# Multiple grok matching fileds

**URL:** <https://discuss.elastic.co/t/multiple-grok-matching-fileds/25523>\
**Category:** Logstash\
**Created:** [July 14, 2015, 1:44pm UTC](https://discuss.elastic.co/t/multiple-grok-matching-fileds/25523 "2015-07-14T13:44:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![abathula](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/abathula/32/3595_2.png) [@abathula](https://discuss.elastic.co/u/abathula)\
**Post date:** [July 14, 2015, 1:44pm UTC](https://discuss.elastic.co/t/multiple-grok-matching-fileds/25523/1 "2015-07-14T13:44:14Z")

</div>

**This is my log line:**

```
2015-04-14 03:28:12,628 [8] DEBUG NCR.XE.Component.MessageHandler.HistoryEventMessageProcessor - Starting RentalTransactionMessageProcessor message type with the data <invoice iid="00000000-4164-1638-e168-ffff08d24460" id="635645932534212842" dt="2015-04-14T07:27:33" dt_local="2015-04-14T00:27:33" cc_digits="0027" gov_id="" email="" f_name="Test" l_name="EB" m_name="" dob="" addr1="" addr2="" city="" state="" zip="99577" country="" phone1="" phone2="" cc_type="0" AllowSpecialOffers="false" AllowReceipts="false" /><payment amount="15" cc_digits="0027" /></invoice>

```

I want to get the **msg** filed separate from this log line and create a **new filed** for **cc\_digits** value for above log line contains **0027**

**my configuration for this:**

```
filter {

multiline{
        pattern => "^%{TIMESTAMP_ISO8601}"
        what => "previous"
        negate=> true
    }

# Delete trailing whitespaces
  mutate {
    strip => "message"
  }

# Delete \n from messages
mutate {
    gsub => ['message', "\n", " "]
}

# Delete \r from messages
mutate {
    gsub => ['message', "\r", " "]
}

grok { 
  match => { "message" => "%{TIMESTAMP_ISO8601:time} \[%{NUMBER:thread}\] %{LOGLEVEL:loglevel} %{JAVACLASS:class} - %{GREEDYDATA:msg}" } 
}

 grok { 
  match => { "msg" => "%{GREEDYDATA:text}" }
  
}
}

```

I am not able to get the correct configuration. Can you please provide the correct configuration

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 14, 2015, 2:47pm UTC](https://discuss.elastic.co/t/multiple-grok-matching-fileds/25523/2 "2015-07-14T14:47:36Z")

</div>

This is basically the exact same question as the one below. Perhaps we can keep the discussions together.

> [@Create new field based on msg filed in logstash](https://discuss.elastic.co/t/create-new-field-based-on-msg-filed-in-logstash/25527):
>
> Hi All, Here i want to create a new field Invoice\_IID based on msg filed, contains Invoice\_IID value in log line msg filed. "msg" =\> "Finished Creating Parent Invoices for Invoice\_IID: 80000000-41fb-1638-cd42-ffff08d24480" My configuration is: filter { grok { match =\> { "message" =\> "%{TIMESTAMP\_ISO8601:time} \[%{NUMBER:thread}\] %{LOGLEVEL:loglevel} %{JAVACLASS:class} - %{GREEDYDATA:msg}" } } if "Invoice\_IID" in [msg] { mutate { add\_field =\> { "Invoice\_IID" =\> "%{msg}" } } } } Th…

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 15, 2015, 4:24am UTC](https://discuss.elastic.co/t/multiple-grok-matching-fileds/25523/3 "2015-07-15T04:24:46Z")

</div>

Yeah, please see existing thread ^

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 15, 2015, 4:24am UTC](https://discuss.elastic.co/t/multiple-grok-matching-fileds/25523/4 "2015-07-15T04:24:48Z")

</div>


