# GROK pattern and Debugger

**URL:** <https://discuss.elastic.co/t/grok-pattern-and-debugger/242905>\
**Category:** Logstash\
**Created:** [July 28, 2020, 12:31pm UTC](https://discuss.elastic.co/t/grok-pattern-and-debugger/242905 "2020-07-28T12:31:17Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dmalchikov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dmalchikov/32/72921_2.png) [@dmalchikov](https://discuss.elastic.co/u/dmalchikov)\
**Post date:** [July 28, 2020, 12:31pm UTC](https://discuss.elastic.co/t/grok-pattern-and-debugger/242905/1 "2020-07-28T12:31:17Z")

</div>

Hi there!  
Could not find a problem and supported index  
I have pattern which pass test in Grok Debugger but shows "The input is not valid." in Processor field while Create pipeline  
Grok pattern:

```auto
^%{TIMESTAMP_ISO8601:timestamp}\s+((?:NOT AVAILABLE)|%{IPORHOST:remote_address})\s+%{POSINT:thread}\s+%{LOGLEVEL:loglevel}\s+(?<logger>\S+)%{GREEDYDATA:message}\s+

```

two log records:

```auto
2020-07-27 00:01:54 NOT AVAILABLE 8 INFO Quartz.Listener.JobChainingJobListener Job 'ProcessGroup.sendNotificationsJobKey' will now chain to Job 'ProcessGroup.makeEscalationNotificationsJobKey'

```

```auto
2020-07-27 00:02:04 95.163.208.222 26 INFO Farin.Infrastructure.System.Host.Core.Log.RequestLogMiddleware >> HttpRequest: https://bapp1-ptfm5.farin.com/api/system/healthtest; Method: GET

```

I see \s+ doesn't like by Processor.  
Any ideas?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 30, 2020, 9:57pm UTC](https://discuss.elastic.co/t/grok-pattern-and-debugger/242905/2 "2020-07-30T21:57:59Z")

</div>

Exactly what error message do you get from logstash.

Also, do you really want a trailing \s+ on the pattern?

---

<div class="post-metadata">

**Author:** ![dmalchikov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dmalchikov/32/72921_2.png) [@dmalchikov](https://discuss.elastic.co/u/dmalchikov)\
**Post date:** [August 5, 2020, 3:34pm UTC](https://discuss.elastic.co/t/grok-pattern-and-debugger/242905/3 "2020-08-05T15:34:22Z")

</div>

Thanks!  
Due some playing tries I've got working pattern:

```auto
"^%{TIMESTAMP_ISO8601:timestamp}%{SPACE}*((?:NOT AVAILABLE)|%{IPORHOST:remote_address})%{SPACE}*%{POSINT:thread}%{SPACE}*%{LOGLEVEL:loglevel}%{SPACE}*(?<logger>%{NOTSPACE}*)%{GREEDYMULTILINE:message}"

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 2, 2020, 3:34pm UTC](https://discuss.elastic.co/t/grok-pattern-and-debugger/242905/4 "2020-09-02T15:34:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
