# Grok filter compile error

**URL:** <https://discuss.elastic.co/t/grok-filter-compile-error/166599>\
**Category:** Logstash\
**Created:** [January 31, 2019, 3:55pm UTC](https://discuss.elastic.co/t/grok-filter-compile-error/166599 "2019-01-31T15:55:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![fefo69](https://avatars.discourse-cdn.com/v4/letter/f/b5a626/32.png) [@fefo69](https://discuss.elastic.co/u/fefo69)\
**Post date:** [January 31, 2019, 3:55pm UTC](https://discuss.elastic.co/t/grok-filter-compile-error/166599/1 "2019-01-31T15:55:20Z")

</div>

Hi,

I have the following log pattern

2019-01-31 01:27:48 10.24.32.4 POST 200 932 0.059 "394" - - - - - - /api/tbapi/services/oe/productinstances/findProductInstances?customerId=9151637854613445859&distributionChannelId=9150626251313798593&lightInit=false - - - - - - - - - -

And the following grok filter:

"%{DATE:date}%{SPACE}%{TIME:logtime}%{SPACE}%{IP:c-ip}%{SPACE}%{WORD:cs-method}%{SPACE}%{NUMBER:sc-status}%{SPACE}%{NUMBER:bytes:int}%{SPACE}%{NUMBER:duration:float}%{SPACE}(-|"(%{NUMBER:ContentLength})")%{SPACE}(-|%{WORD:x-nc.user})%{SPACE}(-|%{WORD:x-nctid})%{SPACE}(-|%{WORD:x-ncparentspan})%{SPACE}(-|%{WORD:x-ncspan})%{SPACE}(-|%{WORD:x-ncsampled})%{SPACE}(-|%{WORD:sXBSOICOMSUSER})%{SPACE}(-|%{URIPATHPARAM:cs-uri})%{SPACE}(-|%{WORD:x-ncsession})%{SPACE}(-|%{WORD:x-ncid})%{SPACE}(-|%{WORD:x-nctab})%{SPACE}(-|%{WORD:x-ncaction})%{SPACE}(-|%{WORD:x-details})%{SPACE}(-|%{WORD:cRequestID})%{SPACE}(-|%{WORD:cOperationID})%{SPACE}(-|%{WORD:sXBSOPROCESSID})%{SPACE}(-|%{URIPATHPARAM:cpageurl})%{SPACE}(-|%{WORD:cReferer})"

The issue is It compiles fine in grok debug sites like [https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/) but not in my logstash:

[ERROR] 2019-01-31 12:48:44.118 [Ruby-0-Thread-1: /usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/task.rb:22] agent - Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, {, } at line 11, column 206 (byte 268) after filter {\n\n grok {\n\n match =\> { "message" =\> "%{DATE:date}%{SPACE}%{TIME:logtime}%{SPACE}%{IP:c-ip}%{SPACE}%{WORD:cs-method}%{SPACE}%{NUMBER:sc-status}%{SPACE}%{NUMBER:bytes:int}%{SPACE}%{NUMBER:duration:float}%{SPACE}(-|"", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:42:in `compile_imperative'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:50:in`compile\_graph'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:12:in `block in compile_sources'", "org/jruby/RubyArray.java:2486:in`map'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:11:in `compile_sources'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:51:in`initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:169:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:40:in`execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:315:in `block in converge_state'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:141:in`with\_pipelines'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:312:in `block in converge_state'", "org/jruby/RubyArray.java:1734:in`each'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:299:in `converge_state'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:166:in`block in converge\_state\_and\_update'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:141:in `with_pipelines'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:164:in`converge\_state\_and\_update'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:90:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:348:in`block in execute'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/task.rb:24:in `block in initialize'"]}

Any idea?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 31, 2019, 4:03pm UTC](https://discuss.elastic.co/t/grok-filter-compile-error/166599/2 "2019-01-31T16:03:18Z")

</div>

> [@fefo69](#):
>
> "%{DATE:date}%{SPACE}%{TIME:logtime}%{SPACE}%{IP:c-ip}%{SPACE}%{WORD:cs-method}%{SPACE}%{NUMBER:sc-status}%{SPACE}%{NUMBER:bytes:int}%{SPACE}%{NUMBER:duration:float}%{SPACE}(-|"(%{NUMBER:ContentLength})")%{SPACE}(-|%{WORD:x-nc.user})%{SPACE}(-|%{WORD:x-nctid})%{SPACE}(-|%{WORD:x-ncparentspan})%{SPACE}(-|%{WORD:x-ncspan})%{SPACE}(-|%{WORD:x-ncsampled})%{SPACE}(-|%{WORD:sXBSOICOMSUSER})%{SPACE}(-|%{URIPATHPARAM:cs-uri})%{SPACE}(-|%{WORD:x-ncsession})%{SPACE}(-|%{WORD:x-ncid})%{SPACE}(-|%{WORD:x-nctab})%{SPACE}(-|%{WORD:x-ncaction})%{SPACE}(-|%{WORD:x-details})%{SPACE}(-|%{WORD:cRequestID})%{SPACE}(-|%{WORD:cOperationID})%{SPACE}(-|%{WORD:sXBSOPROCESSID})%{SPACE}(-|%{URIPATHPARAM:cpageurl})%{SPACE}(-|%{WORD:cReferer})"

You have double quotes embedded in the pattern. It is getting an error where it finds the first one. Either escape them using backslash or use single quotes around the entire pattern instead of double quotes.

---

<div class="post-metadata">

**Author:** ![fefo69](https://avatars.discourse-cdn.com/v4/letter/f/b5a626/32.png) [@fefo69](https://discuss.elastic.co/u/fefo69)\
**Post date:** [January 31, 2019, 8:07pm UTC](https://discuss.elastic.co/t/grok-filter-compile-error/166599/3 "2019-01-31T20:07:58Z")

</div>

It works! I'm using single quotes. Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 28, 2019, 8:08pm UTC](https://discuss.elastic.co/t/grok-filter-compile-error/166599/4 "2019-02-28T20:08:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
