# \_grokparsefailure for matching patterns

**URL:** <https://discuss.elastic.co/t/-grokparsefailure-for-matching-patterns/76212>\
**Category:** Logstash\
**Created:** [February 23, 2017, 12:18pm UTC](https://discuss.elastic.co/t/-grokparsefailure-for-matching-patterns/76212 "2017-02-23T12:18:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rajdeep\_Mukherjee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rajdeep_mukherjee/32/15795_2.png) [@Rajdeep\_Mukherjee](https://discuss.elastic.co/u/Rajdeep_Mukherjee)\
**Post date:** [February 23, 2017, 12:18pm UTC](https://discuss.elastic.co/t/-grokparsefailure-for-matching-patterns/76212/1 "2017-02-23T12:18:51Z")

</div>

contents of pattern file:  
ZX\_ERROR \A!%{SPACE}%{DATE:date}%{SPACE}%{TIME:time}%{SPACE}:%{SPACE}(%{JAVACLASS:caused\_by})?(%{JAVAFILE:caused\_by})?%{GREEDYDATA:error\_message}

Logstash config file:

filter {  
if "tzx" in [app] {

```
   mutate {
   gsub => ["message", "[#\,]", " " ]
          }
   grok {
   add_tag => ["tzx"]
   patterns_dir => "/etc/logstash/patterns"
   match => ["message" , "%{TZX_ERROR}"]
        } }

```

#Exception Handling  
if "\_csvparsefailure" in [tags] {  
mutate { add\_field =\> { 'threat\_type' =\> 'Warn - Long error message' } }  
mutate { remove\_tag =\> ["\_csvparsefailure"] }  
}

```
    }

```

 ![](https://us1.discourse-cdn.com/elastic/original/2X/8/8481cac2d280730995c147286961df4c260d5927.png)

 ![](https://us1.discourse-cdn.com/elastic/original/2X/2/2538490e67cd8b18b4f44af7cea2749560c6bc56.png)

---

<div class="post-metadata">

**Author:** ![Rajdeep\_Mukherjee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rajdeep_mukherjee/32/15795_2.png) [@Rajdeep\_Mukherjee](https://discuss.elastic.co/u/Rajdeep_Mukherjee)\
**Post date:** [February 23, 2017, 12:21pm UTC](https://discuss.elastic.co/t/-grokparsefailure-for-matching-patterns/76212/2 "2017-02-23T12:21:05Z")

</div>

these are the patterns that fail:  
! 16/02/17 11:40:56.161 : App.Transaction : For transaction #170216000000580965, transaction result has been changed to 'System Error' due to database transaction rollback

! 16/02/17 11:40:45.549 : App.Interface : Error processing record: Mandatory translation 'OrigFiName -\> OrigInstId' not found for OrigFiName='null'

! 24/01/17 01:01:26.870 : App.Transaction : Error on transaction finalize: null

Filebeat configuration:

* * *

filebeat:  
prospectors:  
-  
document\_type: log  
fields:  
app: tzx  
fields\_under\_root: true  
include\_lines:  
- ^!  
input\_type: log  
paths:  
- /opt/TranzAxis/logs/_/_/\*/_log._  
registry\_file: /var/lib/filebeat/registry  
logging:  
files:  
rotateeverybytes: 10485760  
output:  
redis:  
db: 0  
hosts:  
- "q-acqpmq-lbm01.wirecard.sys:6379"  
key: filebeat  
reconnect\_interval: 1  
timeout: 5

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 24, 2017, 10:04am UTC](https://discuss.elastic.co/t/-grokparsefailure-for-matching-patterns/76212/3 "2017-02-24T10:04:45Z")

</div>

What exactly are you asking here?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 24, 2017, 10:04am UTC](https://discuss.elastic.co/t/-grokparsefailure-for-matching-patterns/76212/4 "2017-03-24T10:04:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
