# Metatrader: How Parse Such Logs?

**URL:** <https://discuss.elastic.co/t/metatrader-how-parse-such-logs/248406>\
**Category:** Logstash\
**Created:** [September 12, 2020, 12:12pm UTC](https://discuss.elastic.co/t/metatrader-how-parse-such-logs/248406 "2020-09-12T12:12:26Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 12, 2020, 2:41pm UTC](https://discuss.elastic.co/t/metatrader-how-parse-such-logs/248406/2 "2020-09-12T14:41:22Z")

</div>

I would take off the first two fields using then dissect, then use grok with an array of patterns to match each of the message types that you care about.

```
dissect { mapping => { "message" => "%{someNumber} %{someIP} %{[@metadata][restOfLine]}" }
grok {
    match => {
        "[@metadata][restOfLine]" => [
            "^%{IPV4:anotherIP} '%{NUMBER:anotherNumber}': login ...",
            "^Monitor connections: %{NUMBER:connections} free memory: %{NUMBER:freeKB} ..."
        ]
    }
}
```

---

_[View the full topic](https://discuss.elastic.co/t/metatrader-how-parse-such-logs/248406)._
