# Grok is not parsing GREEDYDATA field

**URL:** <https://discuss.elastic.co/t/grok-is-not-parsing-greedydata-field/49704>\
**Category:** Logstash\
**Created:** [May 10, 2016, 7:59pm UTC](https://discuss.elastic.co/t/grok-is-not-parsing-greedydata-field/49704 "2016-05-10T19:59:36Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![eugeniocesar](https://avatars.discourse-cdn.com/v4/letter/e/cab0a1/32.png) [@eugeniocesar](https://discuss.elastic.co/u/eugeniocesar)\
**Post date:** [May 10, 2016, 7:59pm UTC](https://discuss.elastic.co/t/grok-is-not-parsing-greedydata-field/49704/1 "2016-05-10T19:59:36Z")

</div>

Hi Everybody!

I have been facing a problem using Grok with OpenLDAP log, where it ignores a GREEDYDATA value in my match rule.  
Here's a working rule example:

Source log line:  
`May 9 18:53:01 openldap-master slapd[4566]: conn=227215 op=0 BIND dn="cn=admin,dc=example,dc=com" method=128`

Grok match rule:  
`match => ["message", "%{SYSLOGBASE} conn=%{INT:ConnNumber} op=(?:[0-9]+) %{WORD:OpType} dn=%{GREEDYDATA:BindDN} method=128" ]`

ElasticSearch output:  
`{ "_index": "logstash-2016.05.09", "_type": "Test", "_id": "AVSXq6-xMOq1MYWLr-cM", "_version": 1, "_score": 1, "_source": { "message": "May 9 18:53:01 openldap-master slapd[4566]: conn=227215 op=0 BIND dn="cn=admin,dc=example,dc=com" method=128", "@version": "1", "@timestamp": "2016-05-09T21:53:01.000Z", "path": "/tmp/openldap_log.txt", "host": "logstash-server", "type": "Test", "timestamp": "May 9 18:53:01", "logsource": "openldap-master", "program": "slapd", "pid": "4566", "ConnNumber": "227215", "OpType": "BIND", "BindDN": "cn=admin,dc=example,dc=com" } }`

And here's the part that is not working:

Source log line:  
`May 9 18:56:55 openldap-master slapd[4566]: conn=226965 op=50 MOD dn="cn=user,ou=users,dc=example,dc=com"`

Grok match rule:  
`match => ["message", "%{SYSLOGBASE} conn=%{INT:ConnNumber} op=(?:[0-9]+) %{WORD:OpType} dn=%{GREEDYDATA:ModDN}" ]`

ElasticSearch output:  
`{ "_index": "logstash-2016.05.09", "_type": "Test", "_id": "AVSXq6-xMOq1MYWLr-cL", "_version": 1, "_score": 1, "_source": { "message": "May 9 18:56:55 openldap-server slapd[4566]: conn=226965 op=50 MOD dn="cn=user,ou=users,dc=example,dc=com"", "@version": "1", "@timestamp": "2016-05-09T21:56:55.000Z", "path": "/tmp/openldap_log.txt", "host": "logstash-server", "type": "Test", "timestamp": "May 9 18:56:55", "logsource": "openldap-server", "program": "slapd", "pid": "4566", "ConnNumber": "226965", "OpType": "MOD" } }`

As you can see, in the first example, Grok recognizes the GREEDYDATA field and send it correctly to ES, but in the second example, it doesn't recognize the ModDN field.  
Does anybody know what could be happening here?!

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 11, 2016, 11:46pm UTC](https://discuss.elastic.co/t/grok-is-not-parsing-greedydata-field/49704/2 "2016-05-11T23:46:32Z")

</div>

Try using a `NOTSPACE` instead of the greedy data.

---

<div class="post-metadata">

**Author:** ![fbaligand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fbaligand/32/5657_2.png) [@fbaligand](https://discuss.elastic.co/u/fbaligand)\
**Post date:** [May 12, 2016, 11:37am UTC](https://discuss.elastic.co/t/grok-is-not-parsing-greedydata-field/49704/3 "2016-05-12T11:37:02Z")

</div>

And if your DN could contain spaces, you can use `QUOTEDSTRING` grok pattern.

---

<div class="post-metadata">

**Author:** ![eugeniocesar](https://avatars.discourse-cdn.com/v4/letter/e/cab0a1/32.png) [@eugeniocesar](https://discuss.elastic.co/u/eugeniocesar)\
**Post date:** [May 12, 2016, 8:39pm UTC](https://discuss.elastic.co/t/grok-is-not-parsing-greedydata-field/49704/4 "2016-05-12T20:39:49Z")

</div>

Thanks warkolm!

But as fbaligand said, many of my DNs contains spaces, so I think that `QUOTEDSTRING` would fit better.

---

<div class="post-metadata">

**Author:** ![eugeniocesar](https://avatars.discourse-cdn.com/v4/letter/e/cab0a1/32.png) [@eugeniocesar](https://discuss.elastic.co/u/eugeniocesar)\
**Post date:** [May 12, 2016, 8:50pm UTC](https://discuss.elastic.co/t/grok-is-not-parsing-greedydata-field/49704/5 "2016-05-12T20:50:13Z")

</div>

I found out that the problem wasn't in the pattern used, but in the order that my "match" rules where placed in my logstash conf file.  
Some of my log lines were being partially matched by a rule that was declared before the rule that fully matches those log lines.  
For this reason, these lines were "grokked" partially too, with missing fields, generating the error explained in the post.  
What I still can't understand is why logstash consider a partial match as a successfull match...

Thanks warkolm and fbaligand for the help!

---

<div class="post-metadata">

**Author:** ![fbaligand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fbaligand/32/5657_2.png) [@fbaligand](https://discuss.elastic.co/u/fbaligand)\
**Post date:** [May 12, 2016, 8:53pm UTC](https://discuss.elastic.co/t/grok-is-not-parsing-greedydata-field/49704/6 "2016-05-12T20:53:47Z")

</div>

You're welcome 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:57am UTC](https://discuss.elastic.co/t/grok-is-not-parsing-greedydata-field/49704/7 "2017-07-06T04:57:49Z")

</div>


