# Custom patterns in logstash that make logstash stop compiling

**URL:** <https://discuss.elastic.co/t/custom-patterns-in-logstash-that-make-logstash-stop-compiling/84236>\
**Category:** Logstash\
**Created:** [May 2, 2017, 10:39am UTC](https://discuss.elastic.co/t/custom-patterns-in-logstash-that-make-logstash-stop-compiling/84236 "2017-05-02T10:39:46Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Darya\_Semenova](https://avatars.discourse-cdn.com/v4/letter/d/7ba0ec/32.png) [@Darya\_Semenova](https://discuss.elastic.co/u/Darya_Semenova)\
**Post date:** [May 2, 2017, 10:39am UTC](https://discuss.elastic.co/t/custom-patterns-in-logstash-that-make-logstash-stop-compiling/84236/1 "2017-05-02T10:39:46Z")

</div>

I'd written a regular expression for the particular date format in my log (created ./patterns directory and file custom\_time\_pattern in it):

Date format: 2013-11-05T12:05:46.123456+03:00

```
CUSTOMTIMESTAMP ([0-9]{4,4})\-([0-9]{2,2})\-([0-9]{2,2})([A-Za-z])(:?2[0123]|[01]?[0-9])(:?[0-5][0-9])(:?(:?[0-5]?[0-9]|60)(:?[:.,][0-9]+)?)(\+?([0-5][0-9]):?([0-9][0-9]))

```

And then I used it in my filter:

```
filter {
    if [type] == "syslog" {
        grok {
            patterns_dir => ["./patterns"]
            remove_tag => ["_grokparsefailure"]
            match => {
                "message" => ["%{CUSTOMTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}", "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}", "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(\(etc/cron\.hourly\))(?:\[%{POSINT:syslog_pid}) %{GREEDYDATA:syslog_message}", "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\]) %{GREEDYDATA:syslog_message}"]
            }
    add_field => ["received_at", "%{@timestamp}"]
    add_field => ["received_from", "%{host}"]
        }
    }  
}

```

And logstash stopped working (a.k.a. it doesn't compile anymore).

The problem is that with adding custom patterns logstash stops compiling entirely. And by trying out some options, I got that the problem is in that part: "%{CUSTOMTIMESTAMP:syslog\_timestamp}". But I don't get the reason.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 30, 2017, 10:53am UTC](https://discuss.elastic.co/t/custom-patterns-in-logstash-that-make-logstash-stop-compiling/84236/2 "2017-05-30T10:53:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
