> For the complete documentation index, see [llms.txt](https://nag-9-s.gitbook.io/elastic-search-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://nag-9-s.gitbook.io/elastic-search-notes/logstash/grok-patterns.md).

# Grok patterns

<https://qbox.io/blog/logstash-grok-filter-tutorial-patterns>

<https://grokdebug.herokuapp.com/>

Debug

55.3.244.1 GET /index.html 15824 0.043

beneath, u will paste

%{IP:client} %{WORD:method} %{URIPATHPARAM:request} %{NUMBER:bytes} %{NUMBER:duration}

and choose "Named Captures Only"

You will see this in the last text area

```
{
```

```
  "client": [
    [
      "55.3.244.1"
    ]
  ],
  "method": [
    [
      "GET"
    ]
  ],
  "request": [
    [
      "/index.html"
    ]
  ],
  "bytes": [
    [
      "15824"
    ]
  ],
  "duration": [
    [
      "0.043"
    ]
  ]
}
```
