# Grok filter pattern not working

**URL:** <https://discuss.elastic.co/t/grok-filter-pattern-not-working/211780>\
**Category:** Logstash\
**Created:** [December 13, 2019, 11:19am UTC](https://discuss.elastic.co/t/grok-filter-pattern-not-working/211780 "2019-12-13T11:19:44Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![BeMoore](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bemoore/32/58724_2.png) [@BeMoore](https://discuss.elastic.co/u/BeMoore)\
**Post date:** [December 13, 2019, 12:19pm UTC](https://discuss.elastic.co/t/grok-filter-pattern-not-working/211780/5 "2019-12-13T12:19:19Z")

</div>

Its a space issue with the grok parsing.  
two images.... one stock as per your recommendation ( which we'd already tried )  
second with alteration to the username and inserting . between some and user

 ![1](https://us1.discourse-cdn.com/elastic/original/3X/6/9/69b958e94afa2893859dcb1f97b02106b90442a3.jpeg)  
 ![2](https://us1.discourse-cdn.com/elastic/original/3X/d/f/dfeba9e5a41bbc841a2c8ce03b10a55a683421a3.jpeg)

So im on 7.5 ES fully updated at the beginning on this week and in my mind, this means something has gone wrong with the existing patterns that %{USERNAME} makes use of, or something else is foobar'd in respect to how it parses "spaces" in data.  
This guy has exactly same issue

> [@\_grokparsefailure as soon as space in field](https://discuss.elastic.co/t/grokparsefailure-as-soon-as-space-in-field/211711/2):
>
> The first pattern does not work because inside square brackets period does not mean "any character", it means a literal period. The other two work for me. For example, input { generator { count =\> 1 lines =\> ['"foo bar"'] } } filter { grok { match =\> { "message" =\> "\"(?\<ip2\>[\S\s]+)\"" } } } output { stdout { codec =\> rubydebug { metadata =\> false } } } produces "ip2" =\> "foo bar", "message" =\> "\"foo bar\"",

---

_[View the full topic](https://discuss.elastic.co/t/grok-filter-pattern-not-working/211780)._
