# Grok filter works in debugger but not in logstash

**URL:** <https://discuss.elastic.co/t/grok-filter-works-in-debugger-but-not-in-logstash/359903>\
**Category:** Logstash\
**Created:** [May 21, 2024, 9:45am UTC](https://discuss.elastic.co/t/grok-filter-works-in-debugger-but-not-in-logstash/359903 "2024-05-21T09:45:07Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![s0p4L1n3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s0p4l1n3/32/128200_2.png) [@s0p4L1n3](https://discuss.elastic.co/u/s0p4L1n3)\
**Post date:** [May 21, 2024, 9:45am UTC](https://discuss.elastic.co/t/grok-filter-works-in-debugger-but-not-in-logstash/359903/1 "2024-05-21T09:45:07Z")

</div>

Hi,

I want to monitor windows registry event.  
I have a grok filter to extract 2 values of registry path and put them in matching fields.

The target field is `winlog.event_data.ObjectName`

- Kibana displayed value: `\REGISTRY\MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9459C573-B17A-45AE-9F64-1857B5D58CEE}`

- Json displayed value: `\\REGISTRY\\MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{9459C573-B17A-45AE-9F64-1857B5D58CEE}`

```auto
filter {
  #we tells logstash to lookup for the csv if tags field contains windowsregistry string
  if [tags] =~ "windowsregistry" {
    grok { match => { "[winlog][event_data][ObjectName]" => "\\REGISTRY\%{WORD:[winlog][event_data][RegistryType]}\\%{WORD:[winlog][event_data][RegistryHiveType]}\\" } }
  }
}

```

I've tried with double `\\` or simple `\` or even `\\\\` but none of them works. Do you have any ideas ?

Also Logstash in its error logs, read the escape `\` as if its doubled amount.  
If I double `\\` logstash reads `\\\\`, If I `\\\\` logstash reads `\\\\\\\\`

Note: I'm migrating from previous solution Graylogs where grok patterns used is this one (with `\\\\` as escape:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/e/0e37f104b5990e917b30d84b77a026eddbb837c2.png)

Thank you !

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 21, 2024, 10:38am UTC](https://discuss.elastic.co/t/grok-filter-works-in-debugger-but-not-in-logstash/359903/2 "2024-05-21T10:38:34Z")

</div>

> [@s0p4L1n3](#):
>
> ```auto
> grok { match => { "[winlog][event_data][ObjectName]" => "\\REGISTRY\%{WORD:[winlog][event_data][RegistryType]}\\%{WORD:[winlog][event_data][RegistryHiveType]}\\" } }
>   
> 
> ```

There are two changes you need to make to this

```
 match => { "[winlog][event_data][ObjectName]" => "\\REGISTRY\\%{WORD:[winlog][event_data][RegistryType]}\\%{WORD:[winlog][event_data][RegistryHiveType]}\\."

```

Note the second backslash after REGISTRY, and the . added at the end of the pattern. You cannot escape a backslash at the end of a quoted string. The configuration parser will always interpret that as escaping the quote. So ...

```
input { generator { count => 1 lines => ['\REGISTRY\MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9459C573-B17A-45AE-9F64-1857B5D58CEE}'] } }

output { stdout { codec => rubydebug { metadata => false } } }
filter { 
    mutate { rename => { "message" => "[winlog][event_data][ObjectName]" } }
    grok { match => { "[winlog][event_data][ObjectName]" => "\\REGISTRY\\%{WORD:[winlog][event_data][RegistryType]}\\%{WORD:[winlog][event_data][RegistryHiveType]}\\." } }
}

```

will produce

```
    "winlog" => {
    "event_data" => {
            "RegistryType" => "MACHINE",
        "RegistryHiveType" => "SOFTWARE",
              "ObjectName" => "\\REGISTRY\\MACHINE\\SOFTWARE\\Microsoft\\Active Setup\\Installed Components\\{9459C573-B17A-45AE-9F64-1857B5D58CEE}"
    }
},

```

---

<div class="post-metadata">

**Author:** ![s0p4L1n3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s0p4l1n3/32/128200_2.png) [@s0p4L1n3](https://discuss.elastic.co/u/s0p4L1n3)\
**Post date:** [May 21, 2024, 12:10pm UTC](https://discuss.elastic.co/t/grok-filter-works-in-debugger-but-not-in-logstash/359903/3 "2024-05-21T12:10:02Z")

</div>

Thank you it work BUT I had to remove the if statement do make it work, I searching why it is not working with my condition.

I would prefer to run the filter only if this tags appears, otherwise it will try to apply the filter on every event log.

```auto
filter {
  #we tells logstash to lookup for the csv if tags field contains windowsregistry string
# if [tags] =~ "windowsregistry" {

    grok { match => { "[winlog][event_data][ObjectName]" => "\\REGISTRY\\%{WORD:[winlog][event_data][RegistryType]}\\%{WORD:[winlog][event_data][RegistryHiveType]}\\." } }

    translate {
      source => "[winlog][event_data][OperationType]"
      target => "[winlog][event_data][OperationTypeDescription]"
      dictionary_path => "/usr/share/logstash/pipeline/winlogbeat/csv/Windows-Registry-Code-to-CodeDescription.csv"
      refresh_interval => 60
      refresh_behaviour => replace
      fallback => "No Code Description Found"
     }

    translate {
      source => "[winlog][event_data][OldValueType]"
      target => "[winlog][event_data][OldValueTypeDescription]"
      dictionary_path => "/usr/share/logstash/pipeline/winlogbeat/csv/Windows-Registry-Code-to-CodeDescription.csv"
      refresh_interval => 60
      refresh_behaviour => replace
      fallback => "No Code Description Found"
     }

    translate {
      source => "[winlog][event_data][NewValueType]"
      target => "[winlog][event_data][NewValueTypeDescription]"
      dictionary_path => "/usr/share/logstash/pipeline/winlogbeat/csv/Windows-Registry-Code-to-CodeDescription.csv"
      refresh_interval => 60
      refresh_behaviour => replace
      fallback => "No Code Description Found"
     }

  #}
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 21, 2024, 12:17pm UTC](https://discuss.elastic.co/t/grok-filter-works-in-debugger-but-not-in-logstash/359903/4 "2024-05-21T12:17:06Z")

</div>

> [@s0p4L1n3](#):
>
> `if [tags] =~ "windowsregistry"`

[tags] is an array. If you want to test whether one of the array entries is "windowsregistry" then use

```
if "windowsregistry" in [tags] {...

```

---

<div class="post-metadata">

**Author:** ![s0p4L1n3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s0p4l1n3/32/128200_2.png) [@s0p4L1n3](https://discuss.elastic.co/u/s0p4L1n3)\
**Post date:** [May 21, 2024, 12:27pm UTC](https://discuss.elastic.co/t/grok-filter-works-in-debugger-but-not-in-logstash/359903/5 "2024-05-21T12:27:27Z")

</div>

I was reading this info on the doc because I tested with `if [event][action] =~ "Registry"` it works.

And because one of my other filters if condition contains also a regex match like this:  
`if [winlog][channel] =~ "Security" {`

And after I realized that its an array field and not [winlog][channel]

Some details are tricky ! I just need time to get used to it.

Thank you again !
