# Pipeline grok pattern UPPER CASE processing vars

**URL:** <https://community.graylog.org/t/pipeline-grok-pattern-upper-case-processing-vars/4391>\
**Category:** Graylog Central (peer support)\
**Created:** [February 28, 2018, 1:15pm UTC](https://community.graylog.org/t/pipeline-grok-pattern-upper-case-processing-vars/4391 "2018-02-28T13:15:56Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![geosone](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/geosone/32/10445_2.png) [@geosone](https://community.graylog.org/u/geosone)\
**Post date:** [February 28, 2018, 1:15pm UTC](https://community.graylog.org/t/pipeline-grok-pattern-upper-case-processing-vars/4391/1 "2018-02-28T13:15:56Z")

</div>

i have created an pipeline rule to parse the custom apache logs

```auto
rule "apache smsat"
when
 has_field("message") 
then
  // grok the message field
  let message_field = to_string($message.message);
  let parsed_fields = grok(pattern: "%{HOSTNAME:requestdomain} %{COMBINEDAPACHELOG}", value: message_field);
  set_fields(parsed_fields);
end

```

but the created fields also contain the processing field names like

BASE10NUM COMBINEDAPACHELOG COMMONAPACHELOG HOUR INT IP IPV4 MINUTE MONTH MONTHDAY QUOTEDSTRING SECOND TIME USER USERNAME YEAR

what am i doing wrong or how to get rid of these

---

<div class="post-metadata">

**Author:** ![jochen](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jochen/32/8_2.png) [@jochen](https://community.graylog.org/u/jochen)\
**Post date:** [February 28, 2018, 1:22pm UTC](https://community.graylog.org/t/pipeline-grok-pattern-upper-case-processing-vars/4391/2 "2018-02-28T13:22:21Z")

</div>

> [@geosone](#):
>
> what am i doing wrong or how to get rid of these

You have to tell the [`grok()`](http://docs.graylog.org/en/2.4/pages/pipelines/functions.html#grok) function to only use _named captures_.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [March 14, 2018, 1:22pm UTC](https://community.graylog.org/t/pipeline-grok-pattern-upper-case-processing-vars/4391/3 "2018-03-14T13:22:38Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
