# Multiple Grok: add filed of one grok in other groks

**URL:** <https://discuss.elastic.co/t/multiple-grok-add-filed-of-one-grok-in-other-groks/148964>\
**Category:** Logstash\
**Created:** [September 18, 2018, 11:03am UTC](https://discuss.elastic.co/t/multiple-grok-add-filed-of-one-grok-in-other-groks/148964 "2018-09-18T11:03:54Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![richagautam](https://avatars.discourse-cdn.com/v4/letter/r/9e8a1a/32.png) [@richagautam](https://discuss.elastic.co/u/richagautam)\
**Post date:** [September 18, 2018, 11:03am UTC](https://discuss.elastic.co/t/multiple-grok-add-filed-of-one-grok-in-other-groks/148964/1 "2018-09-18T11:03:54Z")

</div>

Hi Team,

I have multiple grok to extract multiple formats from the log files.My question is how can i add filed of grok in other grok.

grok  
{  
match =\> {"message" =\> "%{SYSLOGTIMESTAMP:Time} %{GREEDYDATA:host} (?%{WORD})[[0-9]\*]: %{GREEDYDATA:DataString1}"}  
add\_field =\> { "[TCNAME]" =\> "%{DataString1}" }

```
              }

```

if "\_grokparsefailure" in [tags] {  
grok  
{  
match =\> {"message" =\> "%{SYSLOGTIMESTAMP:Time} %{HOSTNAME:HOST} (?%{WORD})[[0-9]\*]: (?WARNING %{GREEDYDATA})"}  
add\_field =\> { "[TCNAME]" =\> "%{DataString1}" }  
remove\_tag =\> ["\_grokparsefailure"]  
}  
}

I am not able to add "TCNAME" filed in second grok.

Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 20, 2018, 5:31pm UTC](https://discuss.elastic.co/t/multiple-grok-add-filed-of-one-grok-in-other-groks/148964/2 "2018-09-20T17:31:55Z")

</div>

- A single grok filter can include multiple expressions that will be tried in order until there's a match. See the documentation of the filter's `match` options for an example.
- In the second filter no `DataString1` field is extract by the filter so it won't make sense to copy that field to `TCNAME`.
- Your `add_field` settings are pointless. If you want the data in the `TCNAME` field extract it straight to that field instead of using `DataString1` as a temporary field.

---

<div class="post-metadata">

**Author:** ![richagautam](https://avatars.discourse-cdn.com/v4/letter/r/9e8a1a/32.png) [@richagautam](https://discuss.elastic.co/u/richagautam)\
**Post date:** [September 24, 2018, 6:34am UTC](https://discuss.elastic.co/t/multiple-grok-add-filed-of-one-grok-in-other-groks/148964/3 "2018-09-24T06:34:21Z")

</div>

Thanks magnusbaeck,

- A single grok filter can include multiple expressions that will be tried in order until there's a match. See the documentation of the filter's `match` options for an example.

My problem is that i have to extract multiple pattern from the log files and log data is not consistent, like one log line contains filename, second log file contains TCName,3rd error String contains errorString and 4th error String contains TCName:Completed.

Now i have to extract all these string and group them by the TCName.

To extract multiple patterns i am using multiple groks, i am able to extract all the information but i am not group them . Best way i though to group all information is by displaying all the information in the same order it is coming in the log file  
But I am not able to achieve it as log data has same timestamp in some scenario , i am not able to maintain the sequence of log data while parsing it.

How can i maintain the sequence of log data having same timestamp, I am not using filebeat

Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 24, 2018, 6:44am UTC](https://discuss.elastic.co/t/multiple-grok-add-filed-of-one-grok-in-other-groks/148964/4 "2018-09-24T06:44:51Z")

</div>

Okay, so the information you need is spread out over multiple log entries? You can probably use an aggregate filter to save information from previous lines and use them later on.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 22, 2018, 6:44am UTC](https://discuss.elastic.co/t/multiple-grok-add-filed-of-one-grok-in-other-groks/148964/5 "2018-10-22T06:44:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
