Home / Stream/ Knowledge Libraries/Grok Patterns Library

Grok Patterns Library

What Is the Grok Patterns Library

Cribl Stream ships with a Grok Patterns Library that contains a set of pre-built common patterns, organized as files.

Grok Patterns Library
Grok Patterns Library

Managing Library Patterns

You can access the Grok Patterns Library by selecting Worker Groups from the sidebar and choosing a Worker Group. Then, on the Worker Groups submenu, select Processing, then Knowledge, then Grok Patterns. The library contains several pattern files that Cribl provides for basic Grok scenarios, and is searchable.

To create a new pattern file, select Add Grok Pattern File. In the resulting modal, assign a unique File name, populate the file with patterns, then select Save.

Pattern files reside in: $CRIBL_HOME/(default|local)/cribl/grok-patterns/

Using Grok Patterns

In the current Cribl Stream version, you apply Grok patterns by inserting a Grok Function into a Pipeline, then manually typing or pasting patterns into the Pattern field(s).