# Reference to grok patterns that are in another field of event

**URL:** <https://discuss.elastic.co/t/reference-to-grok-patterns-that-are-in-another-field-of-event/311104>\
**Category:** Logstash\
**Created:** [August 1, 2022, 10:46am UTC](https://discuss.elastic.co/t/reference-to-grok-patterns-that-are-in-another-field-of-event/311104 "2022-08-01T10:46:15Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![who](https://avatars.discourse-cdn.com/v4/letter/w/cdc98d/32.png) [@who](https://discuss.elastic.co/u/who)\
**Post date:** [August 1, 2022, 10:46am UTC](https://discuss.elastic.co/t/reference-to-grok-patterns-that-are-in-another-field-of-event/311104/1 "2022-08-01T10:46:15Z")

</div>

There's a `regexes` array field in the event that contains some regexes:

```
"regexes" => [
            [0] "regex1",
            [1] "regex2",
            [2] "regex3"
        ]

```

As this field's content get filled dynamically, I need to use the grok filter plugin the way it uses the regexes inside this field as its patterns. Something like this:

```
grok {
       match => {
         "message" => "%{[regexes]}"
    }
}

```

But despite other filter plugins, grok parses `%{TEXT}` as a pattern, not a field reference format (sprintf format). So it doesn't replace the content of `regexes` field in `"message" => "%{[regexes]}"` string and gives the error:

```
Pipeline error {:pipeline_id=>"main", :exception=>#<Grok::PatternError: pattern %{[regexes]} not defined>

```

Also, another challenge would be to feed the content of `regexes` field as an **array** to the grok plugin, so it evaluates that like this:

```
 grok {
       match => {
         "message" => [
                       "regex1",
                       "regex2",
                       "regex3"
         ]
    }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 29, 2022, 10:46am UTC](https://discuss.elastic.co/t/reference-to-grok-patterns-that-are-in-another-field-of-event/311104/2 "2022-08-29T10:46:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
