# Q. grok filter pattern

**URL:** <https://discuss.elastic.co/t/q-grok-filter-pattern/148731>\
**Category:** Logstash\
**Created:** [September 16, 2018, 3:35am UTC](https://discuss.elastic.co/t/q-grok-filter-pattern/148731 "2018-09-16T03:35:14Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![jeongsyhd](https://avatars.discourse-cdn.com/v4/letter/j/f17d59/32.png) [@jeongsyhd](https://discuss.elastic.co/u/jeongsyhd)\
**Post date:** [September 16, 2018, 3:35am UTC](https://discuss.elastic.co/t/q-grok-filter-pattern/148731/1 "2018-09-16T03:35:15Z")

</div>

I created a filter as shown below.  
There are three types of logs, so there are three patterns.  
log A can use the message if "action" in [message].  
But what about log B and log C ?

log A: sip = 1.1.1.1 dip = 2.2.2.2 sport = 100 dport = 200 action = permit  
log B: sip = 1.1.1.1 dip = 2.2.2.2 sport = 100 dport = 200 attack = 10.10.10.10  
log C: sip = 1.1.1.1 dip = 2.2.2.2 attack = 10.10.10.10

filter {

```
  #log A
  if "action" in [message]
  {
           grok {match => {"message" => "grok_pattern_A"}}
  }

  #log B
  else if "???" in [message]
  {
           grok {match => {"message" => "grok_pattern _B"}}
  }

  #log C
  else if "???" in [message]
  {
           grok {match => {"message" => "grok_pattern _C"}}
  }

```

}

Thank you in advance.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 16, 2018, 4:43am UTC](https://discuss.elastic.co/t/q-grok-filter-pattern/148731/2 "2018-09-16T04:43:56Z")

</div>

Parse our the full part that contains key-value pairs using grok or dissect and then use the kv filter to parse this, not grok.

---

<div class="post-metadata">

**Author:** ![jeongsyhd](https://avatars.discourse-cdn.com/v4/letter/j/f17d59/32.png) [@jeongsyhd](https://discuss.elastic.co/u/jeongsyhd)\
**Post date:** [September 16, 2018, 6:52am UTC](https://discuss.elastic.co/t/q-grok-filter-pattern/148731/3 "2018-09-16T06:52:23Z")

</div>

Can you show an example using the above log?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 16, 2018, 11:03am UTC](https://discuss.elastic.co/t/q-grok-filter-pattern/148731/4 "2018-09-16T11:03:56Z")

</div>

I meant something like this:

```auto
input {
  generator {
    lines => ['log A: sip = 1.1.1.1 dip = 2.2.2.2 sport = 100 dport = 200 action = permit',
              'log B: sip = 1.1.1.1 dip = 2.2.2.2 sport = 100 dport = 200 attack = 10.10.10.10',
              'log C: sip = 1.1.1.1 dip = 2.2.2.2 attack = 10.10.10.10']
    count => 1
  } 
} 

filter {
  dissect {
    mapping => {
      "message" => "%{initial_part}: %{kvpart}"
    }
  }

  mutate {
    gsub => ["kvpart", " = ", "="]
  }

  kv {
    source => "kvpart"
  }
}

output {
  stdout { codec => rubydebug }
}

```

---

<div class="post-metadata">

**Author:** ![jeongsyhd](https://avatars.discourse-cdn.com/v4/letter/j/f17d59/32.png) [@jeongsyhd](https://discuss.elastic.co/u/jeongsyhd)\
**Post date:** [September 16, 2018, 3:46pm UTC](https://discuss.elastic.co/t/q-grok-filter-pattern/148731/5 "2018-09-16T15:46:18Z")

</div>

Thank you for showing me a good sample.

Can I use a grok filter instead of a dissect filter?  
ex) grok {match =\> {"message" =\> "grok\_pattern\_B"}}

And is there any other way?

If there is a simpler way than the above method, I would like to do it.

Thank you in advance.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 16, 2018, 3:48pm UTC](https://discuss.elastic.co/t/q-grok-filter-pattern/148731/6 "2018-09-16T15:48:29Z")

</div>

You can use grok instead of the dissect filter, but for this example I thought it was easier. What about this approach is too complicated? Trying to use grok alone will likely be more complex as well as less efficient.

---

<div class="post-metadata">

**Author:** ![jeongsyhd](https://avatars.discourse-cdn.com/v4/letter/j/f17d59/32.png) [@jeongsyhd](https://discuss.elastic.co/u/jeongsyhd)\
**Post date:** [September 16, 2018, 4:23pm UTC](https://discuss.elastic.co/t/q-grok-filter-pattern/148731/7 "2018-09-16T16:23:16Z")

</div>

Um ...  
Actually, I did not understand the sample well.  
Would you be willing to give me a little more detail?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [September 16, 2018, 4:45pm UTC](https://discuss.elastic.co/t/q-grok-filter-pattern/148731/8 "2018-09-16T16:45:26Z")

</div>

The dissect filter is used to put the full string containing the key-value pairs into a field named `kvpart`. The mutate part then removes spaces surrounding the equals sign so that the key-value string matches the default separators. The kv filter is then applied to parse out the fields.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 14, 2018, 4:45pm UTC](https://discuss.elastic.co/t/q-grok-filter-pattern/148731/9 "2018-10-14T16:45:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
