# Not able to understand this grok filter for a particular code

**URL:** <https://discuss.elastic.co/t/not-able-to-understand-this-grok-filter-for-a-particular-code/187050>\
**Category:** Logstash\
**Created:** [June 24, 2019, 5:53am UTC](https://discuss.elastic.co/t/not-able-to-understand-this-grok-filter-for-a-particular-code/187050 "2019-06-24T05:53:15Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![deepanshu\_goel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/deepanshu_goel/32/48061_2.png) [@deepanshu\_goel](https://discuss.elastic.co/u/deepanshu_goel)\
**Post date:** [June 24, 2019, 5:53am UTC](https://discuss.elastic.co/t/not-able-to-understand-this-grok-filter-for-a-particular-code/187050/1 "2019-06-24T05:53:15Z")

</div>

Here ,i am using a log file but i am not able to understand why the grok is working can anyone please explain me this .  
MY ACCESS LOG IS:-  
184.252.108.229 - - [20/Sep/2017:13:22:22 +0200] "GET /css/style.css HTTP/1.1" 200 11679 "[https://codingexplained.com/products/view/123](https://codingexplained.com/products/view/123)" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.90 Safari/537.36"

AND THE CONFIGURATION FILE WHICH I AM USING IS:-  
input  
{  
file {

```
 path=>"E:/kibana/logstash-7.1.1/logstash-7.1.1/data/event-data/apache_access.log"
    type => "apache-access" 
 start_position => "beginning"
       
     }              	

```

http {  
host =\> "127.0.0.1"  
port =\> 8080  
}  
}

filter  
{

```
    **grok{**

```

\*\* match =\> { "message" =\> '%{HTTPD\_COMMONLOG} "%{GREEDYDATA:referrer}" "%{GREEDYDATA:agent}"' } \*\*

\*\* }\*\*  
}  
output  
{

stdout{

```
      codec=>rubydebug  
   
    } 

```

}  
(PLEASE HELP ME OUT OF THIS)

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [June 24, 2019, 12:28pm UTC](https://discuss.elastic.co/t/not-able-to-understand-this-grok-filter-for-a-particular-code/187050/2 "2019-06-24T12:28:30Z")

</div>

HTTPD\_COMMONLOG is a pattern defind in the logstash core: [https://github.com/logstash-plugins/logstash-patterns-core/blob/master/patterns/httpd](https://github.com/logstash-plugins/logstash-patterns-core/blob/master/patterns/httpd) (More patterns can be found [here](https://github.com/logstash-plugins/logstash-patterns-core/tree/master/patterns))

So basically this is the resolved complete pattern:  
%{IPORHOST:clientip} %{HTTPDUSER:ident} %{HTTPDUSER:auth} [%{HTTPDATE:timestamp}] "(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})" %{NUMBER:response} (?:%{NUMBER:bytes}|-) "%{GREEDYDATA:referrer}" "%{GREEDYDATA:agent}"

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 22, 2019, 12:28pm UTC](https://discuss.elastic.co/t/not-able-to-understand-this-grok-filter-for-a-particular-code/187050/3 "2019-07-22T12:28:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
