# Understanding SYSLOGBASE2 pattern

**URL:** <https://discuss.elastic.co/t/understanding-syslogbase2-pattern/138993>\
**Category:** Logstash\
**Created:** [July 7, 2018, 1:05am UTC](https://discuss.elastic.co/t/understanding-syslogbase2-pattern/138993 "2018-07-07T01:05:57Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![dss](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dss/32/33128_2.png) [@dss](https://discuss.elastic.co/u/dss)\
**Post date:** [July 7, 2018, 1:05am UTC](https://discuss.elastic.co/t/understanding-syslogbase2-pattern/138993/1 "2018-07-07T01:05:58Z")

</div>

`SYSLOGBASE2 (?:%{SYSLOGTIMESTAMP:timestamp}|%{TIMESTAMP_ISO8601:timestamp8601}) (?:%{SYSLOGFACILITY} )?%{SYSLOGHOST:logsource}+(?: %{SYSLOGPROG}:|)`

Could I get a hand with the meaning of a few constructs in this pattern?

1. `(?:%{SYSLOGTIMESTAMP:timestamp}|%{TIMESTAMP_ISO8601:timestamp8601})`

Does the `?:` prefix to a couple of the patterns mean a non-capturing pattern as with some other regex libraries? What does this mean for a pattern chunk in the grok filter? The pattern inherently captures matching text to a named field so I'm not clear what that would mean.

1. `(?:%{SYSLOGFACILITY} )?`

Does this indicate 0 or 1 match of the facility is required (i.e. this field is optional in the pattern?

1. `%{SYSLOGHOST:logsource}+`

Does the `+` indicate that one more log sources may be chained together in the log? In the case where there are multiple, are they typically whitespace separated, and does the pattern accommodate a match on the whitespace between 2 or more SYSLOGHOSTs?

1. `(?: %{SYSLOGPROG}:|)`

I'm curious what the single `|` for the SEMANTIC means with this field. Also it's prefixed with `?:` - why? (Related to #1).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 4, 2018, 1:06am UTC](https://discuss.elastic.co/t/understanding-syslogbase2-pattern/138993/2 "2018-08-04T01:06:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
