# Need help with the Grok filter

**URL:** <https://discuss.elastic.co/t/need-help-with-the-grok-filter/207416>\
**Category:** Logstash\
**Created:** [November 11, 2019, 9:00pm UTC](https://discuss.elastic.co/t/need-help-with-the-grok-filter/207416 "2019-11-11T21:00:45Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![o1o1o11o1](https://avatars.discourse-cdn.com/v4/letter/o/74df32/32.png) [@o1o1o11o1](https://discuss.elastic.co/u/o1o1o11o1)\
**Post date:** [November 11, 2019, 9:00pm UTC](https://discuss.elastic.co/t/need-help-with-the-grok-filter/207416/1 "2019-11-11T21:00:45Z")

</div>

I have the following filter in Logstash that parses AWS ELB access logs:

```
filter {
  grok {
    match => ["message", '%{TIMESTAMP_ISO8601:timestamp} %{NOTSPACE:loadbalancer} %{IP:client_ip}:%{NUMBER:client_port:int} (?:%{IP:backend_ip}:%{NUMBER:backend_port:int}|-) %{NUMBER:request_processing_time:float} %{NUMBER:backend_processing_time:float} %{NUMBER:response_processing_time:float} (?:%{NUMBER:elb_status_code:int}|-) (?:%{NUMBER:backend_status_code:int}|-) %{NUMBER:received_bytes:int} %{NUMBER:sent_bytes:int} "(?:%{WORD:verb}|-) (?:%{GREEDYDATA:request}|-) (?:HTTP/%{NUMBER:httpversion}|-( )?)" "%{DATA:userAgent}"( %{NOTSPACE:ssl_cipher} %{NOTSPACE:ssl_protocol})?']
  }
}

```

which results in various fields in Elasticsearch, one being the `request` filed with a possible value of  
`https://api.example.net:443/v2/domain.com/actions?somefield=somevalue`

Is there a way to add a second grok filter to operate on that field, before it gets indexed to ES and have different conditions based on the `domain.com` field ? For example if the `domain.com` string exists add it to a `domain_name` field in Elasticsearch etc.

---

<div class="post-metadata">

**Author:** ![o1o1o11o1](https://avatars.discourse-cdn.com/v4/letter/o/74df32/32.png) [@o1o1o11o1](https://discuss.elastic.co/u/o1o1o11o1)\
**Post date:** [November 15, 2019, 8:28pm UTC](https://discuss.elastic.co/t/need-help-with-the-grok-filter/207416/2 "2019-11-15T20:28:29Z")

</div>

This is the solution to my question:

```auto
filter {

  grok {
    match => ["message", '%{TIMESTAMP_ISO8601:timestamp} %{NOTSPACE:loadbalancer} %{IP:client_ip}:%{NUMBER:client_port:int} (?:%{IP:backend_ip}:%{NUMBER:backend_port:int}|-) %{NUMBER:request_processing_time:float} %{NUMBER:backend_processing_time:float} %{NUMBER:response_processing_time:float} (?:%{NUMBER:elb_status_code:int}|-) (?:%{NUMBER:backend_status_code:int}|-) %{NUMBER:received_bytes:int} %{NUMBER:sent_bytes:int} "(?:%{WORD:verb}|-) (?:%{GREEDYDATA:request}|-) (?:HTTP/%{NUMBER:httpversion}|-( )?)" "%{DATA:userAgent}"( %{NOTSPACE:ssl_cipher} %{NOTSPACE:ssl_protocol})?']
  }
  grok {
    match => ["request", '(/(?<request_endpoint>[^/]+)+/(?<request_version>[^/]+)+/(?<request_domain>[^/]+)/(?<request_api>[^/!\?]+))' ]
  }

}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 13, 2019, 8:28pm UTC](https://discuss.elastic.co/t/need-help-with-the-grok-filter/207416/3 "2019-12-13T20:28:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
