# Parse and ingest email files using logstack -- help needed

**URL:** <https://discuss.elastic.co/t/parse-and-ingest-email-files-using-logstack-help-needed/119141>\
**Category:** Logstash\
**Created:** [February 8, 2018, 11:35pm UTC](https://discuss.elastic.co/t/parse-and-ingest-email-files-using-logstack-help-needed/119141 "2018-02-08T23:35:26Z")\
**Posts on this page:** 1\
**Showing post:** 10

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 9, 2018, 9:21pm UTC](https://discuss.elastic.co/t/parse-and-ingest-email-files-using-logstack-help-needed/119141/10 "2018-02-09T21:21:30Z")

</div>

> [@abildgaard](#):
>
> match =\> { "message" =\> "Date: (?\<date\>.\*(?=(\nFrom:)))" }

There are no fancy quoting or escaping features in logstash configs 🙂 Try this, with a literal newline embedded in the string

```
grok {
    match => { "message" => "Date: (?<date>.*)
From: " }
  }
```

Note that using .\* sometimes grabs a lot more than you want. These two variants may help you understand what it is doing. The first one says .\* followed by a newline, which ends up consuming the entire message. The second says not-newline followed by a newline, which consumes the rest of the line. If the order of headers ever varies, you will need this one.

```
grok {
    match => { "message" => "Date: (?<date1>.*)
" }
  }
  grok {
    match => { "message" => "Date: (?<date2>[^
]*)
" }
  }
```

---

_[View the full topic](https://discuss.elastic.co/t/parse-and-ingest-email-files-using-logstack-help-needed/119141)._
