# Filebeat mongo module, grok pattern is incorrect for Mongo 4

**URL:** <https://discuss.elastic.co/t/filebeat-mongo-module-grok-pattern-is-incorrect-for-mongo-4/149767>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 25, 2018, 5:45am UTC](https://discuss.elastic.co/t/filebeat-mongo-module-grok-pattern-is-incorrect-for-mongo-4/149767 "2018-09-25T05:45:36Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Matthew\_Zeemann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matthew_zeemann/32/30067_2.png) [@Matthew\_Zeemann](https://discuss.elastic.co/u/Matthew_Zeemann)\
**Post date:** [September 25, 2018, 5:45am UTC](https://discuss.elastic.co/t/filebeat-mongo-module-grok-pattern-is-incorrect-for-mongo-4/149767/1 "2018-09-25T05:45:36Z")

</div>

I am trying to use Filebeat to send MongoDB 4 logs to Elastic and it is failing.

I have a log messages from Mongo that grok is failing to match against the supplied fields, e.g.

`2018-09-25T05:16:13.012+0000 I STORAGE [WT RecordStoreThread: local.oplog.rs] WiredTiger record store oplog truncation finished in: 1ms`

This results in:  
`Provided Grok expressions do not match field value: [2018-09-25T05:16:13.012+0000 I STORAGE [WT RecordStoreThread: local.oplog.rs] WiredTiger record store oplog truncation finished in: 1ms]`

I am using the packaged filter from  
`/usr/share/filebeat/module/mongodb/log/ingest/pipeline.json`

containing  
`"grok": { "field": "message", "patterns":["%{TIMESTAMP_ISO8601:mongodb.log.timestamp} %{WORD:mongodb.log.severity} %{WORD:mongodb.log.component} \\s*\\[%{WORD:mongodb.log.context}\\] %{GREEDYDATA:mongodb.log.message}" ], "ignore_missing": true }`

Based on the documentation ([https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields-mongodb.html](https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields-mongodb.html))

```
mongodb.log.context
type: keyword

example: initandlisten

Context of message

```

So mongodb.log.context is a keyword, but the message I get from Mongo is clearly no longer a single word, e.g.  
`[WT RecordStoreThread: local.oplog.rs]`

My question is are there any known workarounds for this issue?

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [September 26, 2018, 1:08pm UTC](https://discuss.elastic.co/t/filebeat-mongo-module-grok-pattern-is-incorrect-for-mongo-4/149767/2 "2018-09-26T13:08:58Z")

</div>

Hello @Matthew_Zeemann, I took a quick look at the code and you are right this is seems a new behavior in mongo 4 the tests that we have in place are for 3.x.

I think changing the **WORD** pattern for **GREEDYDATA** will work in that case. Something like the following.

```auto
`"%{TIMESTAMP_ISO8601:mongodb.log.timestamp} 
%{WORD:mongodb.log.severity} %{WORD:mongodb.log.component} 
\\s*\\[%{GREEDYDATA:mongodb.log.context}\\] %{GREEDYDATA:mongodb.log.message}"

```

Can you create an issue on our issue tracker for that? if you can test it out that would be awesome.

> **[elastic/beats](https://github.com/elastic/beats/)**
>
> :tropical\_fish: Beats - Lightweight shippers for Elasticsearch & Logstash - elastic/beats

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 24, 2018, 3:09pm UTC](https://discuss.elastic.co/t/filebeat-mongo-module-grok-pattern-is-incorrect-for-mongo-4/149767/3 "2018-10-24T15:09:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
