# Multiple logs pattern in single grok

**URL:** <https://discuss.elastic.co/t/multiple-logs-pattern-in-single-grok/142205>\
**Category:** Logstash\
**Created:** [July 30, 2018, 3:15pm UTC](https://discuss.elastic.co/t/multiple-logs-pattern-in-single-grok/142205 "2018-07-30T15:15:50Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![8Bit\_System](https://avatars.discourse-cdn.com/v4/letter/8/7ea924/32.png) [@8Bit\_System](https://discuss.elastic.co/u/8Bit_System)\
**Post date:** [July 30, 2018, 3:15pm UTC](https://discuss.elastic.co/t/multiple-logs-pattern-in-single-grok/142205/1 "2018-07-30T15:15:50Z")

</div>

Hello Sir

i have a single log file which have different diffrent pattern i just want to create a single grok which will work on all pattern please help me in this condation what should i do .  
#log1  
2018-06-14 13:55:59.059 : INFO : (50280 | DIRECTOR) : (IS | PC\_IS\_SVC\_QA02\_UNICODE) : node01\_tclasetlq002 : VAR\_27028 : Use override value [rf\_data\_conversion@tiffany.com] for user-defined workflow/worklet variable:[$$wf\_email].  
#log2  
2018-06-14 13:55:59.059 : INFO : (50280 | DIRECTOR) : (IS | PC\_IS\_SVC\_QA02\_UNICODE) : node01\_tclasetlq002 : VAR\_27027 : Use default value [] for mapping variable:[$$wf\_name].  
#log3  
2018-06-14 13:55:59.059 : INFO : (50280 | DIRECTOR) : (IS | PC\_IS\_SVC\_QA02\_UNICODE) : node01\_tclasetlq002 : TM\_6685 : Workflow: [wf\_JDE\_World\_to\_E1\_RFConversion\_F4201\_F4211\_to\_F5847001\_F5847003] Run Instance Name: [TAIWAN] Run Id: [301803]

Grok  
%{DATESTAMP:time} : %{WORD:LOGLEVEL} : (%{DATA:d1}) : (%{DATA:d2}) : %{WORD:d3} : %{WORD:d4} : %{DATA:D5}[(?[a-zA-Z0-9\_.+=:-]+@[0-9A-Za-z][0-9A-Za-z-]{0,62}(?:.(?:[0-9A-Za-z][0-‌9A-Za-z-]{0,62}))\*)]%{DATA:D6}[%{GREEDYDATA:D7}]

This pattern work on #log1 please guide me ...

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 30, 2018, 3:25pm UTC](https://discuss.elastic.co/t/multiple-logs-pattern-in-single-grok/142205/2 "2018-07-30T15:25:08Z")

</div>

I would approach that using dissect before doing any grok.

```
dissect { mapping => { "message" => "%{ts} %{+ts} : %{loglevel} : %{d1} : %{d2} : %{d3} : %{restOfLine}" } }
```

---

<div class="post-metadata">

**Author:** ![8Bit\_System](https://avatars.discourse-cdn.com/v4/letter/8/7ea924/32.png) [@8Bit\_System](https://discuss.elastic.co/u/8Bit_System)\
**Post date:** [July 30, 2018, 3:48pm UTC](https://discuss.elastic.co/t/multiple-logs-pattern-in-single-grok/142205/3 "2018-07-30T15:48:16Z")

</div>

you mean inside the logstash filter, i need to call this mapping. here My problem i need to extract some fileds from rest of line, if there is any email id than i need to extact that field as well.can you help me, how can i extract filed from rest of line.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 30, 2018, 5:01pm UTC](https://discuss.elastic.co/t/multiple-logs-pattern-in-single-grok/142205/4 "2018-07-30T17:01:34Z")

</div>

Identifying an email address is a really hard problem. For simple cases something like

```
grok { match => { "restOfLine" => "\[%{EMAILADDRESS:email}\]" } }

```

would work. But that's not going work with an email address like "me@foo.example.com"@bar.example.com (i.e routing embedded in the address) and certainly not with international email addresses such as अजय@डाटा.भारत

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 27, 2018, 5:01pm UTC](https://discuss.elastic.co/t/multiple-logs-pattern-in-single-grok/142205/5 "2018-08-27T17:01:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
