# Grok - every fields is putted into message

**URL:** <https://discuss.elastic.co/t/grok-every-fields-is-putted-into-message/155214>\
**Category:** Logstash\
**Created:** [November 2, 2018, 5:37pm UTC](https://discuss.elastic.co/t/grok-every-fields-is-putted-into-message/155214 "2018-11-02T17:37:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rschirin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rschirin/32/45283_2.png) [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Post date:** [November 2, 2018, 5:37pm UTC](https://discuss.elastic.co/t/grok-every-fields-is-putted-into-message/155214/1 "2018-11-02T17:37:41Z")

</div>

hi all,  
I'm sending messages from Filebeat to Logstash where I will used Grok to parse correctly and then send to Elastic.  
The first step, from FB to LS works correctly.  
unfortunately, when I try to apply Grok I got all the fields directly into `message` field.

here my `logstash.conf`:

```
input { 
	beats {
      		port => 5045
	}
}

filter {
 if [message] =~ "^#" {
  drop {}
 }
 grok {
        break_on_match => false
        match => [
            "message", ".*calling addr\=\\"%{IPV4:client}\/%{INT:client port}\\".*called_addr\=\\"%{IPV4:server}\/%{INT:server port}\\".*login\=\\"%{USERNAME:username}\\"",
			"message", ".*Connection Failure, reason :\s*%{GREEDYDATA:message}",
            "message", ".*CGate\s*%{GREEDYDATA:message}"
        ]
    }
}

output {
 if [CrifBeats] == "ft_audit"{
  elasticsearch { 		
   hosts => ["localhost:9200"]
   index => "ftaudit-%{+YYYY.MM.dd}"
  }
 }
}

```

using grok debugger at [http://grokdebug.herokuapp.com/](http://grokdebug.herokuapp.com/) it works correctly but when message is parsed in my LS I get everything into message field.  
I was sure that grok should be able to create/add indicated fields.  
I know that I'm doing something wrong but I cannot understand where.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 4, 2018, 1:47pm UTC](https://discuss.elastic.co/t/grok-every-fields-is-putted-into-message/155214/2 "2018-11-04T13:47:32Z")

</div>

Does specifying the [overwrite parameter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html#plugins-filters-grok-overwrite) help?

---

<div class="post-metadata">

**Author:** ![rschirin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rschirin/32/45283_2.png) [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Post date:** [November 5, 2018, 8:44pm UTC](https://discuss.elastic.co/t/grok-every-fields-is-putted-into-message/155214/3 "2018-11-05T20:44:03Z")

</div>

The issue was due to the used regex. Basically, it was not matched so new fields were not created

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 3, 2018, 8:44pm UTC](https://discuss.elastic.co/t/grok-every-fields-is-putted-into-message/155214/4 "2018-12-03T20:44:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
