# Nested grok filter or filtering a field using grok

**URL:** https://discuss.elastic.co/t/nested-grok-filter-or-filtering-a-field-using-grok/100841
**Category:** Logstash
**Created:** [September 18, 2017, 9:26am UTC](https://discuss.elastic.co/t/nested-grok-filter-or-filtering-a-field-using-grok/100841 "2017-09-18T09:26:33Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![kumar.1989p](https://avatars.discourse-cdn.com/v4/letter/k/82dd89/32.png) [@kumar.1989p](https://discuss.elastic.co/u/kumar.1989p)
#### Post date: [September 18, 2017, 9:26am UTC](https://discuss.elastic.co/t/nested-grok-filter-or-filtering-a-field-using-grok/100841/1 "2017-09-18T09:26:33Z")

</div>

Hello,

So I have a CommonApache access log format in the below form:

> 8.6.7.9 - - [10/Sep/2017:05:17:11 +0000] "POST /integration/servletloadserviceupdate HTTP/1.0" 200 9157

So I have used the below filter:

```auto
filter {
 grok {
    match => { "message" => ["%{COMMONAPACHELOG}"]} 
  }
  
 mutate {
    remove_field => ["ident", "auth"]
  } 
 }

```

There is a field called [apache2].[access].[url], which basically contains this:

> /integration/clearcase/listpatchtobedone.jsp

I need to split this, and create a new field with name "application" and with value "clearcase" (taken from the above URL)

I have arrived at this as the second last element from the URL taking / as delimiters.

So my question is, is this possible ? Maybe with a second grok right below the first one that matches the URL field. In this case, how is it done exactly ?

I am using the complete stack of v5.5.

Regards,  
pavan

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [September 18, 2017, 11:35am UTC](https://discuss.elastic.co/t/nested-grok-filter-or-filtering-a-field-using-grok/100841/2 "2017-09-18T11:35:29Z")

</div>

Untested:

```nohighlight
grok {
  match => ["[apache2][access][url]", "/(?<application>[^/]+)/[^/]+$"]
}

```

---

<div class="post-metadata">

### Author: ![kumar.1989p](https://avatars.discourse-cdn.com/v4/letter/k/82dd89/32.png) [@kumar.1989p](https://discuss.elastic.co/u/kumar.1989p)
#### Post date: [September 19, 2017, 9:50am UTC](https://discuss.elastic.co/t/nested-grok-filter-or-filtering-a-field-using-grok/100841/3 "2017-09-19T09:50:02Z")

</div>

Hi Magnus,

Thank you very much for your quick reply.

So now, I'm trying to change the `@timestamp` to the `timestamp` present in my log.

My log is as below:

> 0.0.0.0 - - [20/Sep/2017:06:10:57 +0000] "GET /integration/spin/SWAT/scenario/launchShoot.jsp HTTP/1.0" 200 16184

This is the response i see on Kibana:

```auto
{
  "_index": "test",
  "_type": "log",
  "_id": "someid123456-olK",
  "_version": 1,
  "_score": null,
  "_source": {
    "request": "/integration/spin/SWAT/scenario/launchShoot.jsp",
    "offset": 73886,
    "input_type": "log",
    "verb": "GET",
    "source": "\\\\localhost\\ETV_G\\logs\\wls\\intranet\\intranetNode03\\system\\access.log",
    "message": "0.0.0.0 - - [20/Sep/2017:06:10:57 +0000] \"GET /integration/spin/SWAT/scenario/launchShoot.jsp HTTP/1.0\" 200 16184 ",
    "type": "log",
    "tags": [
      "beats_input_codec_plain_applied",
      "_dateparsefailure"
    ],
    "@timestamp": "2017-09-20T06:20:24.283Z",
    "response": "200",
    "bytes": "16184",
    "clientip": "0.0.0.0",
    "@version": "1",
    "beat": {
      "hostname": "localhost",
      "name": "localhost",
      "version": "5.5.2"
    },
    "host": "localhost",
    "httpversion": "1.0",
    "timestamp": "20/Sep/2017:06:10:57 +0000"
  },
  "fields": {
    "@timestamp": [
      1505888424283
    ]
  },
  "sort": [
    1505888424283
  ]
}

```

I tried the below filter, the @timestamp is still different from the log timestamp.

```auto
input {
  beats {
    port => 5044
    host => "0.0.0.0"
  }
}

# The filter part of this file is commented out to indicate that it is
# optional.
filter {
 grok {
    match => { "message" => ["%{COMMONAPACHELOG}"]} 
    #remove_field => ["message","@timestamp"]
  }

   date {
    match => ["timestamp", "dd/MMM/yyyy:HH:mm:ss +Z"]
    target => ["@timestamp"]
    }
  
  #geoip {
   # source => "clientip"
  #}

 mutate {
    remove_field => ["ident", "auth"]
  } 
 }

output {
	#stdout { codec => rubydebug }
  elasticsearch {
    hosts => "localhost:9200"
    action => "index"
    index => "test"
  }
}

```

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [September 19, 2017, 11:49am UTC](https://discuss.elastic.co/t/nested-grok-filter-or-filtering-a-field-using-grok/100841/4 "2017-09-19T11:49:57Z")

</div>

The Kibana result above, is that with the date filter above?

---

<div class="post-metadata">

### Author: ![kumar.1989p](https://avatars.discourse-cdn.com/v4/letter/k/82dd89/32.png) [@kumar.1989p](https://discuss.elastic.co/u/kumar.1989p)
#### Post date: [September 20, 2017, 6:27am UTC](https://discuss.elastic.co/t/nested-grok-filter-or-filtering-a-field-using-grok/100841/5 "2017-09-20T06:27:23Z")

</div>

Hi again Magnus,

Sorry for the late reply, and my mistake.

I have now edited the above post with the exact info that my server has, and is giving me.

Looks like Logstash is saying there is a date parse failure. Not sure, what I'm doing wrong.

Regards,  
Pavan

---

<div class="post-metadata">

### Author: ![kumar.1989p](https://avatars.discourse-cdn.com/v4/letter/k/82dd89/32.png) [@kumar.1989p](https://discuss.elastic.co/u/kumar.1989p)
#### Post date: [September 20, 2017, 7:00am UTC](https://discuss.elastic.co/t/nested-grok-filter-or-filtering-a-field-using-grok/100841/6 "2017-09-20T07:00:27Z")

</div>

Hi Magnus,

I think it is loading correctly. I hadn't realized the time difference between the server and my machine where I was accessing the kibana on browser.

However, I see a `_dateparsefailure` tag being added in the resulting json. Can you please help me debug that?

Regards,  
Pavan

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [October 18, 2017, 7:00am UTC](https://discuss.elastic.co/t/nested-grok-filter-or-filtering-a-field-using-grok/100841/7 "2017-10-18T07:00:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
