# Grok loglevel catches 'er'

**URL:** <https://discuss.elastic.co/t/grok-loglevel-catches-er/47974>\
**Category:** Logstash\
**Created:** [April 20, 2016, 11:00pm UTC](https://discuss.elastic.co/t/grok-loglevel-catches-er/47974 "2016-04-20T23:00:27Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ezer\_Karash](https://avatars.discourse-cdn.com/v4/letter/e/df788c/32.png) [@Ezer\_Karash](https://discuss.elastic.co/u/Ezer_Karash)\
**Post date:** [April 20, 2016, 11:00pm UTC](https://discuss.elastic.co/t/grok-loglevel-catches-er/47974/1 "2016-04-20T23:00:27Z")

</div>

the grok lovel pattern catches 'er' (for example if the word 'number' is in the message)' is there a way to fix that

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 21, 2016, 5:41am UTC](https://discuss.elastic.co/t/grok-loglevel-catches-er/47974/2 "2016-04-21T05:41:15Z")

</div>

You mean catches "er"? And you're talking about the LOGLEVEL pattern, below? Well, don't use the pattern if it doesn't suit you. However, I don't see why it would pick up the "er" in "number" unless you have a very weird grok expression that probably can be improved to avoid the problem altogether. If you give us more details it'll be possible to help.

> <https://github.com/logstash-plugins/logstash-patterns-core/blob/v2.0.5/patterns/grok-patterns#L101>

---

<div class="post-metadata">

**Author:** ![Ezer\_Karash](https://avatars.discourse-cdn.com/v4/letter/e/df788c/32.png) [@Ezer\_Karash](https://discuss.elastic.co/u/Ezer_Karash)\
**Post date:** [April 21, 2016, 6:01am UTC](https://discuss.elastic.co/t/grok-loglevel-catches-er/47974/3 "2016-04-21T06:01:52Z")

</div>

Thanks for the typo fix,  
at any rate my grok is straight forward I think:

```
grok {
 patterns_dir => ["./patterns"]
 break_on_match => false
 match => { "message" => "%{LOGLEVEL:LogLevel}" }
 match => { "message" => "%{TIME:orig_time_stamp}" }
 match => { "message" => "%{BRACKETS:Header}" }
 match => { "message" => "%{STACK_TRACE:ST}" }
 }

```

and I think the problem is regex origin since the loglevel regex seems to catch 'er'

 ![](https://us1.discourse-cdn.com/elastic/original/2X/b/b1a86d844c8823cb5c027980f9f59d8e5b98411c.png)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 21, 2016, 6:15am UTC](https://discuss.elastic.co/t/grok-loglevel-catches-er/47974/4 "2016-04-21T06:15:45Z")

</div>

That use of grok is ill-advised. Use a single grok expression to make the message in one swoop, e.g. like this (depending on what your log messages look like, obviously):

```auto
grok {
  match => {
    "message" => "^%{TIME:orig_time_stamp} %{LOGLEVEL:LogLevel} %{BRACKETS:Header} %{STACK_TRACE:ST}"
  }
  patterns_dir => ["./patterns"]
}

```

The way you've written it you'll look for LOGLEVEL, TIME, and so on anywhere in the message so it's quite possible to get mismatches, as you've seen.

---

<div class="post-metadata">

**Author:** ![Ezer\_Karash](https://avatars.discourse-cdn.com/v4/letter/e/df788c/32.png) [@Ezer\_Karash](https://discuss.elastic.co/u/Ezer_Karash)\
**Post date:** [April 21, 2016, 7:05am UTC](https://discuss.elastic.co/t/grok-loglevel-catches-er/47974/5 "2016-04-21T07:05:30Z")

</div>

Thnaks.

I have a couple of patterns coming in together, and I thought of avoiding: 'if groksfailure in tags' and having a full pattern every time, but I'll try that and see what happens.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:01am UTC](https://discuss.elastic.co/t/grok-loglevel-catches-er/47974/6 "2017-07-06T05:01:18Z")

</div>


