# Multiple Grok Filters

**URL:** <https://discuss.elastic.co/t/multiple-grok-filters/90501>\
**Category:** Logstash\
**Created:** [June 22, 2017, 5:07pm UTC](https://discuss.elastic.co/t/multiple-grok-filters/90501 "2017-06-22T17:07:26Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kevin\_Wiegand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_wiegand/32/19436_2.png) [@Kevin\_Wiegand](https://discuss.elastic.co/u/Kevin_Wiegand)\
**Post date:** [June 22, 2017, 5:07pm UTC](https://discuss.elastic.co/t/multiple-grok-filters/90501/1 "2017-06-22T17:07:26Z")

</div>

Hey there i got a question about my grok filter...  
I'm dealing with Logfiles which are looking like this:

`2017-05-23 14:41:09 DEBUG [09-exec-38] PreparedStatement (27 ) - {pstm-100637} Executing Statement: SELECT wert1 AS value FROM z_var WHERE varnr=?`

They are comitted by filebeat und send to elasticsearch after filtering.  
My Logstash Config File looks like this and the Grok Filter works fine at the moment:

```
input {
  beats {
	port => 5044
	}
}
 
filter{
grok {
   match => { "message" => "%{TIMESTAMP_ISO8601:timestamp} %{LOGLEVEL:log-level} \[%{DATA:Thread}\] %{DATA:Method} \(%{DATA:Line}\) \- %{GREEDYDATA:logmsg}"}

 }
}
 
output {
  elasticsearch {
	hosts => "localhost:9200"
	manage_template => false
	index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
	document_type => "%{[@metadata][type]}"
  }
  stdout { codec => rubydebug }
}

```

Now I'm dealing with 2 issues:

1. Sometimes in the Message Area of the Logfile there could be something like this when a student tried to login in to the managed platform: "Login 52632". Is it possible to only create a field like "Matrikelnummer" or "Login" if there is a match in the given event? Like you can see in the Filter I'm already matching the whole Message area (greedy data..).

2. When i want to watch the events in Kibana there is as a timestamp the timestamp which is created by filebeat as the index. The timestamp which i am filtering out of the original event is only mapped as a string. How can i change this to be of the type "date" so i can analyse or work with the timestamp?

I hope youre understanding my problems, and i'm sorry for the bad english!  
Best regards from germany

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 22, 2017, 6:57pm UTC](https://discuss.elastic.co/t/multiple-grok-filters/90501/2 "2017-06-22T18:57:57Z")

</div>

> Is it possible to only create a field like "Matrikelnummer" or "Login" if there is a match in the given event?

You can use a second grok filter that matches against the `logmsg` field. You'll want to set `tag_on_failure` to an empty list to avoid getting a `_grokparsefailure` tag on many or most events.

> When i want to watch the events in Kibana there is as a timestamp the timestamp which is created by filebeat as the index. The timestamp which i am filtering out of the original event is only mapped as a string. How can i change this to be of the type "date" so i can analyse or work with the timestamp?

Use a date filter to parse the `timestamp` field and store it in the `@timestamp` field. The `@timestamp` field should always be a date field.

---

<div class="post-metadata">

**Author:** ![Kevin\_Wiegand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_wiegand/32/19436_2.png) [@Kevin\_Wiegand](https://discuss.elastic.co/u/Kevin_Wiegand)\
**Post date:** [June 23, 2017, 8:13am UTC](https://discuss.elastic.co/t/multiple-grok-filters/90501/3 "2017-06-23T08:13:57Z")

</div>

Thanks for the fast response. At first i tried to solve the timestamp thing but unfortunately now I'm getting a \_grokparsefailure tag on each event. Here my filter config:

```
filter{
grok {
   match => { "message" => "%{TIMESTAMP_ISO8601:timestamp} %{LOGLEVEL:log-level} \[%{DATA:Thread}\] %{DATA:Method} \(%{DATA:Line}\) \- %{GREEDYDATA:logmsg}"}
 }
date {
   match=>["timestamp", "yyyy-MM-dd HH:mm:ss"]
   target=>"@timestamp"
 }
}

```

Shouldnt it be a \_dateparsefailure? If i remove the date filter again everything works fine. I'm a bit confused

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 26, 2017, 9:20pm UTC](https://discuss.elastic.co/t/multiple-grok-filters/90501/4 "2017-06-26T21:20:24Z")

</div>

Date filters never add `_grokparsefailure` tags so I don't know what's up. I suggest you verify that you're really using the configuration you think you're using. Do you have any extra files in /etc/logstash/conf.d, for example? Logstash reads _all_ files.

---

<div class="post-metadata">

**Author:** ![Kevin\_Wiegand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kevin_wiegand/32/19436_2.png) [@Kevin\_Wiegand](https://discuss.elastic.co/u/Kevin_Wiegand)\
**Post date:** [June 28, 2017, 10:02am UTC](https://discuss.elastic.co/t/multiple-grok-filters/90501/5 "2017-06-28T10:02:14Z")

</div>

No there's only one config File in conf.d...This behaviour is very strange, i thought there could be a Syntax error because of wrong brackets but i can't figure out what. The Date filter sould be inside the filter section and parallel to the Grok filter..  
Could there be a error because i use different timestamp syntax? `TIMESTAMP_ISO8601` versus `yyyy-MM-dd HH:mm:ss` ? But technically it should be the same..

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 26, 2017, 10:02am UTC](https://discuss.elastic.co/t/multiple-grok-filters/90501/6 "2017-07-26T10:02:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
