# Multiple patterns in one index

**URL:** <https://discuss.elastic.co/t/multiple-patterns-in-one-index/131072>\
**Category:** Logstash\
**Created:** [May 8, 2018, 10:13pm UTC](https://discuss.elastic.co/t/multiple-patterns-in-one-index/131072 "2018-05-08T22:13:20Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hamza\_Dhahri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hamza_dhahri/32/29968_2.png) [@Hamza\_Dhahri](https://discuss.elastic.co/u/Hamza_Dhahri)\
**Post date:** [May 8, 2018, 10:13pm UTC](https://discuss.elastic.co/t/multiple-patterns-in-one-index/131072/1 "2018-05-08T22:13:20Z")

</div>

\</\> 2018-02-07T10:42:02,831 [ExtractDwhData] [INFO] Solife :: Tools :: DWH :: ITK DWH - version : 2.6.0-SNAPSHOT - build #265 on 2018-01-04 08:22:32  
2018-02-07T10:42:02,832 [ExtractDwhData] [INFO] Starting DWH Data Extraction with run timestamp : 2018-02-07 10:42:02  
2018-02-07T12:24:45,167 [ExtractDwhData] [INFO] Solife DWH data EXTRACTION finished in 1 hours, 42 minutes, 42.368 seconds  
\</\>

hello everyone

for those three lines i use this config file

\</\>

input {  
file {  
type =\> "test1"  
path =\> ["C:/Users/THINKPAD/Downloads/logstash-6.2.2/essai/_._"]

}

}

filter {  
if [type] == "test1"{  
grok {  
match =\>["message", "%{TIMESTAMP\_ISO8601:timestamp}%{GREEDYDATA:message1}\s+Extraction\sbatch\sID\s:\s%{NUMBER:ID\_extraction\_globale}",  
"message","%{TIMESTAMP\_ISO8601:start\_time\_extraction\_globale}%{GREEDYDATA:message2}\sStarting\sDWH\sData\sExtraction%{GREEDYDATA:message3}"  
,"message","%{TIMESTAMP\_ISO8601:END\_TIME}%{GREEDYDATA:message4}\sSolife\sDWH\sdata\sEXTRACTION\sfinished\sin%{GREEDYDATA:temps\_totales}"]

}

mutate {  
remove\_field =\> ["message1" ,"message2","message3","message4"]  
}

if "\_grokparsefailure" in [tags] {  
drop {}  
}

}  
}

output {  
if [type] == "test1"{  
elasticsearch { hosts =\> ["localhost:9200"]  
index=\>"globalextraction"}  
stdout {  
codec =\> rubydebug  
}  
}  
}

\</\>

i want to get the result of those 3 patterns in elastic search in one line whish have  
the informations  
but the problem is i get each pattern in a single line and in the table of elasticearch i have 3 lines  
someeone help me to add a command to regroup the result of parsing in one line 🙂

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 8, 2018, 10:20pm UTC](https://discuss.elastic.co/t/multiple-patterns-in-one-index/131072/2 "2018-05-08T22:20:54Z")

</div>

Please don't post the same thing twice - [Multiple patterns regrouping in one line index](https://discuss.elastic.co/t/multiple-patterns-regrouping-in-one-line-index/131073)

You are able to edit the subject and post if you need to 🙂

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 8, 2018, 10:20pm UTC](https://discuss.elastic.co/t/multiple-patterns-in-one-index/131072/3 "2018-05-08T22:20:59Z")

</div>


