# Running grok against an HTTP source

**URL:** <https://discuss.elastic.co/t/running-grok-against-an-http-source/60608>\
**Category:** Logstash\
**Created:** [September 15, 2016, 1:32pm UTC](https://discuss.elastic.co/t/running-grok-against-an-http-source/60608 "2016-09-15T13:32:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![amit\_oren](https://avatars.discourse-cdn.com/v4/letter/a/f05b48/32.png) [@amit\_oren](https://discuss.elastic.co/u/amit_oren)\
**Post date:** [September 15, 2016, 1:32pm UTC](https://discuss.elastic.co/t/running-grok-against-an-http-source/60608/1 "2016-09-15T13:32:29Z")

</div>

Hi,

I'm trying to recieve HTTP GET requests via the HTTP input and then run grok and a ruby script on the request\_uri in order to extract the paramters and their values.  
My agent configuration is as follows:

```
input
{
  http {
  }
}

filter
{
  grok {
    patterns_dir => "/opt/logstash/patterns"
    match => {"request_uri" => "{URIPATH:path}\?%{PARAMS:params}"}
  }
  ruby {
    code => "
        fieldArray = event['params'].split('&')
        for field in fieldArray
            if (field != '')
              result = field.split('=')
              event[result[0]] = result[1]
            end
        end
    "
  }
}

output
{
  stdout { codec => rubydebug }
}

```

custom pattern is:  
PARAMS [A-Za-z0-9$.+!_'|(){},~@#%&/=:;\_?-[]\<\>]_

If I try to run curl -XGET '[http://localhost:8080/l/?a=1&bc=2&cdf=3](http://localhost:8080/l/?a=1&bc=2&cdf=3)' for the sake of the example, I get grokparsefailure.  
Since the grok pattern should be fine (grokdebug shows no issues with it), I tend to believe it's something wrong with how I'm trying to get request\_uri. In the response I get -

```
{
       "message" => "",
      "@version" => "1",
    "@timestamp" => "2016-09-15T13:22:32.695Z",
          "host" => "0:0:0:0:0:0:0:1",
       "headers" => {
         "request_method" => "GET",
           "request_path" => "/l/",
            "request_uri" => "/l/?a=1&bc=2&cdf=3",
           "http_version" => "HTTP/1.1",
        "http_user_agent" => "curl/7.29.0",
              "http_host" => "localhost:8080",
            "http_accept" => "*/*"
    },
          "tags" => [
        [0] "_grokparsefailure",
        [1] "_rubyexception"
    ]
}

```

I can see that request\_uri is nested inside headers, which is what I believe causes my problem.  
Am I on the right track? Completly off?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 16, 2016, 5:41am UTC](https://discuss.elastic.co/t/running-grok-against-an-http-source/60608/2 "2016-09-16T05:41:07Z")

</div>

> I can see that request\_uri is nested inside headers, which is what I believe causes my problem.

Yes. You need to reference the field as `[headers][request_uri]` in your grok filter. See [Accessing event data and fields | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:38am UTC](https://discuss.elastic.co/t/running-grok-against-an-http-source/60608/3 "2017-07-06T04:38:11Z")

</div>


