# Parsing grok

**URL:** <https://discuss.elastic.co/t/parsing-grok/182248>\
**Category:** Logstash\
**Created:** [May 22, 2019, 2:16pm UTC](https://discuss.elastic.co/t/parsing-grok/182248 "2019-05-22T14:16:51Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![angie](https://avatars.discourse-cdn.com/v4/letter/a/ec9cab/32.png) [@angie](https://discuss.elastic.co/u/angie)\
**Post date:** [May 22, 2019, 2:16pm UTC](https://discuss.elastic.co/t/parsing-grok/182248/1 "2019-05-22T14:16:51Z")

</div>

I'm using logstash 6.6.0 and I would like to convert this value: "[34mems\_1 |[0m" for this: "ems".

I look forward to hearing from you

---

<div class="post-metadata">

**Author:** ![BennyInc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bennyinc/32/21751_2.png) [@BennyInc](https://discuss.elastic.co/u/BennyInc)\
**Post date:** [May 22, 2019, 2:43pm UTC](https://discuss.elastic.co/t/parsing-grok/182248/2 "2019-05-22T14:43:31Z")

</div>

Hi Angie,

not knowing what possible other values look like, I would say something like  
`"^\[34m%{DATA:myvalue}_1"`  
would work.

You might want to use the Grok Debugger in Kibana to test.

---

<div class="post-metadata">

**Author:** ![angie](https://avatars.discourse-cdn.com/v4/letter/a/ec9cab/32.png) [@angie](https://discuss.elastic.co/u/angie)\
**Post date:** [May 23, 2019, 6:24am UTC](https://discuss.elastic.co/t/parsing-grok/182248/3 "2019-05-23T06:24:40Z")

</div>

Thx for quick answer.  
Actually, the problem is more complicated. Below is my messages, which is very irregular:

[32;1mems\_1 |[0m 2019-05-23 08:09:16.764 DEBUG 41 --- [main] e.m.event.brokercep.cep.CepService : CepService.addAggregatorFunction(): function=EVALAGG, aggregator-factory-class=.cep.CepEvalAggregatorFactory

and

[34mdlmswebservice\_1 |[0m 2019-05-23 08:09:10.444 DEBUG 41 --- [main] org.hibernate.type.EnumType : Using ORDINAL-based conversion for Enum DataSourceType

I use grok debugger  
grok{  
match =\> {"message"=\> "%{GREEDYDATA:logger-name} %{TIMESTAMP\_ISO8601:timestamp} %{LOGLEVEL:log-level} %{GREEDYDATA:info}" }  
overwrite =\> ["message"]  
}

and it looks quite okey, beside first value.

Do you have any advice for me in this case?

Thanks in advance

---

<div class="post-metadata">

**Author:** ![BennyInc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bennyinc/32/21751_2.png) [@BennyInc](https://discuss.elastic.co/u/BennyInc)\
**Post date:** [May 23, 2019, 10:53am UTC](https://discuss.elastic.co/t/parsing-grok/182248/4 "2019-05-23T10:53:43Z")

</div>

Your pattern already extracts the first part into logger-name, which is good to know.  
The surrounding characters are basically from Bash Coloring, which you would need to remove, first.

You can either include it in your grok pattern like I posted before, or you could use a mutate to remove them, like in this sample: [https://gist.github.com/pauloconnor/4707710](https://gist.github.com/pauloconnor/4707710)

I'm not sure whether the Escape-Character would need to be included, but this StackOverflow question has some input, possibly: [https://stackoverflow.com/questions/33440366/grok-pattern-to-parse-the-esc-key](https://stackoverflow.com/questions/33440366/grok-pattern-to-parse-the-esc-key)

---

<div class="post-metadata">

**Author:** ![BennyInc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bennyinc/32/21751_2.png) [@BennyInc](https://discuss.elastic.co/u/BennyInc)\
**Post date:** [May 23, 2019, 10:55am UTC](https://discuss.elastic.co/t/parsing-grok/182248/5 "2019-05-23T10:55:18Z")

</div>

Adapting the gist I linked to your output:

```auto
mutate {
  gsub => ["logger-name", "\x1B\[([0-9]{1,2}(;[0-9]{1,2})?)?[m|K]", ""]
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 20, 2019, 10:55am UTC](https://discuss.elastic.co/t/parsing-grok/182248/6 "2019-06-20T10:55:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
