# Grok from nginx-module gets error

**URL:** <https://discuss.elastic.co/t/grok-from-nginx-module-gets-error/143473>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 8, 2018, 9:49am UTC](https://discuss.elastic.co/t/grok-from-nginx-module-gets-error/143473 "2018-08-08T09:49:59Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![g.myznikov.tinkoff](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/g.myznikov.tinkoff/32/33582_2.png) [@g.myznikov.tinkoff](https://discuss.elastic.co/u/g.myznikov.tinkoff)\
**Post date:** [August 8, 2018, 9:49am UTC](https://discuss.elastic.co/t/grok-from-nginx-module-gets-error/143473/1 "2018-08-08T09:49:59Z")

</div>

Hello!  
I have nginx-module enabled in filebeat.yml:

```auto
filebeat.modules:
- module: nginx
  access:
    var.paths: ["/testvar/nginx/access.log"]
  error:
    var.paths: ["/testvar/nginx/error.log"]

output.elasticsearch:
  hosts: ["localhost:9200"]

setup.kibana:
  host: "localhost:5601"
```

And all logs like:

```auto
127.0.0.1 - 127.0.0.2 - [02/Aug/2018:11:57:45 +0300] "adress.ru" "POST /smth" 
```

are parsed in ElasticSearch. But with logs like:

```auto
-- 127.0.0.2 - [02/Aug/2018:11:57:45 +0300] "adress.ru" "POST /smth"
```

Kibana gets filed **message.error** with entry like:

```auto
Provided Grok expressions do not match field value:[...]
```

Any thoughts what I can do to improve my nginx-module?

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [August 8, 2018, 2:27pm UTC](https://discuss.elastic.co/t/grok-from-nginx-module-gets-error/143473/2 "2018-08-08T14:27:04Z")

</div>

Thanks @g.myznikov.tinkoff

> [@g.myznikov.tinkoff](#):
>
> -- 127.0.0.2 - [02/Aug/2018:11:57:45 +0300] "[adress.ru](http://adress.ru)" "POST /smth"

I have added the above line in our integration test suite and I can reproduce the error:

```auto
AssertionError: not error expected but got: {u'beat': {u'hostname': u'sashimi', u'name': u'sashimi', u'version': u'7.0.0-alpha1'}, u'@timestamp': u'2018-08-08T14:20:02.157Z', u'offset': 2346, u'fileset': {u'name': u'access', u'module': u'nginx'}, u'source': u'/Users/ph/go/src/github.com/elastic/beats/filebeat/module/nginx/access/test/access.log', u'host': {u'name': u'sashimi'}, u'error': {u'message': u'Provided Grok expressions do not match field value: [-- 127.0.0.2 - [02/Aug/2018:11:57:45 +0300] \\"adress.ru\\" \\"POST /smth\\"]'}, u'input': {u'type': u'log'}, u'message': u'-- 127.0.0.2 - [02/Aug/2018:11:57:45 +0300] "adress.ru" "POST /smth"', u'prospector': {u'type': u'log'}}

```

It look like that the following grok pattern is stricter than some real world use case.

```auto
 "pattern_definitions": {
        "IP_LIST": "%{IP}(\"?,?\\s*%{IP})*"
},

```

Can you tell me what is the version of nginx you are running? Also are you using the default log format for nginx or a custom one?

---

<div class="post-metadata">

**Author:** ![g.myznikov.tinkoff](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/g.myznikov.tinkoff/32/33582_2.png) [@g.myznikov.tinkoff](https://discuss.elastic.co/u/g.myznikov.tinkoff)\
**Post date:** [August 13, 2018, 9:52am UTC](https://discuss.elastic.co/t/grok-from-nginx-module-gets-error/143473/3 "2018-08-13T09:52:51Z")

</div>

I use nginx version 1.12.1. I have not changed log format so it is probably default.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 10, 2018, 9:52am UTC](https://discuss.elastic.co/t/grok-from-nginx-module-gets-error/143473/4 "2018-09-10T09:52:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
