# Grok crash if line ending by backslash

**URL:** <https://discuss.elastic.co/t/grok-crash-if-line-ending-by-backslash/216441>\
**Category:** Logstash\
**Created:** [January 24, 2020, 2:25pm UTC](https://discuss.elastic.co/t/grok-crash-if-line-ending-by-backslash/216441 "2020-01-24T14:25:48Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![djgreg13](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/djgreg13/32/61386_2.png) [@djgreg13](https://discuss.elastic.co/u/djgreg13)\
**Post date:** [January 24, 2020, 2:25pm UTC](https://discuss.elastic.co/t/grok-crash-if-line-ending-by-backslash/216441/1 "2020-01-24T14:25:48Z")

</div>

Hello, i have a field pushed by a beat with this content

"D:\Logs\IIS\[test.domain.com](http://test.domain.com)\20191219.log

So i write the following grok for extract [test.domain.com](http://test.domain.com)

```auto
grok {
                match => {
                    "[log][file][path]" => [
                        "D:\\Logs\\IIS\\%{GREEDYDATA:application.name}\\"
                    ]
                }
            }

```

And grok crash with a parse failure, if i try this grok

```auto
grok {
                match => {
                    "[log][file][path]" => [
                        "D:\\Logs\\IIS\\%{GREEDYDATA:application.name}\\%{GREEDYDATA}"
                    ]
                }
            }

```

the output of application.name is : [test.domain.com](http://test.domain.com)\20191219.log

so my final logstash grok is

```auto
grok {
                match => {
                    "[log][file][path]" => [
                        "D:\\Logs\\IIS\\%{GREEDYDATA:application.name}\\2%{GREEDYDATA}"
                    ]
                }
            }

```

and now it's OK application.name is [test.domain.com](http://test.domain.com)

if i try on kibana grok debugger the first expression, the output is correct

So is it an issue of grok ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 24, 2020, 3:00pm UTC](https://discuss.elastic.co/t/grok-crash-if-line-ending-by-backslash/216441/2 "2020-01-24T15:00:42Z")

</div>

That could be [this](https://github.com/elastic/logstash/issues/9701) issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 21, 2020, 3:06pm UTC](https://discuss.elastic.co/t/grok-crash-if-line-ending-by-backslash/216441/3 "2020-02-21T15:06:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
