# Grok pattern not being applied in logstash but working on grok debugger

**URL:** <https://discuss.elastic.co/t/grok-pattern-not-being-applied-in-logstash-but-working-on-grok-debugger/97384>\
**Category:** Logstash\
**Created:** [August 17, 2017, 9:55am UTC](https://discuss.elastic.co/t/grok-pattern-not-being-applied-in-logstash-but-working-on-grok-debugger/97384 "2017-08-17T09:55:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Swaroop\_Chandre](https://avatars.discourse-cdn.com/v4/letter/s/ecc23a/32.png) [@Swaroop\_Chandre](https://discuss.elastic.co/u/Swaroop_Chandre)\
**Post date:** [August 17, 2017, 9:55am UTC](https://discuss.elastic.co/t/grok-pattern-not-being-applied-in-logstash-but-working-on-grok-debugger/97384/1 "2017-08-17T09:55:26Z")

</div>

## My grok pattern is working on grok debugger but when reading from filebeat my grok pattern is not applied.

## My syslog-filter.conf file

filter {  
if [type] == "log" {  
grok {  
patterns\_dir =\> ["/etc/logstash/conf.d/pattern.conf"]  
match =\> { "message" =\>"%{SYSLOGTIMESTAMP:date} %{IPV6:sourceip} %{POSINT:seqnum1}: %{POSINT:seqnum2}: %{DATA:date1} %%{DATA:message}-%{POSINT:severity}-%{DATA:mnemonic}: %{GREEDYDATA:log\_message}" }  
}

}  
}

## I get output as:

{  
"@timestamp": "2017-08-17T07:43:10.892Z",  
"beat": {  
"hostname": "autosysrv107",  
"name": "autosysrv107",  
"version": "5.5.1"  
},  
"input\_type": "log",  
"message": "Jul 16 07:01:04 2405:200:204:101:172:26:161:172 990708: 990653: Jul 16 07:02:24.749 IST: %TCP-6-BADAUTH: No MD5 digest from 172.16.32.120(646) to 172.26.161.172(23750) tableid - 0",  
"offset": 9774736,  
"source": "/var/log/messages-20170723",  
"type": "log"  
}{  
"@timestamp": "2017-08-17T07:43:10.892Z",  
"beat": {  
"hostname": "autosysrv107",  
"name": "autosysrv107",  
"version": "5.5.1"  
},  
"input\_type": "log",  
"message": "Jul 16 07:01:04 2405:200:204:101:172:22:2:96 253818: 253555: Jul 16 07:02:24.827 IST: %TCP-6-BADAUTH: No MD5 digest from 2405:200:201:101:172:22:9:190(179) to 2405:200:201:101:172:22:2:96(12530) (RST) tableid - 0",  
"offset": 9774949,  
"source": "/var/log/messages-20170723",  
"type": "log"  
}

## Where as I want messages in json as (which I get in grok debugger but failing while reading from filebeat)

{  
"date": [  
[  
"Jul 16 07:01:04"  
]  
],  
"MONTH": [  
[  
"Jul"  
]  
],  
"MONTHDAY": [  
[  
"16"  
]  
],  
"TIME": [  
[  
"07:01:04"  
]  
],  
"HOUR": [  
[  
"07"  
]  
],  
"MINUTE": [  
[  
"01"  
]  
],  
"SECOND": [  
[  
"04"  
]  
],  
"sourceip": [  
[  
"2405:200:204:101:172:26:161:227"  
]  
],  
"seqnum1": [  
[  
"1232887"  
]  
],  
"seqnum2": [  
[  
"1232772"  
]  
],  
"date1": [  
[  
"Jul 16 07:02:25.386 IST:"  
]  
],  
"message": [  
[  
"TCP"  
]  
],  
"severity": [  
[  
"6"  
]  
],  
"mnemonic": [  
[  
"BADAUTH"  
]  
],  
"log\_message": [  
[  
"No MD5 digest from 172.22.4.146(646) to 172.26.161.227(52241) tableid - 0"  
]  
]  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 20, 2017, 7:42pm UTC](https://discuss.elastic.co/t/grok-pattern-not-being-applied-in-logstash-but-working-on-grok-debugger/97384/2 "2017-08-20T19:42:45Z")

</div>

It looks like the grok filter is never run at all and it's not clear why. Is that grok filter the only filter you have?

---

<div class="post-metadata">

**Author:** ![Swaroop\_Chandre](https://avatars.discourse-cdn.com/v4/letter/s/ecc23a/32.png) [@Swaroop\_Chandre](https://discuss.elastic.co/u/Swaroop_Chandre)\
**Post date:** [September 1, 2017, 6:45am UTC](https://discuss.elastic.co/t/grok-pattern-not-being-applied-in-logstash-but-working-on-grok-debugger/97384/3 "2017-09-01T06:45:44Z")

</div>

Sorry for late reply. This resolved.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 29, 2017, 6:45am UTC](https://discuss.elastic.co/t/grok-pattern-not-being-applied-in-logstash-but-working-on-grok-debugger/97384/4 "2017-09-29T06:45:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
