# Application of grok pattern to the actual YAML

**URL:** <https://discuss.elastic.co/t/application-of-grok-pattern-to-the-actual-yaml/243877>\
**Category:** Logstash\
**Created:** [August 5, 2020, 1:51pm UTC](https://discuss.elastic.co/t/application-of-grok-pattern-to-the-actual-yaml/243877 "2020-08-05T13:51:32Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![eyts](https://avatars.discourse-cdn.com/v4/letter/e/58f4c7/32.png) [@eyts](https://discuss.elastic.co/u/eyts)\
**Post date:** [August 5, 2020, 1:51pm UTC](https://discuss.elastic.co/t/application-of-grok-pattern-to-the-actual-yaml/243877/1 "2020-08-05T13:51:33Z")

</div>

This is related to topic [Capturing all messages in a log](https://discuss.elastic.co/t/capturing-all-messages-in-a-log/243261).

I was able to parse the messages inside the log with ([%{QS:user\_msg1},)(?:|%{QS:user\_msg2},)(?:|%{QS:user\_msg3},).....(?:|%{QS:user\_msg10}]),"%{NOTSPACE}"

The grok debugger is accepting the grok pattern.

However, when I applied it to YAML:  
'grok {  
match =\> { "message" =\> ([%{QS:user\_msg1},)(?:|%{QS:user\_msg2},)(?:|%{QS:user\_msg3},).....(?:|%{QS:user\_msg10}]),"%{NOTSPACE}"}  
}'

I'm getting error: '"Expected one of #, ", ', -, [, { grok { match =\> { "message" =\> ([%{QS:user\_msg1},)(?:|%{QS:user\_msg2},)(?:|%{QS:user\_msg3},).....(?:|%{QS:user\_msg10}]),"%{NOTSPACE}"} }".'

I checked and doubled check that all {, [ and ( are matching.

I tried all the symbols suggested in the error message but I still got the same result.  
Would anybody have a clue what I'm missing here?

Appreciate any information.

Thank you.

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [August 5, 2020, 2:10pm UTC](https://discuss.elastic.co/t/application-of-grok-pattern-to-the-actual-yaml/243877/2 "2020-08-05T14:10:20Z")

</div>

Put single quotes around your grok pattern 🙂

---

<div class="post-metadata">

**Author:** ![eyts](https://avatars.discourse-cdn.com/v4/letter/e/58f4c7/32.png) [@eyts](https://discuss.elastic.co/u/eyts)\
**Post date:** [August 5, 2020, 2:30pm UTC](https://discuss.elastic.co/t/application-of-grok-pattern-to-the-actual-yaml/243877/3 "2020-08-05T14:30:06Z")

</div>

I already tried using #, ", ', -, [ but still same.  
Maybe i'm doing it wrong.  
Should it be like this?

grok {  
match =\> { "message" =\> '([%{QS:user\_msg1},)(?:|%{QS:user\_msg2},)(?:|%{QS:user\_msg3},).....(?:|%{QS:user\_msg10}])',"%{NOTSPACE}"}  
}

---

<div class="post-metadata">

**Author:** ![eyts](https://avatars.discourse-cdn.com/v4/letter/e/58f4c7/32.png) [@eyts](https://discuss.elastic.co/u/eyts)\
**Post date:** [August 5, 2020, 2:52pm UTC](https://discuss.elastic.co/t/application-of-grok-pattern-to-the-actual-yaml/243877/4 "2020-08-05T14:52:25Z")

</div>

Hi Jenni,

I tried putting the single quote in the different places and now it's working.

Thanks so much.

grok {  
match =\> { "message" =\> '([%{QS:user\_msg1},)(?:|%{QS:user\_msg2},)(?:|%{QS:user\_msg3},).....(?:|%{QS:user\_msg10}]),"%{NOTSPACE}"'}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 2, 2020, 2:52pm UTC](https://discuss.elastic.co/t/application-of-grok-pattern-to-the-actual-yaml/243877/5 "2020-09-02T14:52:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
