# Data is not coming as per custom template in kibana from logstash

**URL:** <https://discuss.elastic.co/t/data-is-not-coming-as-per-custom-template-in-kibana-from-logstash/170995>\
**Category:** Logstash\
**Created:** [March 5, 2019, 9:54pm UTC](https://discuss.elastic.co/t/data-is-not-coming-as-per-custom-template-in-kibana-from-logstash/170995 "2019-03-05T21:54:32Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![anujjai](https://avatars.discourse-cdn.com/v4/letter/a/f08c70/32.png) [@anujjai](https://discuss.elastic.co/u/anujjai)\
**Post date:** [March 5, 2019, 9:54pm UTC](https://discuss.elastic.co/t/data-is-not-coming-as-per-custom-template-in-kibana-from-logstash/170995/1 "2019-03-05T21:54:33Z")

</div>

Hi ,  
i am getting issue while displaying the content in kibana as per my template and can see error in log as \_grokparsefailure".  
we can see out template are getting install successfully in elastic search  
My configuration is

input {  
file {  
path =\> "C:/Anuj/ElasticSearch/DMS\_GTX-Process\_Archive.log"  
start\_position =\> "beginning"  
sincedb\_path =\> "NUL"  
codec =\> multiline {

```
  pattern => '^[0-9]{4}'
  negate => true
what => "previous"
}

```

}  
}  
filter {

mutate {  
gsub =\> ["message", "GMT", ""]  
}  
mutate {  
gsub =\> ["message", "-0800", ""]  
}

grok {  
match =\> { "message" =\>"%{SYSLOGTIMESTAMP :timestamp} %{NUMBER:num} %{USERNAME:Application} User [%{USERNAME :BWuser}] - %{USERNAME :job} [(?[a-zA-Z0-9./\s]+)]:%{GREEDYDATA:Log}" }  
overwrite =\> ["message"]  
}  
date {  
match =\> ["timestamp" , "yyyy MM dd HH:mm:ss,SSS"]  
}  
}

output {  
stdout { codec=\>rubydebug }  
elasticsearch {  
template\_overwrite =\> true  
template\_name =\> "bw-test"  
manage\_template =\> true  
template =\> "C:/Anuj/ElasticSearch/template/bw-gtx.json"  
hosts =\> ["localhost:9200"]  
index =\> "bw-test"

}

}

template is  
{  
"template": "bw-test\*",  
"order": 1,

```
"mappings": {
	"doc": {
		"dynamic": false,

		"properties": {
			"@timestamp": {
				"type": "date"
			},
			"loggedTime": {
				"type": "keyword"
			},

			"Application": {
				"type": "keyword"
			},

			"job": {
				"type": "keyword"
			},
			"BwPath": {
				"type": "keyword"
			},
			"Log": {
				"type": "keyword"
			}

		}
	}
}

```

}  
sample input is  
2019 Jan 09 16:16:23:897 GMT -0800 BW.DKS\_AAd-Process\_Archive User [BW-User] - Job-18454 [Processes/CDM Pub.process/Group/LogSN]: CIM CM publish -  
subj3 Data=\<?xml version="1.0" encoding="UTF-8"?\>

Output i can see in kibana is  
{  
"@version" =\> "1",  
"host" =\> "PC7745L",  
"message" =\> "2019 Jan 09 16:16:23:898 BW.ghh\_GgjhX-Process\_Archive User  
[BW-User] - Job-1454 [Processes/CkkM Pub.process/Log-Complete]: ChhkmM Outage pub  
lish process complete \r\n\r",  
"@timestamp" =\> 2019-03-05T21:41:15.788Z,  
"path" =\> "C:/Anuj/ElasticSearch/DklS\_GkhgX-Process\_Archive.log",  
"tags" =\> [  
[0] "multiline",  
[1] "\_grokparsefailure"  
]  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 5, 2019, 10:32pm UTC](https://discuss.elastic.co/t/data-is-not-coming-as-per-custom-template-in-kibana-from-logstash/170995/2 "2019-03-05T22:32:16Z")

</div>

Your timestamp does not match SYSLOGTIMESTAMP, and I do not see a NUMBER field following it. The square brackets need to be escaped and the optional unnamed capture group does not work. Also, your date filter needs MMM instead of MM, and a colon instead of a comma. Try

```
grok {
    match => { "message" =>"^%{YEAR:[@metadata][year]} %{SYSLOGTIMESTAMP:[@metadata][ts]} %{USERNAME:Application} User \[%{USERNAME:BWuser}\] - %{USERNAME:job} \[[^\]]*\]:%{GREEDYDATA:Log}" }
    add_field => { "timestamp" => "%{[@metadata][year]} %{[@metadata][ts]}" }
}
date { match => ["timestamp" , "yyyy MMM dd HH:mm:ss:SSS"] }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 2, 2019, 10:32pm UTC](https://discuss.elastic.co/t/data-is-not-coming-as-per-custom-template-in-kibana-from-logstash/170995/3 "2019-04-02T22:32:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
