# Custom grok pattern file parsing error

**URL:** <https://discuss.elastic.co/t/custom-grok-pattern-file-parsing-error/165493>\
**Category:** Logstash\
**Created:** [January 23, 2019, 10:25pm UTC](https://discuss.elastic.co/t/custom-grok-pattern-file-parsing-error/165493 "2019-01-23T22:25:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![cganesan](https://avatars.discourse-cdn.com/v4/letter/c/b9e5f3/32.png) [@cganesan](https://discuss.elastic.co/u/cganesan)\
**Post date:** [January 23, 2019, 10:25pm UTC](https://discuss.elastic.co/t/custom-grok-pattern-file-parsing-error/165493/1 "2019-01-23T22:25:07Z")

</div>

I have a custom grok pattern file with following regex patterns. I successfully tested these using regex online tool and it works fine however logstash fails to load the custom patterns file - see below. Appreciate your input.

**Custom Regex:**

```
LEVEL \[[A-Z][A-Z][A-Z][A-Z]*. *\]
CODE [[a-z][a-z][a-z]*. *\]

```

**Input** :  
[2019-01-08 01:49:04] [INFO] [abcd] No data file found, creating one and starting executor

**Logstash config:**  
filter {  
grok {  
patterns\_dir =\> ["/usr/share/logstash/pipeline/patterns"]  
match =\> { "message" =\> "%{LEVEL:level} %{CODE:code}" }  
}  
}

**Error**  
premature end of char-class: /(?LEVEL:level[[A-Z][A-Z][A-Z][A-Z]\*. _]) (?CODE:code[[a-z][a-z][a-z]_. \*])/m\>,

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 23, 2019, 10:39pm UTC](https://discuss.elastic.co/t/custom-grok-pattern-file-parsing-error/165493/2 "2019-01-23T22:39:55Z")

</div>

You need to edit your post and either select the regexps and click on \</\> or precede and follow them with a line containing just three backticks ```

Currently the formatting is changing what appears in the post. The italics suggest there might be underscores in there, but we cannot see them.

---

<div class="post-metadata">

**Author:** ![cganesan](https://avatars.discourse-cdn.com/v4/letter/c/b9e5f3/32.png) [@cganesan](https://discuss.elastic.co/u/cganesan)\
**Post date:** [January 24, 2019, 1:16am UTC](https://discuss.elastic.co/t/custom-grok-pattern-file-parsing-error/165493/3 "2019-01-24T01:16:44Z")

</div>

I have formatted the regex as you requested. Thanks for your time.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 21, 2019, 1:16am UTC](https://discuss.elastic.co/t/custom-grok-pattern-file-parsing-error/165493/4 "2019-02-21T01:16:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
