# Grok pattern for java exception

**URL:** <https://discuss.elastic.co/t/grok-pattern-for-java-exception/95949>\
**Category:** Logstash\
**Created:** [August 4, 2017, 7:55pm UTC](https://discuss.elastic.co/t/grok-pattern-for-java-exception/95949 "2017-08-04T19:55:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![SandhyaRani](https://avatars.discourse-cdn.com/v4/letter/s/8dc957/32.png) [@SandhyaRani](https://discuss.elastic.co/u/SandhyaRani)\
**Post date:** [August 4, 2017, 7:55pm UTC](https://discuss.elastic.co/t/grok-pattern-for-java-exception/95949/1 "2017-08-04T19:55:36Z")

</div>

Hi there!

# I wanted to write grok match pattern for java exception

```
2016-12-16 21:28:05,668 ERROR [int-http-28] [nbiws::::] c.t.d.s.impl.DiagnosticServiceImpl - Error running a diagnostic workflow : 9003: Invalid arguments
com.twowire.dmc.listener.DeviceInteractionException: 9003: Invalid arguments
  at com.twowire.dmc.listener.DeviceInteractionTemplate.execute(DeviceInteractionTemplate.java:102) ~[cms-core-4.2.8.9.jar:4.2.8.9]
  at com.twowire.dmc.listener.DeviceInteractionTemplate.execute(DeviceInteractionTemplate.java:59) ~[cms-core-4.2.8.9.jar:4.2.8.9]
  at com.twowire.dmc.listener.DeviceInteractionTemplate.execute(DeviceInteractionTemplate.java:48) ~[cms-core-4.2.8.9.jar:4.2.8.9]

```

# my logstash conf file:

```
input {
    beats{
  
  port => 5044
  }
}
filter {
     if "_grokparsefailure" in [tags] {
  grok {
match => { "message" => "%{TOMCATLOG:exceptionText} %
     {CATALINALOG:messageText}" }
    }
 }
 if "exception" not in [tags] {

        grok {
            match => {
                message => "%{DATESTAMP:timestamp} %{LOGLEVEL:level}( +)\[%{DATA:thread}\] \[%{DATA:mdc}\] %{JAVACLASS:class} - %{JAVALOGMESSAGE:logmessage}"
    #message => "%{DATESTAMP:timestamp} %{LOGLEVEL:level}( +)\[%{DATA:thread}\] \[%{DATA:mdc}\] %{JAVACLASS:class} - %{GREEDYDATA:logmsg}"
            }
            # Record that this is an "log" event.
            add_tag => ["log"]
      
        }

        if "log" in [tags] {

            grok {
                match => {
                    mdc => "%{DATA:username}:%{DATA:deviceId:int}:%{DATA:sessionId}:%{DATA:userInteraction:int}:%{GREEDYDATA:workflowName}"
                }
            }
            date {
                timezone => GMT
                match => [
                               # "16-12-16 21:58:20,606"
                    "timestamp", "yy-MM-dd HH:mm:ss,SSS"
                ]
            }

        }

    } if [level] in ["ERROR", "error"] or [level] in ["FATAL", "fatal"]{
        mutate {
            add_tag => ["alert"]
        }
    }
   
   
 if [level] in ["TRACE", "trace"] {
        mutate {
        replace => {
        "level" => "%{level}, 0"
        }
      }
    }
     
    else if [level] in ["DEBUG", "debug"]{
        mutate {
            replace => {
            "level" => "%{level}, 1"
        }
        }
    }
   else if [level] in ["INFO", "info"]{
        mutate {
            replace => {
            "level" => "%{level}, 2"
        }
        }
    }
    else if [level] in ["WARN", "warn"]{
        mutate {
            replace => {
            "level" => "%{level}, 3"
        }
        }
    }
    else if [level] in ["ERROR", "error"]{
        mutate {
            replace => {
            "level" => "%{level}, 4"
        }
        }
    }
        else if [level] in ["FATAL", "fatal"]{
        mutate {
            replace => {
            "level" => "%{level}, 5"
        }
        }
    }
     

}
output {
    if "_grokparsefailure" in [tags] {
        stdout { codec => rubydebug {metadata => true }}
    }
if "log" in [tags]{
if "ERROR" in [level]{
    elasticsearch { hosts => ["x.com"] }
}
else if "WARN" in [level]{
    elasticsearch { hosts => ["x.com"] }
}
else if "INFO" in [level]{
    elasticsearch { hosts => ["x.com"] }
}
else if "FATAL" in [level]{
    elasticsearch { hosts => ["x..com"] }
}
}
}

```

when I run logstash im getting error "\_grokparse failure"

 ![exception message](https://us1.discourse-cdn.com/elastic/original/3X/2/d/2d87f9551bfda916a1004d8d3660181e6e402adb.png)

any help please?  
Thanks!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 5, 2017, 5:43pm UTC](https://discuss.elastic.co/t/grok-pattern-for-java-exception/95949/2 "2017-08-05T17:43:31Z")

</div>

For starters I'm pretty sure DATESTAMP won't match this kind of timestamp. Build your expression gradually, possibly using the grok constructor web site as help.

---

<div class="post-metadata">

**Author:** ![SandhyaRani](https://avatars.discourse-cdn.com/v4/letter/s/8dc957/32.png) [@SandhyaRani](https://discuss.elastic.co/u/SandhyaRani)\
**Post date:** [August 7, 2017, 3:33pm UTC](https://discuss.elastic.co/t/grok-pattern-for-java-exception/95949/3 "2017-08-07T15:33:48Z")

</div>

I am trying to build pattern using grok debugger, its working fine.

Thanks for your help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 4, 2017, 3:33pm UTC](https://discuss.elastic.co/t/grok-pattern-for-java-exception/95949/4 "2017-09-04T15:33:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
