# Use of grok and regular expressions

**URL:** <https://discuss.elastic.co/t/use-of-grok-and-regular-expressions/184255>\
**Category:** Logstash\
**Created:** [June 4, 2019, 9:25pm UTC](https://discuss.elastic.co/t/use-of-grok-and-regular-expressions/184255 "2019-06-04T21:25:20Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Camilo\_Franco](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/camilo_franco/32/42912_2.png) [@Camilo\_Franco](https://discuss.elastic.co/u/Camilo_Franco)\
**Post date:** [June 4, 2019, 9:25pm UTC](https://discuss.elastic.co/t/use-of-grok-and-regular-expressions/184255/1 "2019-06-04T21:25:20Z")

</div>

Hello

I'm sending an asterisk log from filebeat to logstash,

The format of the logs is as follows.

[May 19 14:57:19] NOTICE [8583] chan\_sip.c: Registration from '\<sip: 34541@xx.xx.xx.xx\>' failed for '91.214.44.144: 2718 '- Wrong password

Download a filter from github to be able to separate the asterisk logs.

Now my question is if in the field of log\_message you can take the ip that is failing in the password and separate it to generate a new field in elastic with that ip

the ip that I wish to keep would be this 91.214.44.144, I do not know if there is a way to generate a field with this info

I attach my logstash filter

filter {  
if [source] == "security" {  
if [message] =~ /^[/ {  
grok {  
match =\> {  
"message" =\> "[%{SYSLOGTIMESTAMP:log\_timestamp}] +(?\<log\_level\>(?i)(?:debug|notice|warning|error|verbose|dtmf|fax|security)(?-i))[%{INT:thread\_id}](?:[%{DATA:call\_thread\_id}])? %{DATA:module\_name}:(?: +[=|-]{2})? %{GREEDYDATA:log\_message}"  
}  
add\_field =\> ["received\_timestamp", "%{@timestamp}"]  
add\_field =\> ["process\_name", "asterisk"]  
}  
date { match =\> ["log\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"] }  
if ![log\_message] {  
mutate {  
add\_field =\> {"log\_message" =\> ""}  
}  
} # End default asterisk log fields  
} # end log lines that begin with '['   
} # end filter for type == asterisk\_debug  
} # end filter

I am a novice in the use of grok

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 4, 2019, 10:42pm UTC](https://discuss.elastic.co/t/use-of-grok-and-regular-expressions/184255/2 "2019-06-04T22:42:02Z")

</div>

You do not have to match the entire line

```
grok { match => { "message" => "%{IPV4:ip}" } }

```

will pull an IP address out of the message if one is in there.

You should read "[Do you grok Grok?](https://www.elastic.co/blog/do-you-grok-grok)", and then anchor your pattern.

---

<div class="post-metadata">

**Author:** ![Camilo\_Franco](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/camilo_franco/32/42912_2.png) [@Camilo\_Franco](https://discuss.elastic.co/u/Camilo_Franco)\
**Post date:** [June 5, 2019, 6:20pm UTC](https://discuss.elastic.co/t/use-of-grok-and-regular-expressions/184255/3 "2019-06-05T18:20:49Z")

</div>

good afternoon

thanks for your answer, unque I have a question suppose this is my message

Registration from '\<sip: test% [20hdjd@45.79.216.200](mailto:20hdjd@45.79.216.200); transport = UDP\>' failed for '191.95.48.173:31031' - Wrong password

in this message there are two IPs if entry% {IP: ip} would be = 45.79.216.200 how could the two IPs take in different fields?

based on the message described above

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 5, 2019, 7:33pm UTC](https://discuss.elastic.co/t/use-of-grok-and-regular-expressions/184255/4 "2019-06-05T19:33:45Z")

</div>

You could use

```
grok { match => { "message" => "%{IPV4:ip-1}%{DATA}%{IPV4:ip-2}" } }
```

---

<div class="post-metadata">

**Author:** ![Camilo\_Franco](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/camilo_franco/32/42912_2.png) [@Camilo\_Franco](https://discuss.elastic.co/u/Camilo_Franco)\
**Post date:** [June 5, 2019, 9:20pm UTC](https://discuss.elastic.co/t/use-of-grok-and-regular-expressions/184255/5 "2019-06-05T21:20:54Z")

</div>

thank you very much I worked perfect:+1:👍

---

<div class="post-metadata">

**Author:** ![Camilo\_Franco](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/camilo_franco/32/42912_2.png) [@Camilo\_Franco](https://discuss.elastic.co/u/Camilo_Franco)\
**Post date:** [June 5, 2019, 9:28pm UTC](https://discuss.elastic.co/t/use-of-grok-and-regular-expressions/184255/6 "2019-06-05T21:28:34Z")

</div>

Good afternoon

Now I find myself separating by commas a log that is the following:

SecurityEvent="InvalidPassword",EventTV="2019-06-05T14:41:13.146-0500",Severity="Error",Service="SIP",EventVersion="2",AccountID="01148585359002",SessionID="0x7f4d04085258",LocalAddress="IPV4/UDP/45.79.216.200/5090",RemoteAddress="IPV4/UDP/102.165.37.226/58906",Challenge="45241c33",ReceivedChallenge="45241c33",ReceivedHash="25eb0d44b9170f358fdab302d6a48e6f"

and use the following match:

%{GREEDYDATA:SecurityEvent},%{GREEDYDATA:EventTV},%{GREEDYDATA:Severity},%{GREEDYDATA:Service},%{GREEDYDATA:EventVersion},%{GREEDYDATA:AccountID},%{GREEDYDATA:SessionID},%{GREEDYDATA:dummy1},%{GREEDYDATA:dummy2},%{GREEDYDATA:Challenge},%{GREEDYDATA:ReceivedChallenge},%{GREEDYDATA:ReceivedHash}

when I send it to elasticsearch the problem is that each field looks like this:

SecurityEvent = "InvalidPassword"  
I do not know if there is the possibility to remove SecurityEvent = "and the quote that closes"

only left = InvalidPassword

I have done several searches and I have not found this expression, so that in each separation only the value that is in quotes remains.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 5, 2019, 9:55pm UTC](https://discuss.elastic.co/t/use-of-grok-and-regular-expressions/184255/7 "2019-06-05T21:55:54Z")

</div>

I would use

```
kv { field_split => "," }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 3, 2019, 9:56pm UTC](https://discuss.elastic.co/t/use-of-grok-and-regular-expressions/184255/8 "2019-07-03T21:56:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
