# Parsing a message after the pattern

**URL:** <https://discuss.elastic.co/t/parsing-a-message-after-the-pattern/76246>\
**Category:** Logstash\
**Created:** [February 23, 2017, 2:55pm UTC](https://discuss.elastic.co/t/parsing-a-message-after-the-pattern/76246 "2017-02-23T14:55:19Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![cisaksen](https://avatars.discourse-cdn.com/v4/letter/c/49beb7/32.png) [@cisaksen](https://discuss.elastic.co/u/cisaksen)\
**Post date:** [February 23, 2017, 2:55pm UTC](https://discuss.elastic.co/t/parsing-a-message-after-the-pattern/76246/1 "2017-02-23T14:55:19Z")

</div>

New to logstash -

I'm trying to add a field that contains the http host value ([http://host.domin.com/](http://host.domin.com/)).

I have the combinedlog pattern to match the "message" field and now I'm trying to use the addfield but i don't know how to reference the pattern field referrer within the addfield command.

addfield =\> ["httphost" =\> pattern field %{referrer} regex: ^http://._/._?$]

I don't know the correct syntax for applying a regex to a field derived from the match pattern.  
thanks

---

<div class="post-metadata">

**Author:** ![lueneburger](https://avatars.discourse-cdn.com/v4/letter/l/f475e1/32.png) [@lueneburger](https://discuss.elastic.co/u/lueneburger)\
**Post date:** [February 24, 2017, 8:22am UTC](https://discuss.elastic.co/t/parsing-a-message-after-the-pattern/76246/2 "2017-02-24T08:22:16Z")

</div>

Hi cisaksen,

```
	grok {
		match => ["message", "(?<httphost>^http://./.?$) "]
    	        }

```

? will add the new field with the regex you define behind it, like shown above

---

<div class="post-metadata">

**Author:** ![cisaksen](https://avatars.discourse-cdn.com/v4/letter/c/49beb7/32.png) [@cisaksen](https://discuss.elastic.co/u/cisaksen)\
**Post date:** [February 28, 2017, 8:04pm UTC](https://discuss.elastic.co/t/parsing-a-message-after-the-pattern/76246/3 "2017-02-28T20:04:57Z")

</div>

Not sure I'm getting this right.

Can I have 2 match commands on the message

```
grok { 
      match => { "message" => "%{SED_NGINX_COMBINE}" }	
      match => ["message", "(?<httphost>^http://./.?$) "]
        }
```

---

<div class="post-metadata">

**Author:** ![cisaksen](https://avatars.discourse-cdn.com/v4/letter/c/49beb7/32.png) [@cisaksen](https://discuss.elastic.co/u/cisaksen)\
**Post date:** [March 2, 2017, 3:02pm UTC](https://discuss.elastic.co/t/parsing-a-message-after-the-pattern/76246/4 "2017-03-02T15:02:07Z")

</div>

I'm trying to use the pattern file method. Can I have multiple pattern definitions in a single file or is it 1 pattern definition per file ?

in side the pattern file

> SED\_HTTPHOST ^http://./.?$

then in the grok statement

> match =\> { "message" =\> "%{SED\_NGINX\_COMBINE} %{SED\_HTTPHOST:httphost}" }

SED\_NGINX\_COMBINED is also defined in the pattern file.

should this work ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 30, 2017, 3:02pm UTC](https://discuss.elastic.co/t/parsing-a-message-after-the-pattern/76246/5 "2017-03-30T15:02:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
