# GROK filter throws ERROR

**URL:** <https://discuss.elastic.co/t/grok-filter-throws-error/143424>\
**Category:** Logstash\
**Created:** [August 8, 2018, 5:04am UTC](https://discuss.elastic.co/t/grok-filter-throws-error/143424 "2018-08-08T05:04:19Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raghuveer\_SJ](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@Raghuveer\_SJ](https://discuss.elastic.co/u/Raghuveer_SJ)\
**Post date:** [August 8, 2018, 5:04am UTC](https://discuss.elastic.co/t/grok-filter-throws-error/143424/1 "2018-08-08T05:04:19Z")

</div>

I have written a filter to parse logs based on some condition :

```
filter {

	if [message] =~ "\tat" {
		grok {
		  match => ["message", "^(\tat)"]
		  add_tag => ["stacktrace"]
		}
    }
  
  grok {

	  if([fields][log_type] == "tomcat" || [fields][log_type] == "wildfy") {

		match => [
			"message",'^%{TIMESTAMP_ISO8601:timestamp} %{LOGLEVEL:level}%{SPACE}\[%{JAVACLASS:class}\] (\(%{DATA:thread}\) )?%{GREEDYDATA:logMessage}$', #spring logs
			"message",'^%{IPORHOST:clientip} - - \[%{HTTPDATE:timestamp}\] "(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})" %{NUMBER:response} (?:%{NUMBER:bytes}|-)', #tomcat logs		
			"message",'^%{TIMESTAMP_ISO8601:timestamp} %{LOGLEVEL:level}\s+\[(?<package>[a-z.]*)\] \(%{DATA:thread}\) (?<WILDFY_CODE>[A-Z0-9]*): %{GREEDYDATA:log}$' #wildfy
		]		
	  }
	  
	  else {
		match => [
				"message",'%{GREEDYDATA:walla}'
		]	
	  }
    }
}

```

and the exception that I see when I start logstash is :

`[ERROR][logstash.agent] Failed to execute action {:action=>LogStash::PipelineAction::Create/pipeline_id:main, :exception=>"LogStash::ConfigurationError", :message=>"Expected one of #, => at line 21, column 6 (byte 174) after filter {\n\n\tif [message] =~ \"\\tat\" {\n\t\tgrok {\n\t\t match => [\"message\", \"^(\\tat)\"]\n\t\t add_tag => [\"stacktrace\"]\n\t\t}\n }\n\n grok {\n\n\t if", :backtrace=>["C:/tools/logstash-6.3.0/logstash-core/lib/logstash/compiler.rb:42:in`compile\_imperative'", "C:/tools/logstash-6.3.0/logstash-core/lib/logstash/compiler.rb:50:in `compile_graph'", "C:/tools/logstash-6.3.0/logstash-core/lib/logstash/compiler.rb:12:in`block in compile\_sources'", "org/jruby/RubyArray.java:2486:in `map'", "C:/tools/logstash-6.3.0/logstash-core/lib/logstash/compiler.rb:11:in`compile\_sources'", "C:/tools/logstash-6.3.0/logstash-core/lib/logstash/pipeline.rb:49:in `initialize'", "C:/tools/logstash-6.3.0/logstash-core/lib/logstash/pipeline.rb:167:in`initialize'", "C:/tools/logstash-6.3.0/logstash-core/lib/logstash/pipeline\_action/create.rb:40:in `execute'", "C:/tools/logstash-6.3.0/logstash-core/lib/logstash/agent.rb:305:in`block in converge\_state'"]}`

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 8, 2018, 5:25am UTC](https://discuss.elastic.co/t/grok-filter-throws-error/143424/2 "2018-08-08T05:25:22Z")

</div>

You can not have conditionals within a filter definition. Move the conditionals outside the grok block and instead specify multiple grok blocks.

---

<div class="post-metadata">

**Author:** ![Raghuveer\_SJ](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@Raghuveer\_SJ](https://discuss.elastic.co/u/Raghuveer_SJ)\
**Post date:** [August 8, 2018, 5:40am UTC](https://discuss.elastic.co/t/grok-filter-throws-error/143424/3 "2018-08-08T05:40:41Z")

</div>

Can you please correct the snippet if in error ?

```
filter {
    	if [message] =~ "\tat" {
    		grok {
    		  match => ["message", "^(\tat)"]
    		  add_tag => ["stacktrace"]
    		}
        }
	
	if ([fields][log_type] == "tomcat") {
    mutate {
      replace => {
        "[type]" => "tomcat"
      }
    }
  }
  else if ([fields][log_type] == "wildfy") {
    mutate {
      replace => {
        "[type]" => "wildfy"
      }
    }
  }
  
  grok {

	  if(%{type} == "tomcat" || %{type} == "wildfy") {

		match => [
			"message",'^%{TIMESTAMP_ISO8601:timestamp} %{LOGLEVEL:level}%{SPACE}\[%{JAVACLASS:class}\] (\(%{DATA:thread}\) )?%{GREEDYDATA:logMessage}$', #spring logs
			"message",'^%{IPORHOST:clientip} - - \[%{HTTPDATE:timestamp}\] "(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})" %{NUMBER:response} (?:%{NUMBER:bytes}|-)', #tomcat logs		
			"message",'^%{TIMESTAMP_ISO8601:timestamp} %{LOGLEVEL:level}\s+\[(?<package>[a-z.]*)\] \(%{DATA:thread}\) (?<WILDFY_CODE>[A-Z0-9]*): %{GREEDYDATA:log}$' #wildfy
		]		
	  }
	  
	  else {
		match => [
				"message",'%{GREEDYDATA:walla}'
		]	
	  }
    }
}
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 8, 2018, 5:53am UTC](https://discuss.elastic.co/t/grok-filter-throws-error/143424/4 "2018-08-08T05:53:58Z")

</div>

Apart from the problem Chrstian mentioned,

> ```
> if(%{type} == "tomcat" || %{type} == "wildfy") {
> 
> ```

is wrong. Change to

```
  if [type] == "tomcat" or [type] == "wildfy" {

```

or

```
  if [type] in ["tomcat", "wildfy"] {

```

---

<div class="post-metadata">

**Author:** ![Raghuveer\_SJ](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@Raghuveer\_SJ](https://discuss.elastic.co/u/Raghuveer_SJ)\
**Post date:** [August 8, 2018, 6:39am UTC](https://discuss.elastic.co/t/grok-filter-throws-error/143424/5 "2018-08-08T06:39:32Z")

</div>

As you have suggest in [Multiline issue with 2 different patterns for a single event](https://discuss.elastic.co/t/multiline-issue-with-2-different-patterns-for-a-single-event/57896/5) I have put :

```
beats {
	port=>5044
	multiline {
	  pattern => "^%{TIMESTAMP_ISO8601}"
	  negate => true
	  what => "previous"
	}
}

```

and in the beginning of filter before anything I have put :

`overwrite => ["message"]`

should this configuration work for parsing.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 8, 2018, 6:55am UTC](https://discuss.elastic.co/t/grok-filter-throws-error/143424/6 "2018-08-08T06:55:01Z")

</div>

If you are getting data from Filebeat you should consider performing the multiline processing there instead. You always want to do this as close to the source as possible.

---

<div class="post-metadata">

**Author:** ![Raghuveer\_SJ](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@Raghuveer\_SJ](https://discuss.elastic.co/u/Raghuveer_SJ)\
**Post date:** [August 8, 2018, 7:03am UTC](https://discuss.elastic.co/t/grok-filter-throws-error/143424/7 "2018-08-08T07:03:35Z")

</div>

```
filebeat.inputs:

- type: log
  enabled: true
  paths:
    - C:/data/logs_server/apache-tomcat-8.0.39.log
  fields: {log_type: tomcat}
  multiline.pattern: '^[[:space:]]+(at|\.{3})\b|^Caused by:'
  multiline.negate: false
  multiline.match: after

```

I am using the above pattern in file beat but logstash is throwing error can you please suggest ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 8, 2018, 7:07am UTC](https://discuss.elastic.co/t/grok-filter-throws-error/143424/8 "2018-08-08T07:07:12Z")

</div>

> I am using the above pattern in file beat but logstash is throwing error can you please suggest ?

Without seeing the Logstash error we can't help out.

---

<div class="post-metadata">

**Author:** ![Raghuveer\_SJ](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@Raghuveer\_SJ](https://discuss.elastic.co/u/Raghuveer_SJ)\
**Post date:** [August 8, 2018, 7:08am UTC](https://discuss.elastic.co/t/grok-filter-throws-error/143424/9 "2018-08-08T07:08:04Z")

</div>

I have posted it in my original post, in the beginning itself.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 8, 2018, 7:15am UTC](https://discuss.elastic.co/t/grok-filter-throws-error/143424/10 "2018-08-08T07:15:45Z")

</div>

Oh, that error. As we've said put conditionals outside the grok filter.

```nohighlight
if ... {
  grok { ... }
} else {
  grok { ... }
}
```

---

<div class="post-metadata">

**Author:** ![Raghuveer\_SJ](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@Raghuveer\_SJ](https://discuss.elastic.co/u/Raghuveer_SJ)\
**Post date:** [August 8, 2018, 7:17am UTC](https://discuss.elastic.co/t/grok-filter-throws-error/143424/11 "2018-08-08T07:17:47Z")

</div>

With all the updates I am getting the following exception:

> [ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, { at line 16, column 12 (byte 160) after filter {\n\n\toverwrite ", :backtrace=\>["C:/tools/logstash-6.3.0/logstash-core/lib/logstash/compiler.rb:42:in `compile_imperative'", "C:/tools/logstash-6.3.0/logstash-core/lib/logstash/compiler.rb:50:in `compile\_graph'", "C:/tools/logstash-6.3.0/logstash-core/lib/logstash/compiler.rb:12:in `block in compile_sources'", "org/jruby/RubyArray.java:2486:in `map'", "C:/tools/logstash-6.3.0/logstash-core/lib/logstash/compiler.rb:11:in `compile_sources'", "C:/tools/logstash-6.3.0/logstash-core/lib/logstash/pipeline.rb:49:in `initialize'", "C:/tools/logstash-6.3.0/logstash-core/lib/logstash/pipeline.rb:167:in `initialize'", "C:/tools/logstash-6.3.0/logstash-core/lib/logstash/pipeline_action/create.rb:40:in `execute'", "C:/tools/logstash-6.3.0/logstash-core/lib/logstash/agent.rb:305:in `block in converge\_state'"]}  
> [2018-08-08T12:51:30,487][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

So my filebeat config is

```
filebeat.inputs:

- type: log
  enabled: true
  paths:
    - C:/data/logs_server/apache-tomcat-8.0.39.log
  fields: {log_type: tomcat}
  multiline.pattern: '^[[:space:]]+(at|\.{3})\b|^Caused by:'
  multiline.negate: false
  multiline.match: after

```

My logstash config is

```
input {

beats {
	port=>5044
	codec => multiline {
	  pattern => "^%{TIMESTAMP_ISO8601}"
	  negate => true
	  what => "previous"
	}
}

}

filter {

	overwrite => ["message"]

	if [message] =~ "\tat" {
		grok {
		  match => ["message", "^(\tat)"]
		  add_tag => ["stacktrace"]
		}
    }
	
	if ([fields][log_type] == "tomcat") {
    mutate {
      replace => {
        "[type]" => "tomcat"
      }
    }
  }
  else if ([fields][log_type] == "wildfy") {
    mutate {
      replace => {
        "[type]" => "wildfy"
      }
    }
  }
  
  if [type] in ["tomcat", "wildfy"] {
	  grok {  

			match => [
				"message",'^%{TIMESTAMP_ISO8601:betimestamp} %{LOGLEVEL:logLevel}%{SPACE}\[%{JAVACLASS:className}\] (\(%{DATA:threadName}\) )?%{GREEDYDATA:logMessage}$'
			]
		}
	} else {
		  grok {
			match => [
					"message",'%{GREEDYDATA:unparsedText}'
			]	
		  }
		}	 
}

```

Please suggest.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 8, 2018, 7:46am UTC](https://discuss.elastic.co/t/grok-filter-throws-error/143424/12 "2018-08-08T07:46:18Z")

</div>

> overwrite =\> ["message"]

Remove.

---

<div class="post-metadata">

**Author:** ![Raghuveer\_SJ](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@Raghuveer\_SJ](https://discuss.elastic.co/u/Raghuveer_SJ)\
**Post date:** [August 8, 2018, 8:58am UTC](https://discuss.elastic.co/t/grok-filter-throws-error/143424/13 "2018-08-08T08:58:24Z")

</div>

Done. Am using 6.3.x version of ELK stack. Still the exception is there but has changed as :

`[ERROR][logstash.pipeline] Error registering plugin {:pipeline_id=>"main", :plugin=>"<LogStash::Inputs::Beats port=>5044, codec=><LogStash::Codecs::Multiline pattern=>\"^%{TIMESTAMP_ISO8601}\", negate=>true, what=>\"previous\", id=>\"a1da3fb1-8767-44c0-a30d-19230430f5ae\", enable_metric=>true, charset=>\"UTF-8\", multiline_tag=>\"multiline\", max_lines=>500, max_bytes=>10485760>, id=>\"38208dd42da36e7ce6566aa40fac509ec2c67190e9b450a69ed80be203672a0e\", enable_metric=>true, host=>\"0.0.0.0\", ssl=>false, ssl_verify_mode=>\"none\", include_codec_tag=>true, ssl_handshake_timeout=>10000, tls_min_version=>1, tls_max_version=>1.2, cipher_suites=>[\"TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384\", \"TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384\", \"TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256\", \"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256\", \"TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384\", \"TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384\", \"TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256\", \"TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256\"], client_inactivity_timeout=>60, executor_threads=>4>", :error=>"Multiline codec with beats input is not supported. Please refer to the beats documentation for how to best manage multiline data. See https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html", :thread=>"#<Thread:0x24284407 run>"}`  
[ERROR][logstash.pipeline] Pipeline aborted due to error {:pipeline\_id=\>"main", :exception=\>#\<LogStash::ConfigurationError: Multiline codec with beats input is not supported. Please refer to the beats documentation for how to best manage multiline data. See [https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html](https://www.elastic.co/guide/en/beats/filebeat/current/multiline-examples.html)\>, :backtrace=\>["C:/tools/logstash-6.3.0/vendor/bundle/jruby/2.3.0/gems/logstash-input-beats-5.0.14-java/lib/logstash/inputs/beats.rb:153:in `register'", "C:/tools/logstash-6.3.0/logstash-core/lib/logstash/pipeline.rb:340:in`register\_plugin'", "C:/tools/logstash-6.3.0/logstash-core/lib/logstash/pipeline.rb:351:in `block in register_plugins'", "org/jruby/RubyArray.java:1734:in`each'", "C:/tools/logstash-6.3.0/logstash-core/lib/logstash/pipeline.rb:351:in `register_plugins'", "C:/tools/logstash-6.3.0/logstash-core/lib/logstash/pipeline.rb:498:in`start\_inputs'", "C:/tools/logstash-6.3.0/logstash-core/lib/logstash/pipeline.rb:392:in `start_workers'", "C:/tools/logstash-6.3.0/logstash-core/lib/logstash/pipeline.rb:288:in`run'", "C:/tools/logstash-6.3.0/logstash-core/lib/logstash/pipeline.rb:248:in `block in start'"], :thread=\>"#\<Thread:0x24284407 run\>"}  
[2018-08-08T14:38:46,039][ERROR][logstash.agent] Failed to execute action {:id=\>:main, :action\_type=\>LogStash::ConvergeResult::FailedAction, :message=\>"Could not execute action: PipelineAction::Create, action\_result: false", :backtrace=\>nil}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 8, 2018, 9:45am UTC](https://discuss.elastic.co/t/grok-filter-throws-error/143424/14 "2018-08-08T09:45:55Z")

</div>

But the error message tells you in plain English what the problem is and links to the relevant documentation.

---

<div class="post-metadata">

**Author:** ![Raghuveer\_SJ](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@Raghuveer\_SJ](https://discuss.elastic.co/u/Raghuveer_SJ)\
**Post date:** [August 8, 2018, 9:47am UTC](https://discuss.elastic.co/t/grok-filter-throws-error/143424/15 "2018-08-08T09:47:26Z")

</div>

And that's what I am also using if you see my filebeat configuration file.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 8, 2018, 9:48am UTC](https://discuss.elastic.co/t/grok-filter-throws-error/143424/16 "2018-08-08T09:48:23Z")

</div>

Then delete the multiline codec in your Logstash configuration.

---

<div class="post-metadata">

**Author:** ![Raghuveer\_SJ](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@Raghuveer\_SJ](https://discuss.elastic.co/u/Raghuveer_SJ)\
**Post date:** [August 8, 2018, 10:17am UTC](https://discuss.elastic.co/t/grok-filter-throws-error/143424/17 "2018-08-08T10:17:54Z")

</div>

yes done that, but how to add all my error stacktraces as a single group ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 8, 2018, 12:07pm UTC](https://discuss.elastic.co/t/grok-filter-throws-error/143424/18 "2018-08-08T12:07:24Z")

</div>

That's what a proper multiline configuration should take care of. I don't know what your logs look like so I can't make a concrete suggestion, but the [Timestamps example from the documentation](https://www.elastic.co/guide/en/beats/filebeat/current/_examples_of_multiline_configuration.html#_timestamps) is probably what you're looking for.

---

<div class="post-metadata">

**Author:** ![Raghuveer\_SJ](https://avatars.discourse-cdn.com/v4/letter/r/2bfe46/32.png) [@Raghuveer\_SJ](https://discuss.elastic.co/u/Raghuveer_SJ)\
**Post date:** [August 9, 2018, 3:58am UTC](https://discuss.elastic.co/t/grok-filter-throws-error/143424/19 "2018-08-09T03:58:27Z")

</div>

The exception stacktrace is a typical JAVA exception. As a sample I can have :

```
2018-08-03 16:55:06.470 [ThreadPoolTaskScheduler-4] ERROR o.s.s.s.TaskUtils$LoggingErrorHandler.handleError - Unexpected error occurred in scheduled task.
com.mongodb.MongoSocketReadTimeoutException: Timeout while receiving message
	at com.mongodb.connection.InternalStreamConnection.translateReadException(InternalStreamConnection.java:477)
	at com.mongodb.connection.InternalStreamConnection.receiveMessage(InternalStreamConnection.java:228)
	at com.mongodb.connection.UsageTrackingInternalConnection.receiveMessage(UsageTrackingInternalConnection.java:96)
	...
	at java.lang.Thread.run(Thread.java:745)
Caused by: java.net.SocketTimeoutException: Read timed out
	at java.net.SocketInputStream.socketRead0(Native Method)
	...
	at com.mongodb.connection.InternalStreamConnection.receiveMessage(InternalStreamConnection.java:224)
	... 31 common frames omitted

```

or

```
2018-08-07 15:26:02.404 [DefaultQuartzScheduler_Worker-1] ERROR org.slf4j.helpers.SubstituteLogger.error - Unable to start/stop JMX
javax.management.InstanceAlreadyExistsException: com.jolbox.bonecp:type=BoneCP
	at com.sun.jmx.mbeanserver.Repository.addMBean(Repository.java:437)
	at com.sun.jmx.interceptor.DefaultMBeanServerInterceptor.registerWithRepository(DefaultMBeanServerInterceptor.java:1898)
	at com.sun.jmx.interceptor.DefaultMBeanServerInterceptor.registerDynamicMBean(DefaultMBeanServerInterceptor.java:966)
	...
	at org.quartz.simpl.SimpleThreadPool$WorkerThread.run(SimpleThreadPool.java:573)
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 9, 2018, 7:38am UTC](https://discuss.elastic.co/t/grok-filter-throws-error/143424/20 "2018-08-09T07:38:26Z")

</div>

Okay, so a pretty standard log. Follow the Timestamps example (minor adjustments might be necessary).

[Next page](https://discuss.elastic.co/t/grok-filter-throws-error/143424.md?page=2)
