# Parsing dynamically using Logstash grok pattern(custom pattern)

**URL:** <https://discuss.elastic.co/t/parsing-dynamically-using-logstash-grok-pattern-custom-pattern/223450>\
**Category:** Logstash\
**Created:** [March 13, 2020, 5:36am UTC](https://discuss.elastic.co/t/parsing-dynamically-using-logstash-grok-pattern-custom-pattern/223450 "2020-03-13T05:36:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![judragon\_dark](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/judragon_dark/32/64378_2.png) [@judragon\_dark](https://discuss.elastic.co/u/judragon_dark)\
**Post date:** [March 13, 2020, 5:36am UTC](https://discuss.elastic.co/t/parsing-dynamically-using-logstash-grok-pattern-custom-pattern/223450/1 "2020-03-13T05:36:41Z")

</div>

Below is the code for the logstash filter.  
MYCUSTOMPATTERN is a custom pattern defined in ssk-patterns.

```
filter {
    grok {
            patterns_dir => ["/etc/logstash/patterns/ssk-patterns"]
            match => {"message" => "%{MYCUSTOMPATTERN}"}
    }
 }

```

but, I want to apply different patterns to multiple filebeats.

So this is the modified code.

```
filter {
    if [fields][log_type] == '1' {
            grok {
                   patterns_dir => ["/etc/logstash/patterns/ssk-patterns"]
                   match => {"message" => "%{MYCUSTOMPATTERN}"}
            }
    }
    else if [fields][log_type] == '2' {
            grok {
                   patterns_dir => ["/etc/logstash/patterns/ssk-patterns"]
                   match => {"message" => "%{MYCUSTOMPATTERN2}"}
            }      
    }
    .....
    .....
    .....
}

```

[log\_type] is the field data sent by filebeat.

Without using the above method.

```
filter {
    grok {
            patterns_dir => ["/etc/logstash/patterns/ssk-patterns"]
            match => {"message" => "%{[fields][log_type]}"}
    }
}

```

This code doesn't work.  
Is there a way to behave dynamically with this simple code?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 13, 2020, 6:00pm UTC](https://discuss.elastic.co/t/parsing-dynamically-using-logstash-grok-pattern-custom-pattern/223450/2 "2020-03-13T18:00:11Z")

</div>

> [@judragon\_dark](#):
>
> This code doesn't work.

What do you mean by that? There are an infinite number of ways in which it could not work, you cannot expect us to correctly guess which one of them is occurring.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 10, 2020, 6:00pm UTC](https://discuss.elastic.co/t/parsing-dynamically-using-logstash-grok-pattern-custom-pattern/223450/3 "2020-04-10T18:00:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
