# Can't parse after optionnal field has been set

**URL:** <https://discuss.elastic.co/t/cant-parse-after-optionnal-field-has-been-set/272253>\
**Category:** Logstash\
**Created:** [May 6, 2021, 8:23am UTC](https://discuss.elastic.co/t/cant-parse-after-optionnal-field-has-been-set/272253 "2021-05-06T08:23:24Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Travis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/travis/32/54079_2.png) [@Travis](https://discuss.elastic.co/u/Travis)\
**Post date:** [May 6, 2021, 8:23am UTC](https://discuss.elastic.co/t/cant-parse-after-optionnal-field-has-been-set/272253/1 "2021-05-06T08:23:24Z")

</div>

Hello !

I'm working on Cisco WSA logs. Some fields are optionnal. In particular, the filed which contains username infomation: sometimes we have **"DOMAIN\smith@AD"** and sometimes we have just **-**

When username is present, all is ok. But when username is "-", I can't parse what is following

Log sample with no issue :

> \<14\>May 06 08:31:53 ACCESS\_LOGS: Info: 1620282712.713 0 10.31.199.115 TCP\_DENIED/407 0 CONNECT tunnel://nexus.officeapps.live.com:443/ "CORP\smith@AD1" DATA1

Grok pattern :

`<%{POSINT:syslog_pri}>(%{SYSLOGTIMESTAMP:syslog_timestamp}) %{WORD:log_type}: %{WORD:syslog_facility}: %{NUMBER:timestamp} %{INT:elaspsed_time} %{IP:client_ip} %{WORD:result_code}/%{NUMBER:response_code} %{NUMBER:response_size} %{WORD:http_method} (%{URIPROTO:http_protocol}://)?%{IPORHOST:dst_host}(?::%{POSINT:port})?(?:%{NOTSPACE:uri_param})? ("%{WORD:Domain}\\%{USERNAME:user}@%{WORD:DomainController}")? %{WORD:TESTDATA}`

Log sample with issue :

> \<14\>May 06 08:31:53 ACCESS\_LOGS: Info: 1620282712.713 0 10.31.199.115 TCP\_DENIED/407 0 CONNECT tunnel://nexus.officeapps.live.com:443/ - DATA1

=\> no match on grok debug

Thanks for your help

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [May 6, 2021, 8:30am UTC](https://discuss.elastic.co/t/cant-parse-after-optionnal-field-has-been-set/272253/2 "2021-05-06T08:30:52Z")

</div>

Hello Travis,

The problem is that optional fields either exist or do not exist. In your case, the value is not missing but it is replaced with a dash. Therefore, your grok pattern fails. The fix is easy - replace your username pattern with the following:  
`("%{WORD:Domain}\\%{USERNAME:user}@%{WORD:DomainController}"|-)`

This means that either a username with domain is expected or a dash.

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![Travis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/travis/32/54079_2.png) [@Travis](https://discuss.elastic.co/u/Travis)\
**Post date:** [May 6, 2021, 8:40am UTC](https://discuss.elastic.co/t/cant-parse-after-optionnal-field-has-been-set/272253/3 "2021-05-06T08:40:42Z")

</div>

Hello Wolfram,

Yes sounds logic now... it works perfectly. Thanks a lot !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 3, 2021, 8:41am UTC](https://discuss.elastic.co/t/cant-parse-after-optionnal-field-has-been-set/272253/4 "2021-06-03T08:41:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
