# Need Help Groking

**URL:** <https://discuss.elastic.co/t/need-help-groking/221772>\
**Category:** Logstash\
**Created:** [March 2, 2020, 9:02pm UTC](https://discuss.elastic.co/t/need-help-groking/221772 "2020-03-02T21:02:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![uklipse](https://avatars.discourse-cdn.com/v4/letter/u/cdc98d/32.png) [@uklipse](https://discuss.elastic.co/u/uklipse)\
**Post date:** [March 2, 2020, 9:02pm UTC](https://discuss.elastic.co/t/need-help-groking/221772/1 "2020-03-02T21:02:04Z")

</div>

I am attempting to write my first grok filter but I'm not getting any logs parsed. Here is my sample log.

```
<30>2020:02:26-12:41:48 aua[18909]: id="3005" severity="warn" sys="System" sub="auth" 
name="Authentication failed" srcip="1.2.3.4" host="" user="admin" caller="openvpn" 
reason="DENIED"

```

I'm only interested in four fields. I've used the grok debugger [https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/) with the pattern below and it parses correctly.

```
.*name="%{DATA:event.action}".*srcip="%{IP:source.ip}".*user="%{USER:user.name}".*caller="%{WORD:event.type}"

```

Here is my grok filter. I thought it was something to do with the double quotes so I tried escaping them but no change. Very new to this so not sure if this is the easiest method or if there is something else I need to do to create this filter.

```
         grok {
      match => {"message" => ".*name=\"%{DATA:event.action}\".*srcip=\"%{IP:source.ip}\".*user=\"%{USER:user.name}\".*caller=\"%{WORD:event.type}\""}
    }
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 3, 2020, 3:23am UTC](https://discuss.elastic.co/t/need-help-groking/221772/2 "2020-03-03T03:23:39Z")

</div>

I would not use grok for that, I would use [dissect](https://discuss.elastic.co/t/filter-logs-from-firewall/172494/3) to parse off everything up to the : after the pid, and then use a kv filter for the rest of the line, then maybe use prune with a whitelist to clean up the kv output.

Alternatively, set break\_on\_match to false, and grok out all the individual fields. Do not put .\* between them, just enter each pattern like srcip="%{IP:source.ip}" into the array.

---

<div class="post-metadata">

**Author:** ![uklipse](https://avatars.discourse-cdn.com/v4/letter/u/cdc98d/32.png) [@uklipse](https://discuss.elastic.co/u/uklipse)\
**Post date:** [March 3, 2020, 9:11pm UTC](https://discuss.elastic.co/t/need-help-groking/221772/3 "2020-03-03T21:11:58Z")

</div>

Going the kv gives me more fields than I need but it much cleaner and easier.

Thanks Badger for your help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 31, 2020, 9:12pm UTC](https://discuss.elastic.co/t/need-help-groking/221772/4 "2020-03-31T21:12:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
