# Grok pattern from within kibana dev tools

**URL:** <https://discuss.elastic.co/t/grok-pattern-from-within-kibana-dev-tools/103509>\
**Category:** Kibana\
**Created:** [October 11, 2017, 8:43am UTC](https://discuss.elastic.co/t/grok-pattern-from-within-kibana-dev-tools/103509 "2017-10-11T08:43:40Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![barry.marshall73](https://avatars.discourse-cdn.com/v4/letter/b/bbe5ce/32.png) [@barry.marshall73](https://discuss.elastic.co/u/barry.marshall73)\
**Post date:** [October 11, 2017, 8:43am UTC](https://discuss.elastic.co/t/grok-pattern-from-within-kibana-dev-tools/103509/1 "2017-10-11T08:43:41Z")

</div>

I am configuring an ingest pipeline from within the Kibana Dev Tools and I am having issues with grok pattern, apparently some characters require to be preceeded by a double backslash such as "\\[", and DATA pattern gives a greedy behavor.

lets us consider this log line:  
2017-10-10 19:51:38.725 INFO 5648 --- [main] com.seizeit.api.service.StoreService : [method: addInit] [userId: 1] [storeId: 1]

and this pipeline/grok configuration:  
PUT /\_ingest/pipeline/applogs-pipeline  
{  
"processors": [  
{  
"grok": {  
"field": "message",  
"patterns": ["%{TIMESTAMP\_ISO8601:datetime} %{LOGLEVEL:loglevel} %{NUMBER:pid}\s+---\s+\[\s\*%{DATA:thread}\s\*\]\s+%{DATA:class}\s\*:\s\*%{DATA:log\_message}\s\*(\[method\s\*:\s\*%{DATA:method}\s\*\])?\s\*(\[userId\s\*:\s\*%{NUMBER:userId}\s\*\])?\s\*(\[location\s\*:\s\*%{DATA:location}\s\*\])?\s\*(?:\n%{GREEDYDATA:stack})?\n\*$"]  
}  
}  
]  
}

the result is that: method = addInit] [userId: 1] [storeId: 1  
it is a greedy behavor... it should be: method = addInit

Am I missing something

Thanks!

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [October 11, 2017, 5:00pm UTC](https://discuss.elastic.co/t/grok-pattern-from-within-kibana-dev-tools/103509/2 "2017-10-11T17:00:38Z")

</div>

I played around with this a bit and I think `DATA` is behaving as expected. I think there is some issue with the `(?:\n%{GREEDYDATA:stack})?\n*$` part. If I remove it, the rest of the parsing works as expected.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [October 11, 2017, 5:06pm UTC](https://discuss.elastic.co/t/grok-pattern-from-within-kibana-dev-tools/103509/3 "2017-10-11T17:06:05Z")

</div>

Having lots of DATA and GREEDYDATA patterns can be very inefficient as they match a lot. It can also lead to errors. Try to always use as targeted patterns as possible, e.g. NOTSPACE, NUMBER etc.

---

<div class="post-metadata">

**Author:** ![barry.marshall73](https://avatars.discourse-cdn.com/v4/letter/b/bbe5ce/32.png) [@barry.marshall73](https://discuss.elastic.co/u/barry.marshall73)\
**Post date:** [October 12, 2017, 8:02am UTC](https://discuss.elastic.co/t/grok-pattern-from-within-kibana-dev-tools/103509/4 "2017-10-12T08:02:34Z")

</div>

thanks, I removed the last part and it is working well now!

---

<div class="post-metadata">

**Author:** ![barry.marshall73](https://avatars.discourse-cdn.com/v4/letter/b/bbe5ce/32.png) [@barry.marshall73](https://discuss.elastic.co/u/barry.marshall73)\
**Post date:** [October 12, 2017, 8:05am UTC](https://discuss.elastic.co/t/grok-pattern-from-within-kibana-dev-tools/103509/5 "2017-10-12T08:05:11Z")

</div>

thanks for the advise! I am new to grok and your comment is more than welcome 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 9, 2017, 8:05am UTC](https://discuss.elastic.co/t/grok-pattern-from-within-kibana-dev-tools/103509/6 "2017-11-09T08:05:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
