# Nested repeating group

**URL:** https://discuss.elastic.co/t/nested-repeating-group/213638
**Category:** Logstash
**Created:** [January 3, 2020, 12:26am UTC](https://discuss.elastic.co/t/nested-repeating-group/213638 "2020-01-03T00:26:02Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [January 3, 2020, 4:52pm UTC](https://discuss.elastic.co/t/nested-repeating-group/213638/2 "2020-01-03T16:52:50Z")

</div>

I would use ruby

```
    grok { match => { "message" => "%{TIMESTAMP_ISO8601:time} : %{GREEDYDATA:username} %{SYSLOG5424SD:usertype}%{GREEDYDATA:[@metadata][restOfLine]}" } }
    mutate { gsub => ["[@metadata][restOfLine]", "\r", "" ] }
    mutate { gsub => ["usertype", "[\[\]]", "" ] }
    ruby {
        code => "
            data = event.get('[@metadata][restOfLine]')
            matches = data.scan(/\n(\S+)\n\s+RED\s+: ([0-9]+)\n\s+BLUE\s+: ([0-9]+)\n\s+GREEN\s+: ([0-9]+)/)
            groups = []
            matches.each_index { |x|
                group = { 'name' => matches[x][0], 'red' => matches[x][1], 'blue' => matches[x][2], 'green' => matches[x][3] }
                groups << group
            }
            event.set('groups', groups)
        "
    }

```

You may not need the first mutate. And I assume you want red/blue/green, not red/blue/blue, which you cannot have.

---

_[View the full topic](https://discuss.elastic.co/t/nested-repeating-group/213638)._
