# Windows source grok match

**URL:** <https://discuss.elastic.co/t/windows-source-grok-match/40778>\
**Category:** Logstash\
**Created:** [February 2, 2016, 6:37pm UTC](https://discuss.elastic.co/t/windows-source-grok-match/40778 "2016-02-02T18:37:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sd\_karthik](https://avatars.discourse-cdn.com/v4/letter/s/c5a1d2/32.png) [@sd\_karthik](https://discuss.elastic.co/u/sd_karthik)\
**Post date:** [February 2, 2016, 6:37pm UTC](https://discuss.elastic.co/t/windows-source-grok-match/40778/1 "2016-02-02T18:37:26Z")

</div>

How do I write a grok for source in windows file

My source is -- "T:\pricelinelogs\tripair\Xml.16-02-02.log"

How do i grok for "tripair" and the log file name in the source?

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [February 2, 2016, 9:16pm UTC](https://discuss.elastic.co/t/windows-source-grok-match/40778/2 "2016-02-02T21:16:15Z")

</div>

Since you are asking about grok, did you mean to open this in the Logstash section? The Beats don't do grok.

---

<div class="post-metadata">

**Author:** ![sd\_karthik](https://avatars.discourse-cdn.com/v4/letter/s/c5a1d2/32.png) [@sd\_karthik](https://discuss.elastic.co/u/sd_karthik)\
**Post date:** [February 3, 2016, 4:16pm UTC](https://discuss.elastic.co/t/windows-source-grok-match/40778/3 "2016-02-03T16:16:44Z")

</div>

Hi,

I have the following coming into logstash server as input --

"source" =\> "T:\pricelinelogs\tripair\airsearch.16-02-02\_21.log",  
[0] "\_grokparsefailure"

As u see above it says grok failure

The grok match I have in my conf file is

match =\> ["source","%{DATA:home}%{WORD:logfolder}\\%{WORD:application1}\\%{GREEDYDATA:filename}.log"]

I verified this grok pattern in [https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/)

I used "T:\pricelinelogs\tripair\airsearch.16-02-02\_16.log" as input  
and  
%{DATA:home}%{WORD:logfolder}\\%{WORD:application1}\\%{GREEDYDATA:filename}.log as pattern and i was able to parse the fields.

My grok is able to parse the fields but however in logstash i am seeing parse failure.

Can u pls help me

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:13am UTC](https://discuss.elastic.co/t/windows-source-grok-match/40778/4 "2017-07-06T05:13:12Z")

</div>


