# Querting Kibana using grok pattern

**URL:** <https://discuss.elastic.co/t/querting-kibana-using-grok-pattern/54259>\
**Category:** Kibana\
**Created:** [June 29, 2016, 10:29am UTC](https://discuss.elastic.co/t/querting-kibana-using-grok-pattern/54259 "2016-06-29T10:29:07Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Veer\_Shubhranshu\_Shr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/veer_shubhranshu_shr/32/9530_2.png) [@Veer\_Shubhranshu\_Shr](https://discuss.elastic.co/u/Veer_Shubhranshu_Shr)\
**Post date:** [June 29, 2016, 10:29am UTC](https://discuss.elastic.co/t/querting-kibana-using-grok-pattern/54259/1 "2016-06-29T10:29:07Z")

</div>

We have configured ELK stack over our daily logs and using `Kibana` UI to perform basic search/query operation on the the set of logs.

Some of our logs have a certain field in the message while others don't. Therefore we have not configured it as a separate field while configuring `Logstash`.

I have logs like:

```
[28/Jun/2016:23:59:56 +0530] 192.168.xxx.xxx [API:Profile]get_data_login: Project password success: 9xxxxxxxxx0
[28/Jun/2016:23:59:56 +0530] 192.168.xxx.xxx [API:Profile]session_end: Project logout success: 9xxxxxxxxx0 TotalTime:1.1234

```

In these two logs, I wish to extract `TotalTime` for all `session_end` logs. And visualize it.

How should I do it?

I can search all the logs which are listed under `session_end`, however I am not able to perform grok on the set of logs.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 29, 2016, 10:36am UTC](https://discuss.elastic.co/t/querting-kibana-using-grok-pattern/54259/2 "2016-06-29T10:36:43Z")

</div>

Use Logstash to extract the desired fields. Kibana (and ultimately Elasticsearch) can't do it.

---

<div class="post-metadata">

**Author:** ![Veer\_Shubhranshu\_Shr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/veer_shubhranshu_shr/32/9530_2.png) [@Veer\_Shubhranshu\_Shr](https://discuss.elastic.co/u/Veer_Shubhranshu_Shr)\
**Post date:** [June 29, 2016, 10:43am UTC](https://discuss.elastic.co/t/querting-kibana-using-grok-pattern/54259/3 "2016-06-29T10:43:33Z")

</div>

But if I make changes to Logstash the it would take care of the current logs, not the previous logs. right?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 29, 2016, 10:44am UTC](https://discuss.elastic.co/t/querting-kibana-using-grok-pattern/54259/4 "2016-06-29T10:44:43Z")

</div>

Correct. You'd have to reindex the old data or live with the fact that those fields are missing.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:48pm UTC](https://discuss.elastic.co/t/querting-kibana-using-grok-pattern/54259/5 "2017-07-06T13:48:50Z")

</div>


