# Using grok on just one field

**URL:** <https://discuss.elastic.co/t/using-grok-on-just-one-field/142234>\
**Category:** Logstash\
**Created:** [July 30, 2018, 6:05pm UTC](https://discuss.elastic.co/t/using-grok-on-just-one-field/142234 "2018-07-30T18:05:14Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![CoopTang](https://avatars.discourse-cdn.com/v4/letter/c/53a042/32.png) [@CoopTang](https://discuss.elastic.co/u/CoopTang)\
**Post date:** [July 30, 2018, 6:05pm UTC](https://discuss.elastic.co/t/using-grok-on-just-one-field/142234/1 "2018-07-30T18:05:15Z")

</div>

So I have been trying to figure out how to use grok on just one field from the input. Specifically, I'm using the beats input to get all my logs, and it automatically produces a bunch of fields for kibana. One of those fields is a string that contains the log that I want to break apart. Is there a way to use a grok filter on a specific field?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 30, 2018, 6:13pm UTC](https://discuss.elastic.co/t/using-grok-on-just-one-field/142234/2 "2018-07-30T18:13:07Z")

</div>

Yes, the basic syntax of a [grok](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html) filter is

```
filter {
  grok {
    match => { "someField" => "<your pattern goes here>" }
  }
}

```

You can do that against any field you want.

---

<div class="post-metadata">

**Author:** ![CoopTang](https://avatars.discourse-cdn.com/v4/letter/c/53a042/32.png) [@CoopTang](https://discuss.elastic.co/u/CoopTang)\
**Post date:** [July 30, 2018, 6:33pm UTC](https://discuss.elastic.co/t/using-grok-on-just-one-field/142234/3 "2018-07-30T18:33:45Z")

</div>

I have unfortunately tried that. What if this field is nested? For example:

{ \_source: { log: "" } }

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 30, 2018, 6:40pm UTC](https://discuss.elastic.co/t/using-grok-on-just-one-field/142234/4 "2018-07-30T18:40:26Z")

</div>

To refer to a nested field, you specify the full path to that field: [top-level field][nested field].

But \_source is an elasticsearch concept. It is not present in logstash.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 27, 2018, 6:40pm UTC](https://discuss.elastic.co/t/using-grok-on-just-one-field/142234/5 "2018-08-27T18:40:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
