# Overwrite message field issue in grok match

**URL:** <https://discuss.elastic.co/t/overwrite-message-field-issue-in-grok-match/259300>\
**Category:** Logstash\
**Created:** [December 21, 2020, 8:22pm UTC](https://discuss.elastic.co/t/overwrite-message-field-issue-in-grok-match/259300 "2020-12-21T20:22:34Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Muhammad\_Faisal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/muhammad_faisal/32/79213_2.png) [@Muhammad\_Faisal](https://discuss.elastic.co/u/Muhammad_Faisal)\
**Post date:** [December 21, 2020, 8:22pm UTC](https://discuss.elastic.co/t/overwrite-message-field-issue-in-grok-match/259300/1 "2020-12-21T20:22:34Z")

</div>

i want to overwrite message field , but it only overwrites last match i.e. IP and is not overwriting first match i.e. number

`input {  
stdin{}  
}

`filter {`  
`grok {`  
`match => { "message" => "%{DATA}(?<message>(\d{9,12})|(\d{9,12}))%{GREEDYDATA}%{IPV4:message}%{GREEDYDATA}" }`  
`overwrite => ["message"]`  
}  
}

output {  
stdout {  
codec =\> "rubydebug"  
}  
}`

input log  
31438214312 Info:node indicated exception at 10.20.30.11

output :  
{  
"@version" =\> "1",

```
"@timestamp" => 2020-12-21T10:08:13.061Z,
   "message" => "10.20.30.11"

```

}

i want to get  
"message" =\> "31438214312", "10.20.30.11"

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 21, 2020, 9:17pm UTC](https://discuss.elastic.co/t/overwrite-message-field-issue-in-grok-match/259300/2 "2020-12-21T21:17:58Z")

</div>

Well you have told it to overwrite the [message] field, so the "10.20.30.11" overwrites the "31438214312" value. You could use

```
    grok { match => { "message" => "(?<[@metadata][message]>(\d{9,12})|(\d{9,12}))%{GREEDYDATA}%{IPV4:[@metadata][message]}" } }
    mutate { rename => { "[@metadata][message]" => "message" } }

```

Note that the leading %{DATA} and trailing %{GREEDYDATA} in your pattern do nothing, and you can remove them to simplify the pattern.

---

<div class="post-metadata">

**Author:** ![Muhammad\_Faisal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/muhammad_faisal/32/79213_2.png) [@Muhammad\_Faisal](https://discuss.elastic.co/u/Muhammad_Faisal)\
**Post date:** [December 22, 2020, 7:22am UTC](https://discuss.elastic.co/t/overwrite-message-field-issue-in-grok-match/259300/3 "2020-12-22T07:22:40Z")

</div>

thank you badger...can you explain little bit more ...for example, if i test input string in grok debugger it shows me output as that number and IP are part of message field as array......then ,next i am overwriting message field (which means , stdin.... i.e. "31438214312 Info:node indicated exception at 10.20.30.11" )......so message field shall be overwritten which grok debugger shows .

"message": [  
[  
"31438214312"  
],  
[  
"10.20.30.11"  
]  
],

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 22, 2020, 2:22pm UTC](https://discuss.elastic.co/t/overwrite-message-field-issue-in-grok-match/259300/4 "2020-12-22T14:22:03Z")

</div>

The grok debugger is not grok and does not always do exactly what a grok filter will do.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 19, 2021, 2:22pm UTC](https://discuss.elastic.co/t/overwrite-message-field-issue-in-grok-match/259300/5 "2021-01-19T14:22:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
