# Samples of grok filter

**URL:** <https://discuss.elastic.co/t/samples-of-grok-filter/124427>\
**Category:** Logstash\
**Created:** [March 18, 2018, 2:24am UTC](https://discuss.elastic.co/t/samples-of-grok-filter/124427 "2018-03-18T02:24:28Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![jason\_smith](https://avatars.discourse-cdn.com/v4/letter/j/b5e925/32.png) [@jason\_smith](https://discuss.elastic.co/u/jason_smith)\
**Post date:** [March 18, 2018, 2:24am UTC](https://discuss.elastic.co/t/samples-of-grok-filter/124427/1 "2018-03-18T02:24:28Z")

</div>

Hello folks,

Being new to ELK, I struggled to understand from the following sample grok filter script which reads Apache log file as shown in the picture. I want to find out from this forum if there are any good samples of grok filter for me to practice and go over them.

```
    filter{    	
	
	grok{
			match=>["message",'%{IPORHOST:ClientIPAddress} %{USER:userID} %{USER:Authorization} \[%{HTTPDATE:timestamp}\] "%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:versionnumber}" %{NUMBER:response:int} %{NUMBER:bytesint} %{QS:aaa} %{QS:agent}']
	}	
	
	date{
		match=>["timestamp","dd/MMM/YYYY:HH:mm:ss Z"]
		locale=>en
	}
	   geoip{![2018-03-17_19-23-29|690x112](upload://eXBxvNjDgQkL4psiBhX6GJeBwml.jpg)
		   source=>"ClientIPAddress"
	     }
    }

```

 ![2018-03-17_19-23-29](https://us1.discourse-cdn.com/elastic/original/3X/6/8/68db510b4d6745e780b3323035b8eaba4dbcc781.jpg)

---

<div class="post-metadata">

**Author:** ![DanRoscigno](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danroscigno/32/70277_2.png) [@DanRoscigno](https://discuss.elastic.co/u/DanRoscigno)\
**Post date:** [March 23, 2018, 2:28pm UTC](https://discuss.elastic.co/t/samples-of-grok-filter/124427/2 "2018-03-23T14:28:51Z")

</div>

Hi @jason_smith, would it help if I posted a step by step of how I approach writing a grok pattern?

---

<div class="post-metadata">

**Author:** ![DanRoscigno](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danroscigno/32/70277_2.png) [@DanRoscigno](https://discuss.elastic.co/u/DanRoscigno)\
**Post date:** [March 23, 2018, 3:05pm UTC](https://discuss.elastic.co/t/samples-of-grok-filter/124427/3 "2018-03-23T15:05:12Z")

</div>

This is a good post from @jsvd , and it links to a list of examples in github:

> **[Do you grok Grok?](https://www.elastic.co/blog/do-you-grok-grok)**
>
> There are over 200 grok patterns available, so how do you know what way will work best for you? Let us help you grok Grok.

> **[logstash-plugins/logstash-patterns-core](https://github.com/logstash-plugins/logstash-patterns-core/tree/master/patterns)**
>
> Contribute to logstash-patterns-core development by creating an account on GitHub.

---

<div class="post-metadata">

**Author:** ![jason\_smith](https://avatars.discourse-cdn.com/v4/letter/j/b5e925/32.png) [@jason\_smith](https://discuss.elastic.co/u/jason_smith)\
**Post date:** [March 23, 2018, 5:20pm UTC](https://discuss.elastic.co/t/samples-of-grok-filter/124427/4 "2018-03-23T17:20:22Z")

</div>

Dan, I learnt it now. First of all I wasn't good at Regular expressions. I did a course on that Regex and I started looking at Grok. It is kind of making sense now.

Thank You and Kind regards

---

<div class="post-metadata">

**Author:** ![DanRoscigno](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danroscigno/32/70277_2.png) [@DanRoscigno](https://discuss.elastic.co/u/DanRoscigno)\
**Post date:** [March 23, 2018, 6:55pm UTC](https://discuss.elastic.co/t/samples-of-grok-filter/124427/5 "2018-03-23T18:55:16Z")

</div>

Great, have fun and post again if you need a hand.

---

<div class="post-metadata">

**Author:** ![jason\_smith](https://avatars.discourse-cdn.com/v4/letter/j/b5e925/32.png) [@jason\_smith](https://discuss.elastic.co/u/jason_smith)\
**Post date:** [March 23, 2018, 7:52pm UTC](https://discuss.elastic.co/t/samples-of-grok-filter/124427/6 "2018-03-23T19:52:44Z")

</div>

Appreciate your help and I have to say this.

This forum is awesome!!! I tried to get answers from [stackoverflow.com](http://stackoverflow.com) They have tonnes or rules about what questions to ask and all. that sucks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 20, 2018, 7:53pm UTC](https://discuss.elastic.co/t/samples-of-grok-filter/124427/7 "2018-04-20T19:53:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
