grok

Function

ArgDescriptionType
grokGrok pattern.string (required)
dataString to parse.string (required)
patternsAdditional patterns.Any
all_capturesExtract all captures.bool

Description

Parse a string using a Grok expression.

This is most useful for parsing syslog style logs (e.g. IIS, Apache logs).

You can read more about GROK expressions here https://www.elastic.co/blog/do-you-grok-grok