# Parsing IRC Logs

**URL:** <https://discuss.elastic.co/t/parsing-irc-logs/356574>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [April 1, 2024, 6:35pm UTC](https://discuss.elastic.co/t/parsing-irc-logs/356574 "2024-04-01T18:35:16Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![moep](https://avatars.discourse-cdn.com/v4/letter/m/ad7895/32.png) [@moep](https://discuss.elastic.co/u/moep)\
**Post date:** [April 1, 2024, 6:35pm UTC](https://discuss.elastic.co/t/parsing-irc-logs/356574/1 "2024-04-01T18:35:16Z")

</div>

Im running an ELK-Stack in Docker and my goal is, to parse and filter my IRC logs, for learning.

```auto
2024-04-01 20:25:02 me foo
2024-04-01 20:25:46 me bar

```

I found some logstash related stuff on [Github](https://gist.github.com/fastjack/86c4151ad3b27b402c72ff3b4c54c3e9). I guess the input and output part is similar, but I don't understand the filter related part. Do you have maybe some suggestions? I mean it's some years old.

thx  
moep

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [April 1, 2024, 7:43pm UTC](https://discuss.elastic.co/t/parsing-irc-logs/356574/2 "2024-04-01T19:43:39Z")

</div>

You can check the configuration examples from the [documentation](https://www.elastic.co/guide/en/logstash/current/config-examples.html) to understand how logstash works.

And then the filters [documentation](https://www.elastic.co/guide/en/logstash/current/filter-plugins.html) to see which filters are available.

How you will parse depends on what you want to do with the data and how the message looks like.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [April 2, 2024, 1:17pm UTC](https://discuss.elastic.co/t/parsing-irc-logs/356574/3 "2024-04-02T13:17:12Z")

</div>

Few more tips:

- [Do you grok Grok? | Elastic Blog](https://www.elastic.co/blog/do-you-grok-grok)
- IRC grok pattern is simple: timestamp, username, message. Can be something like this: `%{TIMESTAMP_ISO8601:timestamp}\s+%{NOTSPACE:username}\s+%{GREEDYDATA:ircmessage}`
- in your case csv and dissect are also suitable for use

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 30, 2024, 1:17pm UTC](https://discuss.elastic.co/t/parsing-irc-logs/356574/4 "2024-04-30T13:17:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
