# Write a RegEx to match the event pattern in log file

**URL:** <https://discuss.elastic.co/t/write-a-regex-to-match-the-event-pattern-in-log-file/334048>\
**Category:** Logstash\
**Created:** [May 22, 2023, 6:20pm UTC](https://discuss.elastic.co/t/write-a-regex-to-match-the-event-pattern-in-log-file/334048 "2023-05-22T18:20:21Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![hamzeha](https://avatars.discourse-cdn.com/v4/letter/h/a4c791/32.png) [@hamzeha](https://discuss.elastic.co/u/hamzeha)\
**Post date:** [May 22, 2023, 6:20pm UTC](https://discuss.elastic.co/t/write-a-regex-to-match-the-event-pattern-in-log-file/334048/1 "2023-05-22T18:20:21Z")

</div>

Hi Everyone,  
I have application log file which contains the application requests and responses, the complete request and response looks like the below, I tried different patterns using RegEx but unfortunately without any luck, can some one suggest what should I change :

`pattern => "(?m)\b\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2},\d{3}\b.?\bRequest given by the user\b.?\brspDesc is\b(?!.\n)..?(?=\R|$)"`

2023-05-11 00:20:26,103 [http-apr-7777-exec-46] INFO com.welcome.ws.AccountWebServiceImpl. - Request given by the user

 \<?xml version="1.0" encoding="UTF-8" standalone="yes"?\>

\<ns2:GetCustomerBalanceReq xmlns="url" xmlns:ns2="url"\>  
  
testt  
\*\*  
xls  
  
ns2:ID/EID/5000000004/123456\*\*\*\*1234\</ns2:ID\>  
\</ns2:GetCustomerBalanceReq\>

2023-05-11 00:20:26,144 [http-apr-7777-exec-46] INFO com.welcome.svc.AccountService. - rspCode is: **1001** and rspDesc is:Account or Media does not Exist

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 23, 2023, 9:31pm UTC](https://discuss.elastic.co/t/write-a-regex-to-match-the-event-pattern-in-log-file/334048/2 "2023-05-23T21:31:33Z")

</div>

You can make something like this.

Save your lines in the sample.txt file.

```auto
input {
  file {
   path => "/path/sample.txt"
   start_position => beginning
      codec => multiline { 
      pattern => "%{TIMESTAMP_ISO8601}"
      negate => true
      what => "previous"
      }
   sincedb_path => "NUL"
   mode => "tail"
   
  }
}
filter {
    grok {
      match => { "message" => "^%{TIMESTAMP_ISO8601:timestamp}\s+\[%{DATA:thread}\]\s+%{LOGLEVEL:level}\s+%{DATA:method}\.\s+-\s+%{DATA:info}\s*(<%{GREEDYDATA:msg})?$" 
      }
	 
    }
  if [msg] =~ /^\?xml/ {
    ruby {
      code => " event.set('[msg]', '<'+event.get('[msg]') ) "
    }
  }
	
      date {
        match => ["timestamp", "ISO8601"]
        remove_field => ["timestamp"]
      }
  # prune { blacklist_names => ["@version", "location", host, "event", "log", "message", "tags"] } 
   
}

output {
    stdout {
        codec => rubydebug{ metadata => false}
    }
}

```

Result:

```auto
{
           "msg" => "<?xml version=\"1.0\" encoding=\"UTF-8\" standalone=\"yes\"?>\r\n<ns2:GetCustomerBalanceReq xmlns=\"url\" xmlns:ns2=\"url\">\r\n\r\ntestt\r\n **\r\nxls\r\n\r\nns2:ID/EID/5000000004/123456**** 1234</ns2:ID>\r\n</ns2:GetCustomerBalanceReq>\r\n</xml>\r",
         "level" => "INFO",
        "method" => "com.welcome.ws.AccountWebServiceImpl",
        "thread" => "http-apr-7777-exec-46",
          "info" => "Request given by the user",
    "@timestamp" => 2023-05-10T22:20:26.103Z
}
{
         "level" => "INFO",
        "method" => "com.welcome.svc.AccountService",
        "thread" => "http-apr-7777-exec-46",
          "info" => "rspCode is:1001 and rspDesc is:Account or Media does not Exist",
    "@timestamp" => 2023-05-10T22:20:26.144Z
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 20, 2023, 9:32pm UTC](https://discuss.elastic.co/t/write-a-regex-to-match-the-event-pattern-in-log-file/334048/3 "2023-06-20T21:32:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
