# Grok parse failure

**URL:** <https://discuss.elastic.co/t/grok-parse-failure/317379>\
**Category:** Logstash\
**Created:** [October 25, 2022, 8:14am UTC](https://discuss.elastic.co/t/grok-parse-failure/317379 "2022-10-25T08:14:29Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Paf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paf/32/99015_2.png) [@Paf](https://discuss.elastic.co/u/Paf)\
**Post date:** [October 25, 2022, 8:14am UTC](https://discuss.elastic.co/t/grok-parse-failure/317379/1 "2022-10-25T08:14:29Z")

</div>

Hello,

I want to parse the field "ModifiedProperties" with this value :

```auto
{"Name":"StrongAuthenticationMethod","NewValue":"[\r\n {\r\n \"MethodType\": 5,\r\n \"Default\": true\r\n },\r\n {\r\n \"MethodType\": 0,\r\n \"Default\": false\r\n }\r\n]","OldValue":"[]"},{"Name":"StrongAuthenticationUserDetails","NewValue":"[\r\n {\r\n \"PhoneNumber\": \"+xx xxxxxxxxx\",\r\n \"AlternativePhoneNumber\": null,\r\n \"Email\": null,\r\n \"VoiceOnlyPhoneNumber\": null\r\n }\r\n]","OldValue":"[\r\n {\r\n \"PhoneNumber\": null,\r\n \"AlternativePhoneNumber\": null,\r\n \"Email\": null,\r\n \"VoiceOnlyPhoneNumber\": null\r\n }\r\n]"},{"Name":"Included Updated Properties","NewValue":"StrongAuthenticationMethod, StrongAuthenticationUserDetails","OldValue":""},{"Name":"TargetId.UserType","NewValue":"Member","OldValue":""}

```

I try to use this grok pattern :

```auto
        grok {
                match => { "ModifiedProperties" => "{%{DATA:champs1}},{%{DATA:champs2}},{%{DATA:champs3}},{%{DATA:champs4}}" }
        }

```

I use [https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/) to debug my grok and that works, but not in logstash.

Someone can help-me ?

Thanks

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [October 25, 2022, 4:13pm UTC](https://discuss.elastic.co/t/grok-parse-failure/317379/2 "2022-10-25T16:13:13Z")

</div>

Not sure is your value OK, I have to add missing quotes. Anyway, this sample is working on LS 8.4

If this sample below is still not working try with grok with extra backslash \{ and \}

```auto
input {

  generator {
       message => "{\"Name\":\"StrongAuthenticationMethod\",\"NewValue\":\"[\r\n {\r\n \"MethodType\": 5,\r\n \"Default\": true\r\n },\r\n {\r\n \"MethodType\": 0,\r\n \"Default\": false\r\n }\r\n]\",\"OldValue\":\"[]\"},{\"Name\":\"StrongAuthenticationUserDetails\",\"NewValue\":\"[\r\n {\r\n \"PhoneNumber\": \"+xx xxxxxxxxx\",\r\n \"AlternativePhoneNumber\": null,\r\n \"Email\": null,\r\n \"VoiceOnlyPhoneNumber\": null\r\n }\r\n]\",\"OldValue\":\"[\r\n {\r\n \"PhoneNumber\": null,\r\n \"AlternativePhoneNumber\": null,\r\n \"Email\": null,\r\n \"VoiceOnlyPhoneNumber\": null\r\n }\r\n]\"},{\"Name\":\"Included Updated Properties\",\"NewValue\":\"StrongAuthenticationMethod, StrongAuthenticationUserDetails\",\"OldValue\":\"\"},{\"Name\":\"TargetId.UserType\",\"NewValue\":\"Member\",\"OldValue\":\"\"}"
       count => 1
  }

} # input

filter {

grok {
    match => { "message" => "{%{DATA:champs1}},{%{DATA:champs2}},{%{DATA:champs3}},{%{DATA:champs4}}" }
  }
  

}

output {

    stdout {
        codec => rubydebug{}
    }
}

```

---

<div class="post-metadata">

**Author:** ![Paf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paf/32/99015_2.png) [@Paf](https://discuss.elastic.co/u/Paf)\
**Post date:** [October 27, 2022, 7:23am UTC](https://discuss.elastic.co/t/grok-parse-failure/317379/3 "2022-10-27T07:23:40Z")

</div>

I tried this but without success.  
I finally used a ruby script to parse the values  
Tanks for Your help

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 24, 2022, 7:23am UTC](https://discuss.elastic.co/t/grok-parse-failure/317379/4 "2022-11-24T07:23:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
