# Regrok a groked string

**URL:** <https://discuss.elastic.co/t/regrok-a-groked-string/133316>\
**Category:** Logstash\
**Created:** [May 25, 2018, 12:13pm UTC](https://discuss.elastic.co/t/regrok-a-groked-string/133316 "2018-05-25T12:13:48Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![dyl](https://avatars.discourse-cdn.com/v4/letter/d/5fc32e/32.png) [@dyl](https://discuss.elastic.co/u/dyl)\
**Post date:** [May 25, 2018, 12:13pm UTC](https://discuss.elastic.co/t/regrok-a-groked-string/133316/1 "2018-05-25T12:13:48Z")

</div>

Hello everybody, I use Logstash and groke to parse this line :

> 25/05/2018 11:55:28.630 (TACHE) 27/02/2018/D T XX\_CACXXX\_X\_TN\_CAC001MT\_PORTEFEUILLE(945)/SAU\_XXXXXX\_X\_LL\_OPE001\_EFLUID TER STATUS : TN Terminaison normale de la tâche (TN EXIT CODE 0)

This is my logstash config :

```
### INPUT SECTION ###
input
{
  beats
  {
    port => 5044
  }
}

### FILTER SECTION ###
filter
{
  grok
  {
     match => { "message" => ["%{DATE_EU:DATE_LOG} %{TIME:HEURE_TACHE} \(%{WORD:TYPE_TACHE}\) %{DATE_EU:DATE_TACHE}/D . %{WORD:NOM_TACHE}\(%{NUMBER:ID_TACHE}\)/%{WORD:LOCALISATION} (?<STATUS>[A-Z]\w++\s+[A-Z]\w+) : %{WORD:CODE_TACHE} %{GREEDYDATA:DESCRIPTION}" ] }
  }
  mutate
  {
    remove_field => ["@version","CODE_TACHE","DATE_LOG","ID_TACHE","STATUS","TYPE_TACHE","_id","_index","_score","_type","beat.hostname","beat.name","beat.version","filetype","host","offset","prospector.type","tags"]
  }
  if ([message] !~ "CODE")
  {
    drop { }
  }
}

### OUTPUT SECTION ###
output
{
  elasticsearch
  {
    hosts => "http://localhost:9200"
    index => "vega_test"
  }
}

```

Everything OK, I obtain a good parsing, but I want to reparse "DESCRIPTION" field.

Actually, "DESCRIPTION" looks like :

> Terminaison normale de la tâche (TN EXIT CODE 0)

And I would like to have :

"DESCRIPTION" same as above but another field "CODE\_ERREUR" : 0

Can somebody help me ?

PS : **"%{NUMBER:CODE\_ERREUR}"** match but when I add below my first match instruction this line :

`match => { "DESCRIPTION" => ["%{NUMBER:CODE_ERREUR}"] }`

"DESCRIPTION" isn't parse ☹

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [May 25, 2018, 2:22pm UTC](https://discuss.elastic.co/t/regrok-a-groked-string/133316/2 "2018-05-25T14:22:37Z")

</div>

Try

```auto
match => { "DESCRIPTION" => ["%{NUMBER:CODE_ERREUR})$"] }

```

Notice the `)` and the `$` end of string anchor.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 22, 2018, 2:22pm UTC](https://discuss.elastic.co/t/regrok-a-groked-string/133316/3 "2018-06-22T14:22:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
