# GROK Help This setting must be a hash

**URL:** <https://discuss.elastic.co/t/grok-help-this-setting-must-be-a-hash/259408>\
**Category:** Logstash\
**Created:** [December 22, 2020, 4:30pm UTC](https://discuss.elastic.co/t/grok-help-this-setting-must-be-a-hash/259408 "2020-12-22T16:30:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![fastxl](https://avatars.discourse-cdn.com/v4/letter/f/85e7bf/32.png) [@fastxl](https://discuss.elastic.co/u/fastxl)\
**Post date:** [December 22, 2020, 4:30pm UTC](https://discuss.elastic.co/t/grok-help-this-setting-must-be-a-hash/259408/1 "2020-12-22T16:30:50Z")

</div>

Need help trying to break down some data. This is the data being sent

`{"timestamp": "2020-11-17T19:02:19.352Z","sequence": 2460137,"deviceName": "OKUMA.MachiningCenterMA650-EAST","deviceUUID": "OKUMA.MachiningCenterMA650-EAST.190056","componentId": "Mp1","dataItemId": "Mp1ProgramHeader","Events": { "ProgramHeader": { "name": "p1ProgramHeader", "@@data": "(CIMATRON E13)( FILE NAME:24625_DET11B_BSH)( OKUMA PROGRAM )( rob.mank )( Monday November 9, 2020 - 1:22:43 PM )(slab top)( TOOL NAME: 2.0 INGER .06R 4.0 )( TOOL DIAMETER......: 2. )" } } }`

Here is my logstash.conf

```
input {
	file {
		start_position => "beginning"
		path => "/home/eric/logstash-csv/MTConnect-OKUMA.test.log"
		codec => "json"
		sincedb_path => "/dev/null"
	}
}

filter {
	json {
		source => "message"
	}
	if [Events][ProgramHeader][@@data] =~ /\([CIMATRON E13)]+\)/ {
		grok {
			match => ["\((?<custom_field-1>[^)]+)\)\((?<custom_field-2>[^)]+)\)\((?<custom_field-3>[^)]+)\)\((?<custom_field-4>[^)]+)\)\((?<custom_field-5>[^)]+)\)\((?<custom_field-6>[^)]+)\)\((?<custom_field-7>[^)]+)\)\((?<custom_field-8>[^)]+)\)" ]
        }
	}
}

output {
	elasticsearch {
		hosts => ["http://localhost:9200"]
		index => "mt-18"
	}
	stdout {}
}

```

Basically if `Events.ProgramHeader.@@data` contains `(CIMATRON E13)` I want to GROK that data (in `Events.ProgramHeader.@@data`) into individual fields. When I run my GROK Pattern through the GROK debugger it seems to work fine. When I run in Logstash I get the following error

```
filter {
    grok {
      # This setting must be a hash
      # This field must contain an even number of items, got 1

```

Does my GROK need to be formatted different? Am I going down the wrong path with this?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 22, 2020, 4:55pm UTC](https://discuss.elastic.co/t/grok-help-this-setting-must-be-a-hash/259408/2 "2020-12-22T16:55:34Z")

</div>

> [@fastxl](#):
>
> ```auto
> grok {
> match => ["\((?<custom_field-1>[^)]+)\)\((?<custom_field-2>[^)]+)\)\((?<custom_field-3>[^)]+)\)\((?<custom_field-4>[^)]+)\)\((?<custom_field-5>[^)]+)\)\((?<custom_field-6>[^)]+)\)\((?<custom_field-7>[^)]+)\)\((?<custom_field-8>[^)]+)\)" ]
> }
> 
> ```

You probably want

```
grok {
    match => { "[Events][ProgramHeader][@@data]" => "\((?<custom_field-1>[^)]+)\)\((?<custom_field-2>[^)]+)\)\((?<custom_field-3>[^)]+)\)\((?<custom_field-4>[^)]+)\)\((?<custom_field-5>[^)]+)\)\((?<custom_field-6>[^)]+)\)\((?<custom_field-7>[^)]+)\)\((?<custom_field-8>[^)]+)\)" } 
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 19, 2021, 4:55pm UTC](https://discuss.elastic.co/t/grok-help-this-setting-must-be-a-hash/259408/3 "2021-01-19T16:55:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
