# \_grokparsefailure help required ASAP

**URL:** <https://discuss.elastic.co/t/-grokparsefailure-help-required-asap/77426>\
**Category:** Logstash\
**Created:** [March 5, 2017, 6:47pm UTC](https://discuss.elastic.co/t/-grokparsefailure-help-required-asap/77426 "2017-03-05T18:47:49Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vutsuak16](https://avatars.discourse-cdn.com/v4/letter/v/ce7236/32.png) [@Vutsuak16](https://discuss.elastic.co/u/Vutsuak16)\
**Post date:** [March 5, 2017, 6:47pm UTC](https://discuss.elastic.co/t/-grokparsefailure-help-required-asap/77426/1 "2017-03-05T18:47:49Z")

</div>

what could be the regex for this log  
['Estimated', '904699466068', '508587356765', 'LineItem', '61133026369107517924193456', 'AWS CloudTrail', '16091348', '215570231', '1256864', 'APS1-FreeEventsRecorded', 'None', '', 'N', '0.0 per free event recorded in Asia Pacific (Singapore) region', '2017-03-01 00:00:00', '2017-03-01 01:00:00', '67.00000000', '0.0000000000', '0.00000000', '0.0000000000', '0.00000000', '', '', '', '', '', '', '', '', '', '', '', '']

this is an csv file and I am using grok filter. The columns are skewed so I have to use grok for matching

My regex is this  
grok {

```
    match =>{ "message" => "\[%{GREEDYDATA:InvoiceID}\,%{GREEDYDATA:PayerAccountId}\,%{GREEDYDATA:LinkedAccountId}\,%{GREEDYDATA:RecordType},%{GREEDYDATA:RecordId}\,%{GREEDYDATA:ProductName}\,
      %{GREEDYDATA:RateId}\,%{GREEDYDATA:SubscriptionId}\,%{GREEDYDATA:PricingPlanId}\,%{GREEDYDATA:UsageType}\,%{GREEDYDATA:Operation}\,%{GREEDYDATA:AvailabilityZone}\,%{GREEDYDATA:ReservedInstance}\,%{GREEDYDATA:ItemDescription}\,%{GREEDYDATA:UsageStartDate}\,%{GREEDYDATA:UsageEndDate}\,%{GREEDYDATA:UsageQuantity}\,%{GREEDYDATA:BlendedRate}\,%{GREEDYDATA:BlendedCost}\,%{GREEDYDATA:UnBlendedRate}\,%{GREEDYDATA:UnBlendedCost}\,%{GREEDYDATA:ResourceId}\,%{GREEDYDATA:aws:cloudformation:logical-id}\,%{GREEDYDATA:aws:cloudformation:stack-id}\,%{GREEDYDATA:aws:cloudformation:stack-name}\,%{GREEDYDATA:user:Application}\,%{GREEDYDATA:user:Project}\,%{GREEDYDATA:user:Stack}\,%{GREEDYDATA:user:cso_rollup1}\,%{GREEDYDATA:user:cso_rollup2}\,%{GREEDYDATA:user:cso_rollup3}\,%{GREEDYDATA:user:owner}\,%{GREEDYDATA:user:poc}\]" }
  }

```

It is the amazon billing log

---

<div class="post-metadata">

**Author:** ![GautamP](https://avatars.discourse-cdn.com/v4/letter/g/ac91a4/32.png) [@GautamP](https://discuss.elastic.co/u/GautamP)\
**Post date:** [March 6, 2017, 7:36am UTC](https://discuss.elastic.co/t/-grokparsefailure-help-required-asap/77426/2 "2017-03-06T07:36:18Z")

</div>

Hi Kaustuv,

Instead of using the grok filter, you could use the csv filter and specify the names of the columns that are fixed. Any additional columns will be auto numbered.

Could you provide your config file, sample log file and the screenshot of the error?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 6, 2017, 7:38am UTC](https://discuss.elastic.co/t/-grokparsefailure-help-required-asap/77426/3 "2017-03-06T07:38:16Z")

</div>

> The columns are skewed

What do you mean by this?

I don't have time to debug this, but I'll make two general suggestions

- Don't use multiple GREEDYDATA patterns. As long as the values won't contain quotes you should be able to say e.g. `(?<name-of-field>[^']*)` to match zero or more non-quotes.
- Start with the simplest possible expression, e.g. `\[%{GREEDYDATA:InvoiceID}\,` and verify that it works. Add more and more until things stop working. Be systematic.

---

<div class="post-metadata">

**Author:** ![Vutsuak16](https://avatars.discourse-cdn.com/v4/letter/v/ce7236/32.png) [@Vutsuak16](https://discuss.elastic.co/u/Vutsuak16)\
**Post date:** [March 6, 2017, 8:31am UTC](https://discuss.elastic.co/t/-grokparsefailure-help-required-asap/77426/4 "2017-03-06T08:31:45Z")

</div>

Thanks gautam and magnusbaeck it was a regex error. I debugged it and got the answer  
Regex I used  
grok {

```
    match =>{ "message" => "\[%{GREEDYDATA:InvoiceID}\,%{GREEDYDATA:PayerAccountId}\,%{GREEDYDATA:LinkedAccountId}\,%{GREEDYDATA:RecordType}\,%{GREEDYDATA:RecordId}\,%{GREEDYDATA:ProductName}\,%{GREEDYDATA:RateId}\,%{GREEDYDATA:SubscriptionId}\,%{GREEDYDATA:PricingPlanId}\,%{GREEDYDATA:UsageType}\,%{GREEDYDATA:Operation}\,%{GREEDYDATA:AvailabilityZone}\,%{GREEDYDATA:ReservedInstance}\,%{GREEDYDATA:ItemDescription}\,%{GREEDYDATA:UsageStartDate}\,%{GREEDYDATA:UsageEndDate}\,%{GREEDYDATA:UsageQuantity}\,%{GREEDYDATA:BlendedRate}\,%{GREEDYDATA:BlendedCost}\,%{GREEDYDATA:UnBlendedRate}\,%{GREEDYDATA:UnBlendedCost}\,%{GREEDYDATA:ResourceId}\,%{GREEDYDATA:aws:cloudformation:logical-id}\,%{GREEDYDATA:aws:cloudformation:stack-id}\,%{GREEDYDATA:aws:cloudformation:stack-name}\,%{GREEDYDATA:user:Application}\,%{GREEDYDATA:user:Project}\,%{GREEDYDATA:user:Stack}\,%{GREEDYDATA:user:cso_rollup1}\,%{GREEDYDATA:user:cso_rollup2}\,%{GREEDYDATA:user:cso_rollup3}\,%{GREEDYDATA:user:owner}\,%{GREEDYDATA:user:poc}\]" }
  }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 3, 2017, 8:31am UTC](https://discuss.elastic.co/t/-grokparsefailure-help-required-asap/77426/5 "2017-04-03T08:31:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
