# Multiple pattern in log file - logstash config file

**URL:** <https://discuss.elastic.co/t/multiple-pattern-in-log-file-logstash-config-file/55919>\
**Category:** Logstash\
**Created:** [July 19, 2016, 7:16pm UTC](https://discuss.elastic.co/t/multiple-pattern-in-log-file-logstash-config-file/55919 "2016-07-19T19:16:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bishaka](https://avatars.discourse-cdn.com/v4/letter/b/e480ec/32.png) [@bishaka](https://discuss.elastic.co/u/bishaka)\
**Post date:** [July 19, 2016, 7:16pm UTC](https://discuss.elastic.co/t/multiple-pattern-in-log-file-logstash-config-file/55919/1 "2016-07-19T19:16:41Z")

</div>

Hi,  
I have 2 different patterns in my logs..how do I take them both into account in my logstash configuration file?

Pattern 1: 2016-06-03 08:44:52 | INFO | [[ACTIVE] ExecuteThread: '0' for queue: 'weblogic.kernel.Default (self-tuning)'] | WAKEUP-REQ | RECEIVED | urn:uuid:5c10c107-88f2-3d8b-892f-1ebe004f23f5

Pattern 2: 2016-06-03 08:45:02 | INFO | [jmsContainer-15] | AQ-REQ | RECIEVED | urn:uuid:64543F49-6A27-4AD9-AC0D-0B0A0AA27936

My logstash config file looks like the following:  
I used the grokdebugger to make the query:

filter {  
grok {  
match =\> ["message", "%{NOTSPACE} %{NOTSPACE:threadType} %{NOTSPACE} %{NOTSPACE:requestType} %{NOTSPACE} %{NOTSPACE:requestStatus} %{NOTSPACE} %{GREEDYDATA:requestDetails}"]  
}  
if[threadType] {  
grok {  
break\_on\_match =\> true  
match =\> ["message", "%{NOTSPACE} %{NOTSPACE:threadType} %{NOTSPACE} %{NOTSPACE} %{NOTSPACE} %{NOTSPACE} %{NOTSPACE} %{NOTSPACE} %{NOTSPACE} %{NOTSPACE:requestType} %{NOTSPACE} %{NOTSPACE:requestStatus} %{NOTSPACE} %{GREEDYDATA:requestDetails}"]  
}  
}  
mutate {  
remove =\> ["message"]  
}  
}

I am having trouble with it..Please help! The current config file I have...it doesn't work!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 21, 2016, 11:32am UTC](https://discuss.elastic.co/t/multiple-pattern-in-log-file-logstash-config-file/55919/2 "2016-07-21T11:32:14Z")

</div>

```auto
filter {
grok {
match => ["message", "PATTERN1", "PATTERN2"]
}
}

```

Just replace the `PATTERN` sections with the actual patterns.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:47am UTC](https://discuss.elastic.co/t/multiple-pattern-in-log-file-logstash-config-file/55919/3 "2017-07-06T04:47:04Z")

</div>


