# Greedydata does not work

**URL:** <https://discuss.elastic.co/t/greedydata-does-not-work/64032>\
**Category:** Logstash\
**Created:** [October 26, 2016, 4:55pm UTC](https://discuss.elastic.co/t/greedydata-does-not-work/64032 "2016-10-26T16:55:46Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![ally](https://avatars.discourse-cdn.com/v4/letter/a/8edcca/32.png) [@ally](https://discuss.elastic.co/u/ally)\
**Post date:** [October 26, 2016, 4:55pm UTC](https://discuss.elastic.co/t/greedydata-does-not-work/64032/1 "2016-10-26T16:55:46Z")

</div>

Hello,

I have Logstash v2.3 with the following configuration:  
\> input {  
\> beats {  
\> port =\> 5044  
\> }  
\> }  
\> filter {  
\> grok {  
\> match =\> ["message", "(?m)[%{HTTPDATE:msg\_timestamp}] [%{LOGLEVEL:log\_level}] %{GREEDYDATA:log\_message}"]  
\> }  
\> date {  
\> match =\> ["msg\_timestamp", "dd/MMM/YYYY:HH:mm:ss Z"]  
\> target =\> "@timestamp"  
\> }  
\> }  
\> output {  
\> elasticsearch {  
\> ...  
\> }

Moreover, I have the multiline pattern enabled in filebeat as:

> pattern: ^[  
> negate: true  
> match: after

As log\_message I'm expecting to have any kind of character in possibly multilines. So messages, as the following, should match but grok is failing:  
[26/Oct/2016:10:10:29 +0200] [DEBUG] Preparing/etc

However in [http://grokdebug.herokuapp.com/](http://grokdebug.herokuapp.com/) everything works perfectly. What should I change? Is there any known problem/bug with greedydata? What should I use instead?

Thanks in advance,  
Cheers

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 26, 2016, 5:32pm UTC](https://discuss.elastic.co/t/greedydata-does-not-work/64032/2 "2016-10-26T17:32:38Z")

</div>

I'm assuming you've escaped your square brackets, and if I make that change it works fine:

```nohighlight
$ cat test.config 
input { stdin { } }
output { stdout { codec => rubydebug } }
filter {
  grok {
    match => {
      "message" => "(?m)\[%{HTTPDATE:msg_timestamp}\] \[%{LOGLEVEL:log_level}\] %{GREEDYDATA:log_message}"
    }
  }
}
$ echo '[26/Oct/2016:10:10:29 +0200] [DEBUG] Preparing/etc' | logstash -f test.config
Settings: Default pipeline workers: 8
Pipeline main started
{
          "message" => "[26/Oct/2016:10:10:29 +0200] [DEBUG] Preparing/etc",
         "@version" => "1",
       "@timestamp" => "2016-10-26T17:31:02.403Z",
             "host" => "bertie",
    "msg_timestamp" => "26/Oct/2016:10:10:29 +0200",
        "log_level" => "DEBUG",
      "log_message" => "Preparing/etc"
}
Pipeline main has been shutdown
stopping pipeline {:id=>"main"}

```

---

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [October 26, 2016, 5:33pm UTC](https://discuss.elastic.co/t/greedydata-does-not-work/64032/3 "2016-10-26T17:33:12Z")

</div>

This match does not work against your example line

 ![](https://us1.discourse-cdn.com/elastic/original/2X/b/bbd6c573384818d24cf409e26edd4c2b2012a784.png)

HTTPDATE Does not seem to be correct, as the format

Oh it looks like you have not escaped the this has to be \[and \]

 ![](https://us1.discourse-cdn.com/elastic/original/2X/4/45b885fae6f1fc8a8f369c84728cd484940ca7c3.png)

---

<div class="post-metadata">

**Author:** ![ally](https://avatars.discourse-cdn.com/v4/letter/a/8edcca/32.png) [@ally](https://discuss.elastic.co/u/ally)\
**Post date:** [October 27, 2016, 8:08am UTC](https://discuss.elastic.co/t/greedydata-does-not-work/64032/4 "2016-10-27T08:08:01Z")

</div>

Ups, I didn't realise that it was escaped, it's like the following:  
(?m)\[%{HTTPDATE:msg\_timestamp}\] \[%{LOGLEVEL:log\_level}\] %{GREEDYDATA:log\_message}

I seem to have a problem with the escaping character. I have detected that messages like "XXXX /etc" work without any problem but other messages like "XXX/etc" do not. Please, note the space after the "/". What do you think could be the issue? Why is it that sometimes the "/" presents problems and sometimes it doesn't? I give an example below:

```
...
input_type log
message [26/Oct/2016:10:10:29 +0200] [DEBUG] Preparing/etc
offset 438,072
tags beats_input_codec_plain_applied, _grokparsefailure
...
```

---

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [October 27, 2016, 7:26pm UTC](https://discuss.elastic.co/t/greedydata-does-not-work/64032/5 "2016-10-27T19:26:41Z")

</div>

> [@ally](#):
>
> (?m)[%{HTTPDATE:msg\_timestamp}] [%{LOGLEVEL:log\_level}] %{GREEDYDATA:log\_message}

I don't see any issue and the line you provided works in grokdebuger. Greedydata takes everything

maybe the tag is getting set on a different filter? try add\_tag\_on\_falure =\> ["ANYTHING"] to this grok statement just to see if it still has a grok failure

> **[Grok filter plugin | Logstash Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html#plugins-filters-grok-tag_on_failure)**

If it does the "failure is coming from something else. otherwise if you can post your config

---

<div class="post-metadata">

**Author:** ![ally](https://avatars.discourse-cdn.com/v4/letter/a/8edcca/32.png) [@ally](https://discuss.elastic.co/u/ally)\
**Post date:** [November 1, 2016, 9:52am UTC](https://discuss.elastic.co/t/greedydata-does-not-work/64032/6 "2016-11-01T09:52:19Z")

</div>

That's the problem, there is no problem with the pattern match (also working in [http://grokdebug.herokuapp.com/](http://grokdebug.herokuapp.com/) ) but it's not running properly when there is a escape character. I have no other filter as I have posted in my configuration, so the problem is just coming from the grok:  
input {  
beats {  
port =\> 5044  
}  
}  
filter {  
grok {  
match =\> ["message", "(?m)\[%{HTTPDATE:msg\_timestamp}\] \[%{LOGLEVEL:log\_level}\] %{GREEDYDATA:log\_message}"]  
}  
date {  
match =\> ["msg\_timestamp", "dd/MMM/YYYY:HH:mm:ss Z"]  
target =\> "@timestamp"  
}  
}  
output {  
elasticsearch {  
...  
}

Is there anything that I should set? Anything I should be aware?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 1, 2016, 9:59am UTC](https://discuss.elastic.co/t/greedydata-does-not-work/64032/7 "2016-11-01T09:59:32Z")

</div>

```
match => {
    "message" => "(?m)\[%{HTTPDATE:msg_timestamp}\] \[%{LOGLEVEL:log_level}\] %{GREEDYDATA:log_message}"
}

```

What you are showing above does not look correct. Have you tried with the **exact configuration** Magnus provided in his example above?

---

<div class="post-metadata">

**Author:** ![ally](https://avatars.discourse-cdn.com/v4/letter/a/8edcca/32.png) [@ally](https://discuss.elastic.co/u/ally)\
**Post date:** [November 1, 2016, 10:03am UTC](https://discuss.elastic.co/t/greedydata-does-not-work/64032/8 "2016-11-01T10:03:36Z")

</div>

Yes, it is what I'm trying. I was editing my answer when you replied. I forgot again to escape here.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 1, 2016, 10:08am UTC](https://discuss.elastic.co/t/greedydata-does-not-work/64032/9 "2016-11-01T10:08:25Z")

</div>

But that is not exactly what Magnus provided. You syntax is wrong. Either copy the entire filter configuration from the example (not just the expression) or have a look in [the documentation](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html) to see how a match clause should be constructed.

---

<div class="post-metadata">

**Author:** ![ally](https://avatars.discourse-cdn.com/v4/letter/a/8edcca/32.png) [@ally](https://discuss.elastic.co/u/ally)\
**Post date:** [November 17, 2016, 10:14am UTC](https://discuss.elastic.co/t/greedydata-does-not-work/64032/10 "2016-11-17T10:14:28Z")

</div>

I have tried that syntax but still does not work. It might be a problem with escaping character, not about how the grok is built. Any suggestion?

> input {  
> beats {  
> port =\> 5044  
> }  
> }  
> filter {  
> grok {  
> match =\> {"message" =\> "(?m)\[%{HTTPDATE:msg\_timestamp}\] \[%{LOGLEVEL:log\_level}\] %{GREEDYDATA:log\_message}"}  
> }  
> date {  
> match =\> ["msg\_timestamp", "dd/MMM/YYYY:HH:mm:ss Z"]  
> target =\> "@timestamp"  
> }  
> }  
> output {  
> elasticsearch {  
> ...  
> }

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 17, 2016, 10:28am UTC](https://discuss.elastic.co/t/greedydata-does-not-work/64032/11 "2016-11-17T10:28:21Z")

</div>

Can you replace the elasticsearch output with `stdout { codec => rubydebug }` and show us the output and exactly what is not working?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:30am UTC](https://discuss.elastic.co/t/greedydata-does-not-work/64032/12 "2017-07-06T04:30:26Z")

</div>


