# Please, I need help with grok patterns

**URL:** <https://discuss.elastic.co/t/please-i-need-help-with-grok-patterns/218246>\
**Category:** Logstash\
**Created:** [February 6, 2020, 7:51pm UTC](https://discuss.elastic.co/t/please-i-need-help-with-grok-patterns/218246 "2020-02-06T19:51:30Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 6, 2020, 8:24pm UTC](https://discuss.elastic.co/t/please-i-need-help-with-grok-patterns/218246/2 "2020-02-06T20:24:08Z")

</div>

When I run

```
input { generator { count => 1 lines => [ 'Output: Export (1)
Export name: test123
Export file format: salesforce
Amount requested: 1

Last balance: 43087128
Current balance: 43087127

Searched fields and terms:
    Identifiers: 04475444000129

' ] } }
filter {
    grok {
        match => {
            "message" => "Output: %{DATA:output}\\nExport name: %{DATA:export_name}\\nExport file format: %{DATA:export_file_format}\\nAmount requested: %{DATA:amount_requested}\\n\\nLast balance: %{DATA:last_balance}\\nCurrent balance: %{DATA:current_balance}\\n\\nSearched fields and terms: %{DATA:search}\\n\\tIdentifiers: %{DATA:identifiers}\\n%{GREEDYDATA}"
        }
    }
}
output { stdout { codec => rubydebug { metadata => false } } }

```

It works fine for me...

```
       "identifiers" => "04475444000129",
"export_file_format" => "salesforce",
       "export_name" => "test123",

```

etc. I suggest you read [this](https://discuss.elastic.co/t/help-needed-in-grok/213827/2).

---

_[View the full topic](https://discuss.elastic.co/t/please-i-need-help-with-grok-patterns/218246)._
