# Passing custom regex inside grok filter

**URL:** <https://discuss.elastic.co/t/passing-custom-regex-inside-grok-filter/261907>\
**Category:** Logstash\
**Created:** [January 22, 2021, 11:15am UTC](https://discuss.elastic.co/t/passing-custom-regex-inside-grok-filter/261907 "2021-01-22T11:15:33Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Flavio1](https://avatars.discourse-cdn.com/v4/letter/f/cab0a1/32.png) [@Flavio1](https://discuss.elastic.co/u/Flavio1)\
**Post date:** [January 22, 2021, 11:15am UTC](https://discuss.elastic.co/t/passing-custom-regex-inside-grok-filter/261907/1 "2021-01-22T11:15:33Z")

</div>

Hi everybody,  
During these days i'm trying to implement a custom regex system configuration in order to have a single point, outside pipelines, in which i can make crud operations on regexes. I tried this solution:

```
mutate {
            add_field => {
                          "regex_status" => "specific_status"                        
                          "default_status" => "default_status"
            }
        }       
        translate {
            field => "regex_status"
            destination => "[regex_data]"
            dictionary_path => "C:/lookup-regex.json"
            add_field => { "status_exists" => "true" }
        }
        if ([status_exists] == "true") {
          grok {
             match => ["message", "%{[regex_data][status]}" ]
          }
        }
        else{
          translate {
                field => "default_timestamp"
                destination => "[regex_data]"
                dictionary_path => "c:/lookup-regex.json"   
          }

```

and this is the lookup-regex.json:

```
{
    "default_status":".*HTTPv2.0\\/\\d\\.\\d\\\"\\s(?<status>\\d{3})\\s",
    "specific_status": {
        "status":".*HTTP\\/\\d\\.\\d\\\"\\s(?<status>\\d{3})\\s"
    }
}

```

It seems that during the parsing of the pipeline the logstash debugger gives me that pipeline stop worked because %{[regex\_data][status]} it's not a regex. Is this any way to accomplish this behaviour? Essentialy, i would like to know if i can pass string of regex like variable in grok filters. Thx in advance.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 22, 2021, 11:49am UTC](https://discuss.elastic.co/t/passing-custom-regex-inside-grok-filter/261907/2 "2021-01-22T11:49:24Z")

</div>

I'm not sure if this approach would work and it seems overcomplicated when you compare with the approach in the [documentation](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html#_custom_patterns) to use custom patterns.

You could try putting your custom regex expressions in a file and use the `patterns_dir` option in your grok filter.

For example, you could create a file named `CUSTOM-REGEX` with the following content.

```auto
DEFAULTSTATUS .*HTTPv2.0\\/\\d\\.\\d\\\"\\s(?<status>\\d{3})\\s
SPECIFICSTATUS .*HTTP\\/\\d\\.\\d\\\"\\s(?<status>\\d{3})\\s

```

Then you would use this file in your grok config.

```auto
grok {
    patterns_dir => ["/path/to/your/custom/regex/file"]
    match => { "message", "%{DEFAULTSTATUS:field_name}" }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 19, 2021, 11:49am UTC](https://discuss.elastic.co/t/passing-custom-regex-inside-grok-filter/261907/3 "2021-02-19T11:49:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
