# GROK errors

**URL:** <https://discuss.elastic.co/t/grok-errors/273973>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 25, 2021, 3:58pm UTC](https://discuss.elastic.co/t/grok-errors/273973 "2021-05-25T15:58:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![NogNeetMachinaal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nogneetmachinaal/32/58893_2.png) [@NogNeetMachinaal](https://discuss.elastic.co/u/NogNeetMachinaal)\
**Post date:** [May 25, 2021, 3:58pm UTC](https://discuss.elastic.co/t/grok-errors/273973/1 "2021-05-25T15:58:52Z")

</div>

Everyone,

# Below 2 lines of syslog messages:

> ```
> 2021-05-15T14:24:35.235Z - Omada[Controller] [client:A6-09-A2-5A-31-E3] was disconnected from network "LAN (default)" on [osg:90-9A-4A-FD-0D-A5](connected t>
> 2021-05-15T14:24:42.762Z - Omada[Controller] [client:04-92-26-4A-F2-06] is connected to [osg:90-9A-4A-FD-0D-A5] on LAN (default) network.
> 
> ```

=====

This results in the following messages when doing a discovery in Kibana: "Provided Grok expressions do not match field value". Most like likely due to the fact that one of these has the phrase LAN (default) network in quotes.

What can be done to fix this?

Kind regards - Will

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [May 26, 2021, 7:12am UTC](https://discuss.elastic.co/t/grok-errors/273973/2 "2021-05-26T07:12:26Z")

</div>

I think you need to provide more details.

Which application are you running/which version?  
Which modules/fileset/metricset you're using?  
Did you check the module configuration in Elastic Beats repository?  
Did you try to use Grok debugger to figure out the difference?

---

<div class="post-metadata">

**Author:** ![NogNeetMachinaal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nogneetmachinaal/32/58893_2.png) [@NogNeetMachinaal](https://discuss.elastic.co/u/NogNeetMachinaal)\
**Post date:** [May 29, 2021, 4:36pm UTC](https://discuss.elastic.co/t/grok-errors/273973/3 "2021-05-29T16:36:50Z")

</div>

Thank you for the quick replay.

> Which application are you running/which version?

I'm running ELK as part of the 7.12

> Which modules/fileset/metricset you're using?

Only filebeat with a syslog feed based on rsyslog on an Ubuntu server version 20.04.02. The syslog-config is shown below:

```
# provides UDP syslog reception
module(load="imudp")
input(type="imudp" port="514")

# provides TCP syslog reception
module(load="imtcp")
input(type="imtcp" port="514")

# Write remote messages in different log => stop processing if done
if $fromhost-ip startswith '192.168.' then /var/log/syslog2elk.log
& stop

```

> Did you check the module configuration in Elastic Beats repository?

I activated the system module on FileBeat.  
And modified the system.yml - see below:

```
- module: system
  # Syslog
  syslog:
    enabled: true

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    var.paths: ["/var/log/syslog2elk.log"]

```

> Did you try to use Grok debugger to figure out the difference?

I don't know Grok debugger - let alone what to do with it.  
Any pointers here are helpful.

Thank you - Will

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 26, 2021, 6:36pm UTC](https://discuss.elastic.co/t/grok-errors/273973/4 "2021-06-26T18:36:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
