# Multiple match in one grok {}

**URL:** <https://discuss.elastic.co/t/multiple-match-in-one-grok/246569>\
**Category:** Logstash\
**Created:** [August 27, 2020, 7:29am UTC](https://discuss.elastic.co/t/multiple-match-in-one-grok/246569 "2020-08-27T07:29:11Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![shani](https://avatars.discourse-cdn.com/v4/letter/s/e95f7d/32.png) [@shani](https://discuss.elastic.co/u/shani)\
**Post date:** [August 27, 2020, 7:29am UTC](https://discuss.elastic.co/t/multiple-match-in-one-grok/246569/1 "2020-08-27T07:29:12Z")

</div>

Hi All,

I want to match multiple different fields using GROK, this doesn't work

```
grok {
            match => {
              "winlog_subject" => "Subject:\\nSecurity ID:%{DATA:[winlog][event_data][SubjectUserSid]}\\nAccount Name:%{DATA:[winlog][event_data][SubjectUserName]}\\nAccount Domain:%{DATA:[winlog][event_data][SubjectDomainName]}\\nLogon ID:%{DATA:[winlog][event_data][SubjectLogonId]}$"
            }
            match => {
              "winlog_logon" => ["Logon Information:\\nLogon Type:%{DATA:[winlog][event_data][LogonType]}\\nRestricted Admin Mode:%{DATA:[winlog][event_data][RestrictedAdminMode]}\\nVirtual Account:%{DATA:[winlog][event_data][VirtualAccountNumber]}\\nElevated Token:%{WORD:[winlog][event_data][ElevatedToken]}","Logon Type:%{NUMBER:[winlog][event_data][LogonType]}"]
            }
            match => {
              "winlog_impersonation" => "Impersonation Level:%{WORD:[winlog][event_data][ImpersonationLevel]}"
            }
            match => {
              "winlog_newlogon" => "New Logon:\\nSecurity ID:%{DATA:[winlog][event_data][TargetUserSid]}\\nAccount Name:%{DATA:[winlog][event_data][TargetUserName]}\\nAccount Domain:%{DATA:[winlog][event_data][TargetDomainName]}\\nLogon ID:%{DATA:[winlog][event_data][TargetLogonId]}\\nLinked Logon ID:%{DATA:[winlog][event_data][LinkedLogonId]}\\nNetwork Account Name:%{DATA:[winlog][event_data][NetworkAccountName]}\\nNetwork Account Domain:%{DATA:[winlog][event_data][NetworkAccountDomain]}\\nLogon GUID:%{DATA:[winlog][event_data][LogonGuid]}$"
            }
            match => {
              "winlog_process" => "Process Information:\\nProcess ID:%{DATA:[winlog][event_data][ProcessId]}\\nProcess Name:%{DATA:[winlog][event_data][ProcessName]}$"
            }
            match => {
              "winlog_network" => "Network Information:\\nWorkstation Name:%{DATA:[winlog][event_data][WorkStationName]}\\nSource Network Address:%{IPV4:[winlog][event_data][SrcNetworkAddress]}\\nSource Port:%{NUMBER:[winlog][event_data][SourcePort]}$"
            }
            match => {
              "winlog_authentication" => "%{GREEDYDATA:[winlog][event_data][authentication]}"
            }
          }#end_grok
```

---

<div class="post-metadata">

**Author:** ![shani](https://avatars.discourse-cdn.com/v4/letter/s/e95f7d/32.png) [@shani](https://discuss.elastic.co/u/shani)\
**Post date:** [August 28, 2020, 4:38pm UTC](https://discuss.elastic.co/t/multiple-match-in-one-grok/246569/2 "2020-08-28T16:38:24Z")

</div>

Hi All,

Can anyone please reply me on this^

Would be greatful!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 28, 2020, 4:43pm UTC](https://discuss.elastic.co/t/multiple-match-in-one-grok/246569/3 "2020-08-28T16:43:57Z")

</div>

Generally it is a bad idea to supply an option to a filter more than once. logstash will combine them and sometimes it does it a way that you would not expect. You probably want to add a break\_on\_match option

> [@shani](#):
>
> ```auto
> grok {
> break_on_match => false
> match => {
> "winlog_subject" => "Subject:\\nSecurity ID:%{DATA:[winlog][event_data][SubjectUserSid]}\\nAccount Name:%{DATA:[winlog][event_data][SubjectUserName]}\\nAccount Domain:%{DATA:[winlog][event_data][SubjectDomainName]}\\nLogon ID:%{DATA:[winlog][event_data][SubjectLogonId]}$"
> "winlog_logon" => ["Logon Information:\\nLogon Type:%{DATA:[winlog][event_data][LogonType]}\\nRestricted Admin Mode:%{DATA:[winlog][event_data][RestrictedAdminMode]}\\nVirtual Account:%{DATA:[winlog][event_data][VirtualAccountNumber]}\\nElevated Token:%{WORD:[winlog][event_data][ElevatedToken]}","Logon Type:%{NUMBER:[winlog][event_data][LogonType]}"]
> "winlog_impersonation" => "Impersonation Level:%{WORD:[winlog][event_data][ImpersonationLevel]}"
> "winlog_newlogon" => "New Logon:\\nSecurity ID:%{DATA:[winlog][event_data][TargetUserSid]}\\nAccount Name:%{DATA:[winlog][event_data][TargetUserName]}\\nAccount Domain:%{DATA:[winlog][event_data][TargetDomainName]}\\nLogon ID:%{DATA:[winlog][event_data][TargetLogonId]}\\nLinked Logon ID:%{DATA:[winlog][event_data][LinkedLogonId]}\\nNetwork Account Name:%{DATA:[winlog][event_data][NetworkAccountName]}\\nNetwork Account Domain:%{DATA:[winlog][event_data][NetworkAccountDomain]}\\nLogon GUID:%{DATA:[winlog][event_data][LogonGuid]}$"
> "winlog_process" => "Process Information:\\nProcess ID:%{DATA:[winlog][event_data][ProcessId]}\\nProcess Name:%{DATA:[winlog][event_data][ProcessName]}$"
> "winlog_network" => "Network Information:\\nWorkstation Name:%{DATA:[winlog][event_data][WorkStationName]}\\nSource Network Address:%{IPV4:[winlog][event_data][SrcNetworkAddress]}\\nSource Port:%{NUMBER:[winlog][event_data][SourcePort]}$"
> "winlog_authentication" => "%{GREEDYDATA:[winlog][event_data][authentication]}"
> }
> }#end_grok
> 
> ```

Of course that assumes that those 7 fields already exist.

---

<div class="post-metadata">

**Author:** ![shani](https://avatars.discourse-cdn.com/v4/letter/s/e95f7d/32.png) [@shani](https://discuss.elastic.co/u/shani)\
**Post date:** [August 29, 2020, 2:07pm UTC](https://discuss.elastic.co/t/multiple-match-in-one-grok/246569/4 "2020-08-29T14:07:44Z")

</div>

this didn't work for me

**error details**

> %{winlog\_subject}\n\n%{winlog\_after\_subject}"}\n tag\_on\_failure =\> ["event\_code\_4719\_dissect\_again\_failed"]\n }#end\_dissect\n }#end\_if\_after\_first\_failed\_dissect\n # apply grok to extract exact event of interest / required fields\n grok {\n break\_on\_match =\> false\n match ", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:32:in `compile_imperative'", "org/logstash/execution/AbstractPipelineExt.java:183:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:69:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/reload.rb:53:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:357:in `block in converge\_state'"]}

**code:**

> grok {  
> break\_on\_match =\> false  
> match =\> {  
> "winlog\_header" =\> "\<%{NOTSPACE}\>%{SPACE}%{HOSTNAME:host\_name}%{GREEDYDATA:remaining\_winlog\_header}"  
> "winlog\_subject" =\> "Subject:\nSecurity ID:%{DATA:winlog\_eventdata\_SubjectUserSid}\nAccount Name:%{DATA:winlog\_eventdata\_SubjectUserName}\nAccount Domain:%{DATA:winlog\_eventdata\_SubjectDomainName}\nLogon ID:%{GREEDYDATA:winlog\_eventdata\_SubjectLogonId}"  
> "winlog\_service" =\> "Service:\nServer:%{DATA:service\_server}\nService Name:%{DATA:winlog\_eventdata\_ServiceName}\n"  
> "winlog\_process" =\> "Process Information:\nProcess ID:%{DATA:winlog\_eventdata\_ProcessId}\nProcess Name:%{DATA:winlog\_eventdata\_ProcessName}"  
> "winlog\_ServiceRequestInformation" =\> "Service Request Information:\nPrivileges:%{DATA:service\_privileges}\n"  
> "winlog\_after\_subject" =\> "%{GREEDYDATA:catch\_all}"  
> }  
> tag\_on\_failure =\> ["event\_code\_4719\_grokfailed"]  
> }#end\_grok

---

<div class="post-metadata">

**Author:** ![shani](https://avatars.discourse-cdn.com/v4/letter/s/e95f7d/32.png) [@shani](https://discuss.elastic.co/u/shani)\
**Post date:** [August 29, 2020, 2:15pm UTC](https://discuss.elastic.co/t/multiple-match-in-one-grok/246569/5 "2020-08-29T14:15:35Z")

</div>

Sir, if a field (i.e winlog\_after\_subject) doesn't exist and we apply to grok on that field how grok behaves then. we're saying in grok like extract more fields using regex on the source field but if it doesn't exists then will it throw an error or how will it treat.

Am I causing error due to this behavior?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 29, 2020, 2:45pm UTC](https://discuss.elastic.co/t/multiple-match-in-one-grok/246569/6 "2020-08-29T14:45:49Z")

</div>

> [@shani](#):
>
> this didn't work for me

What is the actual error message?

---

<div class="post-metadata">

**Author:** ![shani](https://avatars.discourse-cdn.com/v4/letter/s/e95f7d/32.png) [@shani](https://discuss.elastic.co/u/shani)\
**Post date:** [August 30, 2020, 8:46am UTC](https://discuss.elastic.co/t/multiple-match-in-one-grok/246569/7 "2020-08-30T08:46:09Z")

</div>

it's working now thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 27, 2020, 8:46am UTC](https://discuss.elastic.co/t/multiple-match-in-one-grok/246569/8 "2020-09-27T08:46:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
