7:05pm UTC](https://discuss.elastic.co/t/metadata-and-regexp-named-groups/93237 "2017-07-14T19:05:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![danielmotaleite](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielmotaleite/32/19796_2.png) [@danielmotaleite](https://discuss.elastic.co/u/danielmotaleite)\
**Post date:** [July 14, 2017, 7:05pm UTC](https://discuss.elastic.co/t/metadata-and-regexp-named-groups/93237/1 "2017-07-14T19:05:19Z")

</div>

in the url  
[https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html)  
we can see that we can use [@metadata][timestamp] in a grok:

```
filter {
  grok { match => ["message", "%{HTTPDATE:[@metadata][timestamp]}" ] }
  date { match => ["[@metadata][timestamp]", "dd/MMM/yyyy:HH:mm:ss Z" ] }
}

```

yet, nothing is said about regexp named groups and trying to use this

```
filter {
  grok { match => ["message", "(?<[@metadata][timestamp]>[^]+)" ] }
  date { match => ["[@metadata][timestamp]", "dd/MMM/yyyy:HH:mm:ss Z" ] }
}

```

fails... so how to use @metadata within a named group?

After knowing, i will probably open a bug to update the docs to include a example for named groups

thanks

---

<div class="post-metadata">

**Author:** ![paz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paz/32/28003_2.png) [@paz](https://discuss.elastic.co/u/paz)\
**Post date:** [July 17, 2017, 12:53pm UTC](https://discuss.elastic.co/t/metadata-and-regexp-named-groups/93237/2 "2017-07-17T12:53:51Z")

</div>

I'm pretty sure you can't use nested fields (or even bracket/@ characters ) as capture groups in pure regex.  
A possible alternative would be to capture it in a single temporary field and then use e.g. mutate to add it's value to '[@metadata][timestamp]'

---

<div class="post-metadata">

**Author:** ![danielmotaleite](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danielmotaleite/32/19796_2.png) [@danielmotaleite](https://discuss.elastic.co/u/danielmotaleite)\
**Post date:** [August 4, 2017, 5:35pm UTC](https://discuss.elastic.co/t/metadata-and-regexp-named-groups/93237/3 "2017-08-04T17:35:18Z")

</div>

That is almost what i'm doing right now... but then i have to remove the useless variable.

I was trying to save a few cycles (doing the drop of a temporary field) and space (waste disk space by storing both @timestamp and the event date field) by using the @metadata field to store the log date, as it is automatically discarded in the end.

In many millions events per day, a few optimizations like this always help... but if it is not possible, lets do the drop  
thanks for the help

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2017, 5:35pm UTC](https://discuss.elastic.co/t/metadata-and-regexp-named-groups/93237/4 "2017-09-01T17:35:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
