# Filebeat "Provided Grok expressions do not match field value:" for /var/log/messages on RHEL7 with system module

**URL:** <https://discuss.elastic.co/t/filebeat-provided-grok-expressions-do-not-match-field-value-for-var-log-messages-on-rhel7-with-system-module/174616>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 29, 2019, 11:10pm UTC](https://discuss.elastic.co/t/filebeat-provided-grok-expressions-do-not-match-field-value-for-var-log-messages-on-rhel7-with-system-module/174616 "2019-03-29T23:10:19Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ian\_Bishop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ian_bishop/32/43138_2.png) [@Ian\_Bishop](https://discuss.elastic.co/u/Ian_Bishop)\
**Post date:** [March 29, 2019, 11:10pm UTC](https://discuss.elastic.co/t/filebeat-provided-grok-expressions-do-not-match-field-value-for-var-log-messages-on-rhel7-with-system-module/174616/1 "2019-03-29T23:10:20Z")

</div>

Hi, sorry for the massive title. I think that encapsulates what we're seeing. We have a completely new ELK install, with filebeat forwarding directly into elasticsearch. All /var/log/messages entries are failing to parse with "Provided Grok expressions do not match field value:" in the error.message field in ES/Kibana, and none of the fields in the message parsed.

Here's some examples of log messages:  
2019-03-29T15:48:37.038843-07:00 redacted sshd[32115]: error: Could not load host key: /etc/ssh/ssh\_host\_dsa\_key  
2019-03-29T15:48:50.472292-07:00 redacted su: (to root) ibishop on pts/1  
2019-03-29T15:48:58.094462-07:00 redacted rsyslogd: -- MARK --  
2019-03-29T15:49:58.153474-07:00 redacted rsyslogd: -- MARK --  
2019-03-29T15:50:58.213546-07:00 redacted rsyslogd: -- MARK --  
2019-03-29T15:51:10.884977-07:00 redacted iantest: asdflkjsdflkjsdflkj sldfjlsdkjf lsdj f

Same problem with the /var/log/secure logs.

Here's the json of one of the messages:

{  
"\_index": "filebeat-6.7.0-2019.03.29",  
"\_type": "doc",  
"\_id": "NBC1y2kBK6MrnDZw3pgy",  
"\_version": 1,  
"\_score": null,  
"\_source": {  
"offset": 910325,  
"log": {  
"file": {  
"path": "/var/log/messages"  
}  
},  
"prospector": {  
"type": "log"  
},  
"source": "/var/log/messages",  
"message": "2019-03-29T16:07:59.111429-07:00 redacted rsyslogd: -- MARK --",  
"fileset": {  
"module": "system",  
"name": "syslog"  
},  
"error": {  
"message": "Provided Grok expressions do not match field value: [2019-03-29T16:07:59.111429-07:00 redacted rsyslogd: -- MARK --]"  
},  
"input": {  
"type": "log"  
},  
"@timestamp": "2019-03-29T23:08:01.571Z",  
"beat": {  
"hostname": "redacted.redacted.redacted .com",  
"name": "[redacted.redacted.redacted.com](http://redacted.redacted.redacted.com)",  
"version": "6.7.0"  
},  
"host": {  
"os": {  
"codename": "Maipo",  
"name": "Red Hat Enterprise Linux Server",  
"family": "",  
"version": "7.6 (Maipo)",  
"platform": "rhel"  
},  
"containerized": true,  
"name": "[redacted.redacted.redacted.com](http://redacted.redacted.redacted.com)",  
"id": "21743549ee3f4395870848eb0bf59f29",  
"architecture": "x86\_64"  
},  
"event": {  
"dataset": "system.syslog"  
}  
},  
"fields": {  
"@timestamp": [  
"2019-03-29T23:08:01.571Z"  
]  
},  
"sort": [  
1553900881571  
]  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2019, 11:14pm UTC](https://discuss.elastic.co/t/filebeat-provided-grok-expressions-do-not-match-field-value-for-var-log-messages-on-rhel7-with-system-module/174616/2 "2019-04-26T23:14:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
