# Grok filter does not match message

**URL:** <https://discuss.elastic.co/t/grok-filter-does-not-match-message/78128>\
**Category:** Logstash\
**Created:** [March 10, 2017, 10:17am UTC](https://discuss.elastic.co/t/grok-filter-does-not-match-message/78128 "2017-03-10T10:17:45Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![andre22](https://avatars.discourse-cdn.com/v4/letter/a/d07c76/32.png) [@andre22](https://discuss.elastic.co/u/andre22)\
**Post date:** [March 10, 2017, 10:17am UTC](https://discuss.elastic.co/t/grok-filter-does-not-match-message/78128/1 "2017-03-10T10:17:46Z")

</div>

Hi,

when importing the following log lines, they are getting into Elasticsearch without being matched by grok:

`2017-02-16 00:03:03 202.152.71.0 - www.host.ch GET /content/specialinterest var1=234&var3=876234 200 - - Mozilla/5.0+(Windows+NT+6.1)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/56.0.2924.87+Safari/537.36 - https://www.refer.com/ par1=123&par2=12354 - get-2017-02-16-00-00000-srvname logidentifier_234523`

Here's my logstash.yml:

```
input {
# beats {
# port => 5044
# }
  file {
    path => "/home/elk/logtest1/*"
    start_position => "beginning"
    codec => plain {
       charset => "ISO-8859-1"
   }  
     }
      }
filter {
  grok {
    match => { "message" => "%{TIMESTAMP_ISO8601} %{IP:ip} %{USERNAME:username} %{HOSTNAME:host} %{WORD:method} %{URIPATH:uri} %{NOTSPACE:uriryy} %{NUMBER:status}$ %{NOTSPACE:bytes} %{NOTSPACE:version} %{NOTSPACE:UserAgent} %{NOTSPACE:Cookie} %{NOTSPACE:Referer} %{NOTSPACE:gv-var} %{NOTSPACE:var_xyv} %{NOTSPACE:origin} %{NOTSPACE:id5}" }
  }
  }
output {
  elasticsearch { hosts => ["localhost:9200"] }
  stdout { codec => rubydebug }
  }

```

checking in Kibana, the whole log line is within the message field.

I also tried `match => { "message" => "\A%{TIMESTAMP_ISO8601}` without success

What could be wrong here?

---

<div class="post-metadata">

**Author:** ![andre22](https://avatars.discourse-cdn.com/v4/letter/a/d07c76/32.png) [@andre22](https://discuss.elastic.co/u/andre22)\
**Post date:** [March 10, 2017, 11:24am UTC](https://discuss.elastic.co/t/grok-filter-does-not-match-message/78128/2 "2017-03-10T11:24:05Z")

</div>

> [@andre22](#):
>
> %{TIMESTAMP\_ISO8601} %{IP:ip} %{USERNAME:username} %{HOSTNAME:host} %{WORD:method} %{URIPATH:uri} %{NOTSPACE:uriryy} %{NUMBER:status}$ %{NOTSPACE:bytes} %{NOTSPACE:version} %{NOTSPACE:UserAgent} %{NOTSPACE:Cookie} %{NOTSPACE:Referer} %{NOTSPACE:gv-var} %{NOTSPACE:var\_xyv} %{NOTSPACE:origin} %{NOTSPACE:id5}" }  
> }

I found it, there was a typo in the grok term 😫

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 7, 2017, 11:24am UTC](https://discuss.elastic.co/t/grok-filter-does-not-match-message/78128/3 "2017-04-07T11:24:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
