# Unable to use grok pattern on GREEDYDATA message

**URL:** <https://discuss.elastic.co/t/unable-to-use-grok-pattern-on-greedydata-message/301086>\
**Category:** Logstash\
**Created:** [March 30, 2022, 12:36pm UTC](https://discuss.elastic.co/t/unable-to-use-grok-pattern-on-greedydata-message/301086 "2022-03-30T12:36:43Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rahulgupta18](https://avatars.discourse-cdn.com/v4/letter/r/5f9b8f/32.png) [@rahulgupta18](https://discuss.elastic.co/u/rahulgupta18)\
**Post date:** [March 30, 2022, 12:36pm UTC](https://discuss.elastic.co/t/unable-to-use-grok-pattern-on-greedydata-message/301086/1 "2022-03-30T12:36:43Z")

</div>

Hi,

I have this log message -  
2022-03-08 04:16:04 [DEBUG] Creating linked clone: from Template-CentOS, to CentOS-001122

My logstash config. file is as follows -

```auto
filter {
    grok {
      match => {
        "message" => [
          "^%{TIMESTAMP_ISO8601:logTimestamp} \[%{LOGLEVEL:logLevel}\] %{DATA} %{DATA} %{DATA:actionName} %{GREEDYDATA:logMessage}$"
        ]
      }
    }

    if [actionName] == "clone:" {
      grok {
        match => {
          "logMessage" => [
            "^%{TIMESTAMP_ISO8601:logTimestamp} \[%{LOGLEVEL:logLevel}\] %{DATA} %{DATA} %{DATA:actionName} %{WORD} %{DATA:templateName} %{GREEDYDATA:logMessage}$"
          ]
        }
      }
    }
}

```

My actionName field contains string "clone:" and I have verified that it is entering the if loop using mutate filter (remove and rename fields are working). The only time I am having issue is when I am looking to grok for template name in the above copied log i.e. want to retrieve "Template-CentOS" name.

I have reviewed a lot of KB articles, however, couldn't get through. Can someone please point out what am I doing wrong?

Thanks,

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [March 30, 2022, 1:38pm UTC](https://discuss.elastic.co/t/unable-to-use-grok-pattern-on-greedydata-message/301086/2 "2022-03-30T13:38:33Z")

</div>

Not quite sure your question but if all your logs follow a similar format then this should work.

```auto
^%{TIMESTAMP_ISO8601:logTimestamp} \[%{LOGLEVEL:logLevel}\] Creating linked %{DATA:actionName}: from %{DATA:from}\, to %{GREEDYDATA:to}

```

Output

```auto
{
  "logTimestamp": "2022-03-08 04:16:04",
  "logLevel": "DEBUG",
  "from": "Template-CentOS",
  "to": "CentOS-001122",
  "actionName": "clone"
}

```

---

<div class="post-metadata">

**Author:** ![rahulgupta18](https://avatars.discourse-cdn.com/v4/letter/r/5f9b8f/32.png) [@rahulgupta18](https://discuss.elastic.co/u/rahulgupta18)\
**Post date:** [March 31, 2022, 4:09am UTC](https://discuss.elastic.co/t/unable-to-use-grok-pattern-on-greedydata-message/301086/3 "2022-03-31T04:09:19Z")

</div>

Hi Aaron,

Thanks a lot for your response. Now that's where the challenge lies since there are several different events being logged in the files.

For example:

```auto
2022-03-28 07:05:31 [ERROR] save_variable: Error while trying to work with DB. Exception => (1205, u'Lock wait timeout exceeded; try restarting transaction')
2022-03-25 12:37:11: [DEBUG] diag-_do_action [1] action_name='alert' action_params='['admins', 'N5K failed to boot up']' ### dlgscr.py: 382: _do_action(): 
2022-03-08 04:16:04 [DEBUG] Creating linked clone: from Template-CentOS, to CentOS-001122

```

Regards,  
Rahul

---

<div class="post-metadata">

**Author:** ![rahulgupta18](https://avatars.discourse-cdn.com/v4/letter/r/5f9b8f/32.png) [@rahulgupta18](https://discuss.elastic.co/u/rahulgupta18)\
**Post date:** [March 31, 2022, 4:13am UTC](https://discuss.elastic.co/t/unable-to-use-grok-pattern-on-greedydata-message/301086/4 "2022-03-31T04:13:08Z")

</div>

In addition to my previous comment, I am parsing different kind of events from logs. And I do segregating with different field names in Kibana visualisations.

For example:

```auto
2022-03-25 12:37:11: [DEBUG] diag-_do_action [1] action_name='alert' action_params='['admins', 'N5K failed to boot up']' ### dlgscr.py: 382: _do_action(): 

```

I am creating an alert visualisation in Kibana for the above event.

```auto
2022-03-08 04:16:04 [DEBUG] Creating linked clone: from Template-CentOS, to CentOS-001122

```

I am creating a template name visualisation for above event.

Note: The source of all these events is same.

Thanks,

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [March 31, 2022, 10:04am UTC](https://discuss.elastic.co/t/unable-to-use-grok-pattern-on-greedydata-message/301086/5 "2022-03-31T10:04:32Z")

</div>

If you want to parse all the different types of messages then you need to write grok patterns for all of them. It's not possible to write 1 to parse to the level you want.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 28, 2022, 10:05am UTC](https://discuss.elastic.co/t/unable-to-use-grok-pattern-on-greedydata-message/301086/6 "2022-04-28T10:05:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
