# Slowlog message's entries grok

**URL:** <https://discuss.elastic.co/t/slowlog-messages-entries-grok/363794>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-monitoring\
**Created:** [July 25, 2024, 2:45pm UTC](https://discuss.elastic.co/t/slowlog-messages-entries-grok/363794 "2024-07-25T14:45:52Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![rschirin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rschirin/32/45283_2.png) [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Post date:** [July 25, 2024, 2:45pm UTC](https://discuss.elastic.co/t/slowlog-messages-entries-grok/363794/1 "2024-07-25T14:45:52Z")

</div>

Hey there,  
to investigate possible issues I used to collect slowlog entries.  
Obviously, `query` field is very important but I saw during these years that there isn't any easy way to analyze it. I mean, generally I use a Logstash instance that get messages from pub/sub queue and then use `grok filter` to simplify the read.  
This approach is prone to out-of-date `query` usage, since if the source query changes I will get a `grokparsefailure` tag.  
Is there any suggest?  
For example, using `ingest pipeline` will give me the chance to use `json` processor but it will make the ingested document not easy to be read.
