# Grok on logstash not working, but working on grokdebugger

**URL:** <https://discuss.elastic.co/t/grok-on-logstash-not-working-but-working-on-grokdebugger/114527>\
**Category:** Logstash\
**Created:** [January 8, 2018, 1:13pm UTC](https://discuss.elastic.co/t/grok-on-logstash-not-working-but-working-on-grokdebugger/114527 "2018-01-08T13:13:44Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![anjali](https://avatars.discourse-cdn.com/v4/letter/a/aeb1de/32.png) [@anjali](https://discuss.elastic.co/u/anjali)\
**Post date:** [January 8, 2018, 1:13pm UTC](https://discuss.elastic.co/t/grok-on-logstash-not-working-but-working-on-grokdebugger/114527/1 "2018-01-08T13:13:45Z")

</div>

Hello,  
The following grok pattern is working on grokdebugger perfectly.

%{DATESTAMP:Timestamp} %{LOGLEVEL:LogLevel} [%{JAVACLASS:Class}] (%{GREEDYDATA:MessageID}) %{GREEDYDATA:Error}\n(?m)%{GREEDYDATA:JavaStackTrace}

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/d/5d8bcf1e82e86e17adaf22bdbcc10d79d651288c.png)  
This is precisely the response I want.

Now, when I run the same pattern in logstash, I get an incorrect output.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/5/d57c3405141c93b93f34c504777662c0c2045228.png)

both are using a multiline pattern "^\s"

Can someone please tell me why?

This is my config file.

input {

beats {  
type =\> "syserr"  
port =\> "5044"  
codec =\> multiline {  
pattern =\> "^\s"  
what =\> "previous"  
}  
}  
}

filter {

```
if [type] =="syserr"{
    grok {
         
         match => ["message", "%{DATESTAMP:Timestamp} %{LOGLEVEL:LogLevel} \[%{JAVACLASS:Class}\] \(%{GREEDYDATA:MessageID}\) %{GREEDYDATA:Error}\n(?m)%{GREEDYDATA:JavaStackTrace}"]
         overwrite => ["message"]
        
         
         }

}

```

}

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
}

```
stdout {
    codec => "rubydebug"
}

```

}

```
indent preformatted text by 4 spaces
```

---

<div class="post-metadata">

**Author:** ![anjali](https://avatars.discourse-cdn.com/v4/letter/a/aeb1de/32.png) [@anjali](https://discuss.elastic.co/u/anjali)\
**Post date:** [January 8, 2018, 1:21pm UTC](https://discuss.elastic.co/t/grok-on-logstash-not-working-but-working-on-grokdebugger/114527/2 "2018-01-08T13:21:53Z")

</div>

I have negate =\> "true" in the grok debugger. But adding this statement to my logstash config causes a \_grokparsefailure.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 5, 2018, 1:21pm UTC](https://discuss.elastic.co/t/grok-on-logstash-not-working-but-working-on-grokdebugger/114527/3 "2018-02-05T13:21:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
