# Grok filter pattern not working

**URL:** <https://discuss.elastic.co/t/grok-filter-pattern-not-working/211780>\
**Category:** Logstash\
**Created:** [December 13, 2019, 11:19am UTC](https://discuss.elastic.co/t/grok-filter-pattern-not-working/211780 "2019-12-13T11:19:44Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![BeMoore](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bemoore/32/58724_2.png) [@BeMoore](https://discuss.elastic.co/u/BeMoore)\
**Post date:** [December 13, 2019, 11:19am UTC](https://discuss.elastic.co/t/grok-filter-pattern-not-working/211780/1 "2019-12-13T11:19:44Z")

</div>

I must be going mad today, i can't get this filter to work.  
I extracted a single log line from an azure activity log, so i parse it through grok debugger both in kibana and herokuapp and i can't get it to work. so i split it out and chopped it down to try and isolate why its not working

`'createdDateTime': '2019-12-11T09:06:47.5489252Z', 'userDisplayName': 'Some User, 'userPrincipalName': 'some.user@custom.domain`

and the pattern

`(\')%{TIMESTAMP_ISO8601:timestamp}(\'),\s(\')%{USER:userDisplayName}(\'),\s(\')%{WORD:principlename}(\')`

and in both debuggers, it doesn't return anything, yet the individual usages work....  
i know its friday, and its been a long slog this week, but im not surely missing something so simple here am i ?

---

<div class="post-metadata">

**Author:** ![ITIC](https://avatars.discourse-cdn.com/v4/letter/i/90ced4/32.png) [@ITIC](https://discuss.elastic.co/u/ITIC)\
**Post date:** [December 13, 2019, 11:41am UTC](https://discuss.elastic.co/t/grok-filter-pattern-not-working/211780/2 "2019-12-13T11:41:35Z")

</div>

Hi

It might be a typo, but your line is missing some "'" that you are trying to parse in your pattern.

Otherwise, I think your `match`, assuming your line is in `message`, could be something like this:

```auto
"messge" => "'createdDateTime': '%{TIMESTAMP_ISO8601:timestamp}', 'userDisplayName': '%{USER:userDisplayName}, 'userPrincipalName': '%{GREEDYDATA:principlename}"

```

Hope this helps

---

<div class="post-metadata">

**Author:** ![BeMoore](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bemoore/32/58724_2.png) [@BeMoore](https://discuss.elastic.co/u/BeMoore)\
**Post date:** [December 13, 2019, 11:54am UTC](https://discuss.elastic.co/t/grok-filter-pattern-not-working/211780/3 "2019-12-13T11:54:44Z")

</div>

> [@ITIC](#):
>
> "messge" =\> "'createdDateTime': '%{TIMESTAMP\_ISO8601:timestamp}', 'userDisplayName': '%{USER:userDisplayName}, 'userPrincipalName': '%{GREEDYDATA:principlename}"

Nope, thats not working either. However its got something to do with , followed by a space. The parsing breaks there.  
with the data i should be able to parse it with just the following line

`'createdDateTime': '%{TIMESTAMP_ISO8601:timestamp}', 'userDisplayName': '%{USER:userDisplayName}, 'userPrincipalName': '%{GREEDYDATA:principlename}`

but it doesn't ☹

Yet each one works on its own with its own data, except when inline with , and a space. in my logic, including the, and a \s should eliminate this but its not, hence banging my head on the table repeatedly this morning each time this doesn't work.!

 ![Capture](https://us1.discourse-cdn.com/elastic/original/3X/7/8/783bd616987c3f226885feebde5bc7910c10abb3.jpeg)  
this should work  
 ![1](https://us1.discourse-cdn.com/elastic/original/3X/9/5/95eb5b453d75849695995988a11f728644529056.jpeg)  
but it dosn't  
 ![Capture1](https://us1.discourse-cdn.com/elastic/original/3X/2/e/2eea86768faf543bc109585e0fa15413f8b278cb.jpeg)  
this works without , and a space

---

<div class="post-metadata">

**Author:** ![ITIC](https://avatars.discourse-cdn.com/v4/letter/i/90ced4/32.png) [@ITIC](https://discuss.elastic.co/u/ITIC)\
**Post date:** [December 13, 2019, 12:03pm UTC](https://discuss.elastic.co/t/grok-filter-pattern-not-working/211780/4 "2019-12-13T12:03:16Z")

</div>

Hi

Looking at your pictures I see the "'" are not missing in your line, so the filter should be

```auto
"messge" => "'createdDateTime': '%{TIMESTAMP_ISO8601:timestamp}', 'userDisplayName': '%{USER:userDisplayName}', 'userPrincipalName': '%{GREEDYDATA:principlename}'"

```

This should work. If it doesn't I'll start also banging my head on the table 😄

---

<div class="post-metadata">

**Author:** ![BeMoore](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bemoore/32/58724_2.png) [@BeMoore](https://discuss.elastic.co/u/BeMoore)\
**Post date:** [December 13, 2019, 12:19pm UTC](https://discuss.elastic.co/t/grok-filter-pattern-not-working/211780/5 "2019-12-13T12:19:19Z")

</div>

Its a space issue with the grok parsing.  
two images.... one stock as per your recommendation ( which we'd already tried )  
second with alteration to the username and inserting . between some and user

 ![1](https://us1.discourse-cdn.com/elastic/original/3X/6/9/69b958e94afa2893859dcb1f97b02106b90442a3.jpeg)  
 ![2](https://us1.discourse-cdn.com/elastic/original/3X/d/f/dfeba9e5a41bbc841a2c8ce03b10a55a683421a3.jpeg)

So im on 7.5 ES fully updated at the beginning on this week and in my mind, this means something has gone wrong with the existing patterns that %{USERNAME} makes use of, or something else is foobar'd in respect to how it parses "spaces" in data.  
This guy has exactly same issue

> [@\_grokparsefailure as soon as space in field](https://discuss.elastic.co/t/grokparsefailure-as-soon-as-space-in-field/211711/2):
>
> The first pattern does not work because inside square brackets period does not mean "any character", it means a literal period. The other two work for me. For example, input { generator { count =\> 1 lines =\> ['"foo bar"'] } } filter { grok { match =\> { "message" =\> "\"(?\<ip2\>[\S\s]+)\"" } } } output { stdout { codec =\> rubydebug { metadata =\> false } } } produces "ip2" =\> "foo bar", "message" =\> "\"foo bar\"",

---

<div class="post-metadata">

**Author:** ![BeMoore](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bemoore/32/58724_2.png) [@BeMoore](https://discuss.elastic.co/u/BeMoore)\
**Post date:** [December 13, 2019, 12:22pm UTC](https://discuss.elastic.co/t/grok-filter-pattern-not-working/211780/6 "2019-12-13T12:22:33Z")

</div>

![tenor](https://us1.discourse-cdn.com/elastic/original/3X/4/a/4a51929a08d5fbd8c58a064d318917583aaf643d.gif)

---

<div class="post-metadata">

**Author:** ![BeMoore](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bemoore/32/58724_2.png) [@BeMoore](https://discuss.elastic.co/u/BeMoore)\
**Post date:** [December 13, 2019, 12:24pm UTC](https://discuss.elastic.co/t/grok-filter-pattern-not-working/211780/7 "2019-12-13T12:24:23Z")

</div>

and doesn't appear to be anything related in the 7.5.0 change log for this.

---

<div class="post-metadata">

**Author:** ![BeMoore](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bemoore/32/58724_2.png) [@BeMoore](https://discuss.elastic.co/u/BeMoore)\
**Post date:** [December 13, 2019, 12:25pm UTC](https://discuss.elastic.co/t/grok-filter-pattern-not-working/211780/8 "2019-12-13T12:25:32Z")

</div>

btw... to get around this, %{DATA:username} works

---

<div class="post-metadata">

**Author:** ![ITIC](https://avatars.discourse-cdn.com/v4/letter/i/90ced4/32.png) [@ITIC](https://discuss.elastic.co/u/ITIC)\
**Post date:** [December 13, 2019, 12:32pm UTC](https://discuss.elastic.co/t/grok-filter-pattern-not-working/211780/9 "2019-12-13T12:32:28Z")

</div>

You are right! Neither `USER` nor `USERNAME` allow for spaces in their definitions (see [https://github.com/elastic/logstash/blob/v1.4.2/patterns/grok-patterns](https://github.com/elastic/logstash/blob/v1.4.2/patterns/grok-patterns)), so you have to use `DATA` or `GREEDYDATA` or similar.

I didn't catch that one!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 10, 2020, 12:32pm UTC](https://discuss.elastic.co/t/grok-filter-pattern-not-working/211780/10 "2020-01-10T12:32:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
