# Grok failure inspite of all pattern getting parsed

**URL:** <https://discuss.elastic.co/t/grok-failure-inspite-of-all-pattern-getting-parsed/171775>\
**Category:** Logstash\
**Created:** [March 11, 2019, 1:34pm UTC](https://discuss.elastic.co/t/grok-failure-inspite-of-all-pattern-getting-parsed/171775 "2019-03-11T13:34:12Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![manikandanid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manikandanid/32/91013_2.png) [@manikandanid](https://discuss.elastic.co/u/manikandanid)\
**Post date:** [March 11, 2019, 1:34pm UTC](https://discuss.elastic.co/t/grok-failure-inspite-of-all-pattern-getting-parsed/171775/1 "2019-03-11T13:34:12Z")

</div>

I have a grok pattern  
(?(\d{2})/(\d{2})/(\d{4}) (\d{2}):(\d{2}):(\d{2}).(\d{3}) [A,P]M):.\*::%{WORD:StudyAuthorityProviderType}: Serializing result stream of %{NUMBER:ImageSize:float} bytes for component %{NOTSPACE:abcid} in study %{NOTSPACE:xyzid}

and the message as

03/11/2019 08:56:41.909 AM:Debug:StorageService:0:\<3\> xyz:🔤:StudyResourceProvider::GetComponentByNameProvider: Serializing result stream of 262160 bytes for component 1.3.46.670589.33.1.63687812345677469000001.533575123467382911231059 in study 1.3.46.670589.33.1.63687123456789980900001.4667668482223205023

All the fields in the grok pattern is being populated but at the same time the tag contain grokparsefailure. Any idea why this is so ...

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 11, 2019, 1:52pm UTC](https://discuss.elastic.co/t/grok-failure-inspite-of-all-pattern-getting-parsed/171775/2 "2019-03-11T13:52:17Z")

</div>

What does your full config look like? Do you have any other grok expressions that could fail, in this or other files?

---

<div class="post-metadata">

**Author:** ![manikandanid](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manikandanid/32/91013_2.png) [@manikandanid](https://discuss.elastic.co/u/manikandanid)\
**Post date:** [March 12, 2019, 3:58am UTC](https://discuss.elastic.co/t/grok-failure-inspite-of-all-pattern-getting-parsed/171775/3 "2019-03-12T03:58:15Z")

</div>

You were right there was two grok filter inside one if condition which was causing this problem. For the benefit of user who might face the same problem, following is the change i did

if [document\_type] == "abc"  
{  
grok {  
match =\> {  
"message" =\> [  
"Filter 1",  
"Filter 2",  
"Filter 3"  
]  
}  
}  
kv {  
source =\> "uri\_query"  
field\_split =\> "&"  
target =\> "query"  
}  
grok {  
match =\> {  
"message" =\> [  
"(?(\d{2})/(\d{2})/(\d{4}) (\d{2}):(\d{2}):(\d{2}).(\d{3}) [A,P]M):.\*::%{WORD:StudyAuthorityProviderType}: Serializing result stream of %{NUMBER:ImageSize:float} bytes for component %{NOTSPACE:ImageInstanceUID} in study %{NOTSPACE:StudyUID}",  
"Filter 4",  
"Filter 5"  
]  
}  
}  
}

modified to

if [document\_type] == "abc"  
{  
grok {  
match =\> {  
"message" =\> [  
"Filter 1",  
"Filter 2",  
"Filter 3",  
"Filter 4",  
"(?(\d{2})/(\d{2})/(\d{4}) (\d{2}):(\d{2}):(\d{2}).(\d{3}) [A,P]M):.\*::%{WORD:StudyAuthorityProviderType}: Serializing result stream of %{NUMBER:ImageSize:float} bytes for component %{NOTSPACE:ImageInstanceUID} in study %{NOTSPACE:StudyUID}",  
"Filter 5"  
]  
}  
}  
kv {  
source =\> "uri\_query"  
field\_split =\> "&"  
target =\> "query"  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 9, 2019, 4:09am UTC](https://discuss.elastic.co/t/grok-failure-inspite-of-all-pattern-getting-parsed/171775/4 "2019-04-09T04:09:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
