# Grok expression works in debugger but fails when posted on the pipeline simulation api

**URL:** <https://discuss.elastic.co/t/grok-expression-works-in-debugger-but-fails-when-posted-on-the-pipeline-simulation-api/160816>\
**Category:** Beats\
**Created:** [December 13, 2018, 9:17pm UTC](https://discuss.elastic.co/t/grok-expression-works-in-debugger-but-fails-when-posted-on-the-pipeline-simulation-api/160816 "2018-12-13T21:17:33Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dovid](https://avatars.discourse-cdn.com/v4/letter/d/e95f7d/32.png) [@Dovid](https://discuss.elastic.co/u/Dovid)\
**Post date:** [December 13, 2018, 9:17pm UTC](https://discuss.elastic.co/t/grok-expression-works-in-debugger-but-fails-when-posted-on-the-pipeline-simulation-api/160816/1 "2018-12-13T21:17:33Z")

</div>

Here is my simulate JSON

```
POST _ingest/pipeline/_simulate
{
  "pipeline": {
    "description": "ASDF log pipeline",
    "processors": [
      {
        "grok": {
          "field": "message",
          "patterns": [
            "%{TIMESTAMP_ISO8601:@timestamp} %{LOGLEVEL:level} %{WORD:namespace} .*? %{GREEDYDATA:message}"
          ]
        }
      }
    ]
  },
  "docs": [
    {
      "_source": {
        "@timestamp": "2018-12-13T20:58:12.651Z",
        "@metadata": {
          "beat": "filebeat",
          "type": "doc",
          "version": "6.2.1"
        },
        "message": "2018-12-12 10:15:29,697 DEBUG ASDF - OnLoadingDelayChangedCallback: 1, 2",
        "source": "C:\\ASDF\\serverlogs\\testlog.log",
        "offset": 158,
        "prospector": {
          "type": "log"
        },
        "beat": {
          "name": "ASDF",
          "hostname": "ASDF",
          "version": "6.2.1"
        }
      }
    }
  ]
}

```

This returns me the following error  
**"java.lang.IllegalArgumentException: java.lang.IllegalArgumentException: Provided Grok expressions do not match field value: [2018-12-12 10:15:29,697 DEBUG WayPoints - OnLoadingDelayChangedCallback: 1, 2]"**

I am struggling to understand as the grok appear to be valid when tested in the debugger

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 13, 2018, 9:39pm UTC](https://discuss.elastic.co/t/grok-expression-works-in-debugger-but-fails-when-posted-on-the-pipeline-simulation-api/160816/2 "2018-12-13T21:39:59Z")

</div>

You seem to have spaces before the colon in some of your pattern definitions. Can you try removing those?

---

<div class="post-metadata">

**Author:** ![Dovid](https://avatars.discourse-cdn.com/v4/letter/d/e95f7d/32.png) [@Dovid](https://discuss.elastic.co/u/Dovid)\
**Post date:** [December 13, 2018, 9:47pm UTC](https://discuss.elastic.co/t/grok-expression-works-in-debugger-but-fails-when-posted-on-the-pipeline-simulation-api/160816/3 "2018-12-13T21:47:29Z")

</div>

I tried removing the spaces. The simulation still error.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 13, 2018, 9:49pm UTC](https://discuss.elastic.co/t/grok-expression-works-in-debugger-but-fails-when-posted-on-the-pipeline-simulation-api/160816/4 "2018-12-13T21:49:44Z")

</div>

Strange, because this work for me:

```auto
POST _ingest/pipeline/_simulate
{
  "pipeline": {
    "description": "ASDF log pipeline",
    "processors": [
      {
        "grok": {
          "field": "message",
          "patterns": [
            "%{TIMESTAMP_ISO8601:@timestamp} %{LOGLEVEL:level} %{WORD:namespace} .*? %{GREEDYDATA:message}"
          ]
        }
      }
    ]
  },
  "docs": [
    {
      "_source": {
        "@timestamp": "2018-12-13T20:58:12.651Z",
        "@metadata": {
          "beat": "filebeat",
          "type": "doc",
          "version": "6.2.1"
        },
        "message": "2018-12-12 10:15:29,697 DEBUG ASDF - OnLoadingDelayChangedCallback: 1, 2",
        "source": "C:\\ASDF\\serverlogs\\testlog.log",
        "offset": 158,
        "prospector": {
          "type": "log"
        },
        "beat": {
          "name": "ASDF",
          "hostname": "ASDF",
          "version": "6.2.1"
        }
      }
    }
  ]
}

```

---

<div class="post-metadata">

**Author:** ![Dovid](https://avatars.discourse-cdn.com/v4/letter/d/e95f7d/32.png) [@Dovid](https://discuss.elastic.co/u/Dovid)\
**Post date:** [December 13, 2018, 9:53pm UTC](https://discuss.elastic.co/t/grok-expression-works-in-debugger-but-fails-when-posted-on-the-pipeline-simulation-api/160816/5 "2018-12-13T21:53:03Z")

</div>

It does not work here. I just started a major update from v5.6.9 to v6.5.3 ill let you know if this help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 10, 2019, 11:53pm UTC](https://discuss.elastic.co/t/grok-expression-works-in-debugger-but-fails-when-posted-on-the-pipeline-simulation-api/160816/6 "2019-01-10T23:53:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
