# Grok Pattern Help Please

**URL:** https://discuss.elastic.co/t/grok-pattern-help-please/143905
**Category:** Logstash
**Created:** [August 10, 2018, 4:32pm UTC](https://discuss.elastic.co/t/grok-pattern-help-please/143905 "2018-08-10T16:32:50Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![jenyphur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenyphur/32/40735_2.png) [@jenyphur](https://discuss.elastic.co/u/jenyphur)
#### Post date: [August 10, 2018, 4:32pm UTC](https://discuss.elastic.co/t/grok-pattern-help-please/143905/1 "2018-08-10T16:32:51Z")

</div>

Hi there, pretty new to Logstash and Grok patterns. I am trying to parse out a custom log file and here is what I'm trying to do.

Log Sample;  
\<15\>1 2018-08-09T07:37:48.306-05:00 MacBook-Pro.local ReaccomTask - Audit [mdc@18060 app\_className="TDSSabreConnection" app\_client\_tranid="D228E0B6192E4C748CCCDDD5494B4698" app\_loglevel="DEBUG" app\_recordLoc="UANNFR" app\_servername="QueueMoveWorker" app\_timestamp="2018-08-09T07:37:48,306" app\_tranid="BD15A16391FC4C3EB1BA840D6BE2C03F" app\_version="Thread-8" cf\_offset="706"] \<\>

I am having trouble taking everything after ReaccomTask to the beginning of app\_className and essentially ignoring it. Then I am trying to get each field after that parsed out using the field name provided.

Using an online grok tester I was able to get the result I'm looking for ![ugh](https://us1.discourse-cdn.com/elastic/original/3X/9/a/9a9e93e811d464d0dd8fe71e592dbce8e60ca001.png)

Using this ugly grok pattern:

 ![ugh2](https://us1.discourse-cdn.com/elastic/original/3X/8/0/8074f3a0ef40425201cfda6752f2c4fa9edb03f6.png)

%{TIMESTAMP\_ISO8601:timestamp} %{DATA:host} %{DATA:app\_name} %{DATA:app\_notsure} app\_className="%{NOTSPACE:app\_className}&quot; app\_client\_tranid="%{NOTSPACE:app\_client\_tranid}&quot; app\_loglevel="%{NOTSPACE:app\_loglevel}&quot; app\_recordLoc="%{NOTSPACE:app\_recordLoc}&quot; app\_servername="%{NOTSPACE:app\_servername}&quot; app\_timestamp="%{NOTSPACE:app\_timestamp}&quot; app\_tranid="%{NOTSPACE:app\_tranid}&quot; app\_version="%{NOTSPACE:app\_version}&quot; cf\_offset="%{NOTSPACE:cf\_offset}&quot;]%{GREEDYDATA:app\_message}

But when I try to use this in logstash , I keep getting these errors:  
[2018-08-10T08:54:47,395][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, {, } at line 17, column 128 (byte 291) after filter\n{\n\n if [type] == "syslog"\n {\n\n grok\n {\n\t\tmatch =\> { "message" =\> "%{TIMESTAMP\_ISO8601:timestamp} %{DATA:host} %{DATA:app\_name} %{DATA:app\_notsure} app\_className="", :backtrace=\>["C:/Logstash/logstash-core/lib/logstash/compiler.rb:42:in `compile_imperative'", "C:/Logstash/logstash-core/lib/logstash/compiler.rb:50:in`compile\_graph'", "C:/Logstash/logstash-core/lib/logstash/compiler.rb:12:in `block in compile_sources'", "org/jruby/RubyArray.java:2486:in`map'", "C:/Logstash/logstash-core/lib/logstash/compiler.rb:11:in `compile_sources'", "C:/Logstash/logstash-core/lib/logstash/pipeline.rb:51:in`initialize'", "C:/Logstash/logstash-core/lib/logstash/pipeline.rb:169:in `initialize'", "C:/Logstash/logstash-core/lib/logstash/pipeline_action/create.rb:40:in`execute'", "C:/Logstash/logstash-core/lib/logstash/agent.rb:315:in `block in converge_state'", "C:/Logstash/logstash-core/lib/logstash/agent.rb:141:in`with\_pipelines'", "C:/Logstash/logstash-core/lib/logstash/agent.rb:312:in `block in converge_state'", "org/jruby/RubyArray.java:1734:in`each'", "C:/Logstash/logstash-core/lib/logstash/agent.rb:299:in `converge_state'", "C:/Logstash/logstash-core/lib/logstash/agent.rb:166:in`block in converge\_state\_and\_update'", "C:/Logstash/logstash-core/lib/logstash/agent.rb:141:in `with_pipelines'", "C:/Logstash/logstash-core/lib/logstash/agent.rb:164:in`converge\_state\_and\_update'", "C:/Logstash/logstash-core/lib/logstash/agent.rb:105:in `block in execute'", "C:/Logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/interval.rb:18:in`interval'", "C:/Logstash/logstash-core/lib/logstash/agent.rb:94:in `execute'", "C:/Logstash/logstash-core/lib/logstash/runner.rb:348:in`block in execute'", "C:/Logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/task.rb:24:in `block in initialize'"]}

So something is clearly wrong.

Any help would be GREATLY appreciated.

Jennifer

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [August 10, 2018, 4:46pm UTC](https://discuss.elastic.co/t/grok-pattern-help-please/143905/2 "2018-08-10T16:46:12Z")

</div>

You need to escape the double quote immediately after app\_className.

Personally I would use dissect for this, not grok.

---

<div class="post-metadata">

### Author: ![jenyphur](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenyphur/32/40735_2.png) [@jenyphur](https://discuss.elastic.co/u/jenyphur)
#### Post date: [August 10, 2018, 4:47pm UTC](https://discuss.elastic.co/t/grok-pattern-help-please/143905/3 "2018-08-10T16:47:44Z")

</div>

Excellent..I actually removed all the double quotes and it seems to be working now 🙂

I'm not sure with dissect is, but I'll definitely look into it.

thanks!

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [August 10, 2018, 4:57pm UTC](https://discuss.elastic.co/t/grok-pattern-help-please/143905/4 "2018-08-10T16:57:43Z")

</div>

Looking just at the part inside the square brackets. I would grok that to extract the key/value pairs then use a kv filter.

```
    grok { match => { "message" => "\[(?<mailperhaps>[^]+) %{DATA:restOfLine}\]" } } 
    kv { source => "restOfLine" }
```

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 7, 2018, 5:10pm UTC](https://discuss.elastic.co/t/grok-pattern-help-please/143905/5 "2018-09-07T17:10:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
