# Using grok filter to parse log file

**URL:** <https://discuss.elastic.co/t/using-grok-filter-to-parse-log-file/269138>\
**Category:** Logstash\
**Created:** [April 3, 2021, 2:08am UTC](https://discuss.elastic.co/t/using-grok-filter-to-parse-log-file/269138 "2021-04-03T02:08:25Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![bab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bab/32/86201_2.png) [@bab](https://discuss.elastic.co/u/bab)\
**Post date:** [April 3, 2021, 2:08am UTC](https://discuss.elastic.co/t/using-grok-filter-to-parse-log-file/269138/1 "2021-04-03T02:08:25Z")

</div>

Hi guys,

i'm trying to parse the following log files, i succeed to filter all fields unless the last one, can some one help pls, thank you.

Log file:

```
1;2;06-19-15;start inbound processing;50034744;1;ok;2021-03-18 16:10:44.63; ; ;/var/webMethods/bbb/cbbb/download/06-19-99/xcdc.xml;"FilePolling.60088
"

```

using Grok Filter:

`%{NUMBER:Row Nr};%{DATA:Nr};%{DATA:corrier Nr};%{DATA:was Passiert};%{NUMBER:ID Prozess};%{NUMBER:Indicators};%{DATA:Status};%{TIMESTAMP_ISO8601:Datum};%{SPACE};%{SPACE};%{URIPATHPARAM:location}; /"%{GREEDYDATA:response} /n"`

result 🙂

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/0/a070895d407e89adef19bc1aabd718e4204d2172.png)

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [April 3, 2021, 2:55pm UTC](https://discuss.elastic.co/t/using-grok-filter-to-parse-log-file/269138/2 "2021-04-03T14:55:43Z")

</div>

Why the ` /` in front of the final variable?

---

<div class="post-metadata">

**Author:** ![bab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bab/32/86201_2.png) [@bab](https://discuss.elastic.co/u/bab)\
**Post date:** [April 4, 2021, 10:34am UTC](https://discuss.elastic.co/t/using-grok-filter-to-parse-log-file/269138/3 "2021-04-04T10:34:18Z")

</div>

hi , to escape the (" ... " ) and the lline after the last variable ans extract onle that Word (FilePolling.60088) .

........; `"FilePolling.60088`  
` "`

---

<div class="post-metadata">

**Author:** ![kavierkoo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kavierkoo/32/86555_2.png) [@kavierkoo](https://discuss.elastic.co/u/kavierkoo)\
**Post date:** [April 4, 2021, 1:20pm UTC](https://discuss.elastic.co/t/using-grok-filter-to-parse-log-file/269138/4 "2021-04-04T13:20:02Z")

</div>

Hi Bab,

Out side of your question, the logs seems to follow a pretty standard delimiter of semicolon ";",  
I wonder why don't you use dissect with ; as delimiter instead?

> **[Dissect filter plugin | Logstash Reference \[7.12\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-dissect.html)**

Back to your question, I tested and modified your query in a GROK tester by adding "\s" in before double quote, it seems to work.

```
%{DATA:Nr};%{DATA:corrier Nr};%{DATA:was Passiert};%{NUMBER:ID Prozess};%{NUMBER:Indicators};%{DATA:Status};%{TIMESTAMP_ISO8601:Datum};%{SPACE};%{SPACE};%{URIPATHPARAM:location};"%{GREEDYDATA:response}\s"

```

Result

```
{
  "Nr": [
    "1"
  ],
  "corrier": [
    "2"
  ],
  "was": [
    "06-19-15;start inbound processing"
  ],
  "ID": [
    "50034744"
  ],
  "BASE10NUM": [
    "50034744",
    "1"
  ],
  "Indicators": [
    "1"
  ],
  "Status": [
    "ok"
  ],
  "Datum": [
    "2021-03-18 16:10:44.63"
  ],
  "YEAR": [
    "2021"
  ],
  "MONTHNUM": [
    "03"
  ],
  "MONTHDAY": [
    "18"
  ],
  "HOUR": [
    "16",
    null
  ],
  "MINUTE": [
    "10",
    null
  ],
  "SECOND": [
    "44.63"
  ],
  "ISO8601_TIMEZONE": [
    null
  ],
  "SPACE": [
    " ",
    " "
  ],
  "location": [
    "/var/webMethods/bbb/cbbb/download/06-19-99/xcdc.xml"
  ],
  "URIPATH": [
    "/var/webMethods/bbb/cbbb/download/06-19-99/xcdc.xml"
  ],
  "URIPARAM": [
    null
  ],
  "response": [
    "FilePolling.60088"
  ]
}

```

Hope this can help you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 2, 2021, 1:20pm UTC](https://discuss.elastic.co/t/using-grok-filter-to-parse-log-file/269138/5 "2021-05-02T13:20:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
