# Parsing a log with colon separated fields

**URL:** <https://discuss.elastic.co/t/parsing-a-log-with-colon-separated-fields/67433>\
**Category:** Logstash\
**Created:** [November 29, 2016, 5:12am UTC](https://discuss.elastic.co/t/parsing-a-log-with-colon-separated-fields/67433 "2016-11-29T05:12:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![verno\_s](https://avatars.discourse-cdn.com/v4/letter/v/e19adc/32.png) [@verno\_s](https://discuss.elastic.co/u/verno_s)\
**Post date:** [November 29, 2016, 5:12am UTC](https://discuss.elastic.co/t/parsing-a-log-with-colon-separated-fields/67433/1 "2016-11-29T05:12:19Z")

</div>

Hi,

I've tried to read the Logstash docs on grok parsing but i can't find an answer to my issue.

I want to parse a : separated logfile e.g.

29/11/2016 11:49:17 AM : Response: 125 Data connection already open; Transfer starting.  
29/11/2016 11:54:18 AM : Response: 226 Transfer complete.  
29/11/2016 11:54:18 AM : Command : PWD

If i use the following match statement the hours and minutes from the timestamp are mistakenly parsed as fields.

:%{DATA:log\_timestamp}:%{DATA:action}:%{GREEDYDATA:message}

Output from grokconstructor:

MATCHED  
log\_timestamp 49  
action 17·AM·  
message ·Response:·125·Data·connection·already·open;·Transfer·starting.  
before match: 29/11/2016 11  
29/11/2016 11:54:18 AM : Response: 226 Transfer complete.  
MATCHED  
log\_timestamp 54  
action 18·AM·  
message ·Response:·226·Transfer·complete.  
before match: 29/11/2016 11  
29/11/2016 11:54:18 AM : Command : PWD  
MATCHED  
log\_timestamp 54  
action 18·AM·  
message ·Command·:·PWD  
before match: 29/11/2016 11

I would like the the following result, what is the best way to do this, is it to create a custom pattern?

log\_timestamp 29/11/2016 11:49:17 AM  
action Response  
message 125 Data connection already open; Transfer starting.

Many thanks,

Scott

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 29, 2016, 7:19am UTC](https://discuss.elastic.co/t/parsing-a-log-with-colon-separated-fields/67433/2 "2016-11-29T07:19:07Z")

</div>

Using more than one DATA or GREEDYDATA in the same expression is asking for trouble. Use more specific patterns for matching the timestamp. The grok constructor web site should be able to help with suggestions. For example, you can use `%{DATE_EU} %{TIME}` to match the timestamp (except AM/PM).

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 29, 2016, 7:44am UTC](https://discuss.elastic.co/t/parsing-a-log-with-colon-separated-fields/67433/3 "2016-11-29T07:44:03Z")

</div>

Based on the log entries you presented, it looks like the fields are actually separated by`' : '` and not just a`':'`. If you add these spaces I suspect your expression should work. Finding more specific patterns than DATA would however as Magnus suggests improve parsing.

---

<div class="post-metadata">

**Author:** ![verno\_s](https://avatars.discourse-cdn.com/v4/letter/v/e19adc/32.png) [@verno\_s](https://discuss.elastic.co/u/verno_s)\
**Post date:** [November 29, 2016, 11:53pm UTC](https://discuss.elastic.co/t/parsing-a-log-with-colon-separated-fields/67433/4 "2016-11-29T23:53:04Z")

</div>

Thanks guys! Much appreciated. I have modified the delimiter to be ' : ' (with spaces) I've also changed one of the DATA's to a WORD and will investigate using more specific patterns to match the date.

Thanks again for the quick suggestions.

Scott

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 27, 2016, 11:53pm UTC](https://discuss.elastic.co/t/parsing-a-log-with-colon-separated-fields/67433/5 "2016-12-27T23:53:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
