# QUESTION ABOUT "LOGSTASH GROK MATCH" WITH ARRAY

**URL:** <https://discuss.elastic.co/t/question-about-logstash-grok-match-with-array/178827>\
**Category:** Logstash\
**Created:** [April 29, 2019, 3:14am UTC](https://discuss.elastic.co/t/question-about-logstash-grok-match-with-array/178827 "2019-04-29T03:14:02Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![GGUERRA](https://avatars.discourse-cdn.com/v4/letter/g/b2d939/32.png) [@GGUERRA](https://discuss.elastic.co/u/GGUERRA)\
**Post date:** [April 29, 2019, 3:14am UTC](https://discuss.elastic.co/t/question-about-logstash-grok-match-with-array/178827/1 "2019-04-29T03:14:02Z")

</div>

Hello everyone, I have the following question regarding the logstash filters.

I have logs that have fields that sometimes appear and sometimes do not, for example

"ip" = "1.1.1.1", "mac" = "a1: a1: a1: a1: a1: a1", "bytes" = "100", "radio" = "a / g"  
"ip" = "2.2.2.2", "mac" = "a2: a2: a2: a2: a2: a2", "radio" = "B / g"

So in the grok I generate a pattern array something like that

grok {  
match =\> {  
"message" =\> ["" ip \ "= "% {IP: clientIP} \ "",  
"" mac \ "= "% {mac} \ "",  
"" bytes \ "= "% {NUMBER: bytes} \ "",  
"" radio \ "= "% {DATA: radio} \ ""  
]  
}  
}

I would like to ask you if it is necessary that all the elements of this array always appear in the message to work, and if the order of the elements of the array influences, or they capture the occurrence independent of the order in the array.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 29, 2019, 4:27am UTC](https://discuss.elastic.co/t/question-about-logstash-grok-match-with-array/178827/2 "2019-04-29T04:27:19Z")

</div>

Have you considered using the [kv filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-kv.html) instead of grok for this type of data? It should be able to handle aribrary combinations of fields more efficiently than grok.

---

<div class="post-metadata">

**Author:** ![GGUERRA](https://avatars.discourse-cdn.com/v4/letter/g/b2d939/32.png) [@GGUERRA](https://discuss.elastic.co/u/GGUERRA)\
**Post date:** [April 29, 2019, 12:30pm UTC](https://discuss.elastic.co/t/question-about-logstash-grok-match-with-array/178827/3 "2019-04-29T12:30:01Z")

</div>

Christian, thanks for your answer! The message that comes to me comes with quotes, do you know if this influences the kv filter?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 29, 2019, 12:35pm UTC](https://discuss.elastic.co/t/question-about-logstash-grok-match-with-array/178827/4 "2019-04-29T12:35:38Z")

</div>

If it causes problems you can always trim then using a mutate gsub filter before processing.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 27, 2019, 12:35pm UTC](https://discuss.elastic.co/t/question-about-logstash-grok-match-with-array/178827/5 "2019-05-27T12:35:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
