# Need Help Groking

**URL:** <https://discuss.elastic.co/t/need-help-groking/221772>\
**Category:** Logstash\
**Created:** [March 2, 2020, 9:02pm UTC](https://discuss.elastic.co/t/need-help-groking/221772 "2020-03-02T21:02:03Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 3, 2020, 3:23am UTC](https://discuss.elastic.co/t/need-help-groking/221772/2 "2020-03-03T03:23:39Z")

</div>

I would not use grok for that, I would use [dissect](https://discuss.elastic.co/t/filter-logs-from-firewall/172494/3) to parse off everything up to the : after the pid, and then use a kv filter for the rest of the line, then maybe use prune with a whitelist to clean up the kv output.

Alternatively, set break\_on\_match to false, and grok out all the individual fields. Do not put .\* between them, just enter each pattern like srcip="%{IP:source.ip}" into the array.

---

_[View the full topic](https://discuss.elastic.co/t/need-help-groking/221772)._
