# Grok pattern DATA vs GREEDYDATA mismatch

**URL:** <https://discuss.elastic.co/t/grok-pattern-data-vs-greedydata-mismatch/225300>\
**Category:** Logstash\
**Created:** [March 26, 2020, 10:03pm UTC](https://discuss.elastic.co/t/grok-pattern-data-vs-greedydata-mismatch/225300 "2020-03-26T22:03:50Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mehak\_Bhargava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehak_bhargava/32/54750_2.png) [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Post date:** [March 26, 2020, 10:03pm UTC](https://discuss.elastic.co/t/grok-pattern-data-vs-greedydata-mismatch/225300/1 "2020-03-26T22:03:50Z")

</div>

In one log file, I have two different formats of log lines as below. Why does %{GREEDYDATA:loglevel} and %{DATA:loglevel} make a huge difference in loglevel output?

```auto
2020-03-26 11:31:10,324 [Thread-40] INFO o.e.j.s.AbstractConnector - Stopped ServerConnector@676505de{HTTP/1.1,[http/1.1]}{0.0.0.0:8780} 

%{DATESTAMP:timestamp} \[%{DATA:thread}\] %{GREEDYDATA:loglevel} %{JAVACLASS:javaClass} %{GREEDYDATA:logmessage}

{
  "javaClass": "o.e.j.s.AbstractConnector",
  "loglevel": " INFO ",
  "logmessage": " - Stopped ServerConnector@676505de{HTTP/1.1,[http/1.1]}{0.0.0.0:8780}",
  "thread": "Thread-40",
  "timestamp": "20-03-26 11:31:10,324"
}

```

```auto
2020-03-26 03:36:21,546 [DispatcherScheduler_Worker-1] INFO o.a.c.h.HttpMethodDirector - I/O exception (java.net.ConnectException) caught when processing request: Connection timed out: connect 

%{DATESTAMP:timestamp} \[%{DATA:thread}\] %{DATA:loglevel} %{JAVACLASS:javaClass} %{GREEDYDATA:logmessage}

{
  "javaClass": "o.a.c.h.HttpMethodDirector",
  "loglevel": "INFO ",
  "logmessage": " - I/O exception (java.net.ConnectException) caught when processing request: Connection timed out: connect",
  "thread": "DispatcherScheduler_Worker-1",
  "timestamp": "20-03-26 03:36:21,546"
}

```

```auto
2020-03-26 11:31:10,324 [Thread-40] INFO o.e.j.s.AbstractConnector - Stopped ServerConnector@676505de{HTTP/1.1,[http/1.1]}{0.0.0.0:8780} 

%{DATESTAMP:timestamp} \[%{DATA:thread}\] %{DATA:loglevel} %{JAVACLASS:javaClass}%{GREEDYDATA:logmessage}

{
  "javaClass": "INFO",
  "loglevel": " ",
  "logmessage": " o.e.j.s.AbstractConnector - Stopped ServerConnector@676505de{HTTP/1.1,[http/1.1]}{0.0.0.0:8780}",
  "thread": "Thread-40",
  "timestamp": "20-03-26 11:31:10,324"
}

```

Because of this, the data in Kibana parsed sometimes shows Loglevel and sometimes not-

```auto
Timestamp: Mar 26, 2020 @ 15:13:42.950	
JavaClass: VER.jks	
LogLevel: ER	
Message: 2020-03-26 11:31:39,799 [WrapperSimpleAppMain] INFO o.e.j.u.s.SslContextFactory - x509=X509@706a432c(rmmca,h=[],w=[]) for SslContextFactory@7f4f185d(file:///C:/Program%20Files%20(x86)/ESQ%20SST/Certificates_ESQ/SERVER.jks,null)

Timestamp: Mar 26, 2020 @ 15:13:42.950	
JavaClass: o.e.j.s.AbstractConnector	
LogLevel: INFO	
Message: 2020-03-26 11:31:39,821 [WrapperSimpleAppMain] INFO o.e.j.s.AbstractConnector - Started ServerConnector@665c31ea{SSL,[ssl, http/1.1]}{0.0.0.0:8782}

```

---

<div class="post-metadata">

**Author:** ![fadjar340](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fadjar340/32/43610_2.png) [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Post date:** [March 28, 2020, 2:54am UTC](https://discuss.elastic.co/t/grok-pattern-data-vs-greedydata-mismatch/225300/2 "2020-03-28T02:54:59Z")

</div>

I suggest you make 2 filter using | (pipe) to differentiate the log format.  
It's complicated if you use GREEDYDATA into single grok filter.  
Before go to the filter building into production, try this URL  
[https://grokconstructor.appspot.com/do/match](https://grokconstructor.appspot.com/do/match) to match it first

Regards,  
Fadjar Tandabawana

---

<div class="post-metadata">

**Author:** ![Mehak\_Bhargava](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehak_bhargava/32/54750_2.png) [@Mehak\_Bhargava](https://discuss.elastic.co/u/Mehak_Bhargava)\
**Post date:** [March 31, 2020, 5:58pm UTC](https://discuss.elastic.co/t/grok-pattern-data-vs-greedydata-mismatch/225300/3 "2020-03-31T17:58:34Z")

</div>

Thanks, while I looked into it, I saw it was used only for log formats which had pipes in logs. like this-

```auto
2020-03-30 06:15:23.773	IncidentAgent	5980	Information	Processing next batch of scheduled incident activity records	

```

But I dont have this. Is there a way I can just slice the information I want and get that?

---

<div class="post-metadata">

**Author:** ![fadjar340](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fadjar340/32/43610_2.png) [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Post date:** [April 11, 2020, 4:45pm UTC](https://discuss.elastic.co/t/grok-pattern-data-vs-greedydata-mismatch/225300/4 "2020-04-11T16:45:52Z")

</div>

> [@Mehak\_Bhargava](#):
>
> 2020-03-26 11:31:10,324 [Thread-40] INFO o.e.j.s.AbstractConnector - Stopped ServerConnector@676505de{HTTP/1.1,[http/1.1]}{0.0.0.0:8780}

and

> [@Mehak\_Bhargava](#):
>
> 2020-03-30 06:15:23.773 IncidentAgent 5980 Information Processing next batch of scheduled incident activity records

is very different, you need to build several grok matching using if match then do the grok specific for that format

The second one is no "[" character, you need to build matching for this

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 9, 2020, 4:47pm UTC](https://discuss.elastic.co/t/grok-pattern-data-vs-greedydata-mismatch/225300/5 "2020-05-09T16:47:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
