# Grok Pattern not parsing

**URL:** <https://discuss.elastic.co/t/grok-pattern-not-parsing/49750>\
**Category:** Logstash\
**Created:** [May 11, 2016, 10:03am UTC](https://discuss.elastic.co/t/grok-pattern-not-parsing/49750 "2016-05-11T10:03:27Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![dlopez](https://avatars.discourse-cdn.com/v4/letter/d/bc79bd/32.png) [@dlopez](https://discuss.elastic.co/u/dlopez)\
**Post date:** [May 11, 2016, 10:03am UTC](https://discuss.elastic.co/t/grok-pattern-not-parsing/49750/1 "2016-05-11T10:03:27Z")

</div>

Hi, I'm trying to parse a log file with content like this:

```
2016-05-09 12:00:00,006 INFO [com.level2.quartz.BaseLevel2EngineJob] (MVCScheduler_Worker-1) Executing job It removes expired activation codes
2016-05-09 12:00:00,006 INFO [com.seglan.mvc.batch.MvcActivationCodesJobImpl] (MVCScheduler_Worker-1) Activation codes cleanup job is running...

```

I've tested the filter using the Grok Debugger but when starting logstash, nothing is parsed.

Here is my logstash.conf file:

```
input {
  file {
        path => "/home/dlopez/server.log"
        start_position => "beginning"
       }
}

filter {
   grok {
     match =>
        {
          "message" => "%{TIMESTAMP_ISO8601:timestamp}%{SPACE}%{LOGLEVEL:level}\s+\[%{DATA:className}\]%{SPACE}%{GREEDYDATA:message}"
        }
   }
}
output {
  elasticsearch {
    hosts => "localhost:9200"
    index => "logstash-%{+YYYY.MM.dd}"
  }
}

```

Is there any way to test the pattern?

Any help would be appreciated. Thanks

Regards

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 11, 2016, 10:44am UTC](https://discuss.elastic.co/t/grok-pattern-not-parsing/49750/2 "2016-05-11T10:44:55Z")

</div>

Comment out the elasticsearch output and replace it with `stdout { codec => rubydebug }` to shorten the feedback loop. You might also find [https://github.com/magnusbaeck/logstash-filter-verifier](https://github.com/magnusbaeck/logstash-filter-verifier) useful.

---

<div class="post-metadata">

**Author:** ![dlopez](https://avatars.discourse-cdn.com/v4/letter/d/bc79bd/32.png) [@dlopez](https://discuss.elastic.co/u/dlopez)\
**Post date:** [May 11, 2016, 12:46pm UTC](https://discuss.elastic.co/t/grok-pattern-not-parsing/49750/3 "2016-05-11T12:46:18Z")

</div>

Thank you very much!

this is what I got:

> {  
> "message" =\> "2016-05-09 12:00:00,029 DEBUG [com.googlecode.genericdao.search.BaseSearchProcessor] (MVCScheduler\_Worker-1) generateQL:",  
> "@version" =\> "1",  
> "@timestamp" =\> "2016-05-11T12:40:49.362Z",  
> "path" =\> "/home/dlopez/server\_test.log",  
> "host" =\> "sgl-v6-hce-piraeusbank-back",  
> "tags" =\> [  
> [0] "\_grokparsefailure"  
> ]  
> }

My parser is not working fine but I don't know why

Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 11, 2016, 1:21pm UTC](https://discuss.elastic.co/t/grok-pattern-not-parsing/49750/4 "2016-05-11T13:21:42Z")

</div>

Start small and increase the complexity. Begin with the simplest possible expression (`%{TIMESTAMP_ISO8601:timestamp}`) and make sure that works. Then add more and more tokens until things break.

---

<div class="post-metadata">

**Author:** ![diwertowski](https://avatars.discourse-cdn.com/v4/letter/d/ac91a4/32.png) [@diwertowski](https://discuss.elastic.co/u/diwertowski)\
**Post date:** [May 11, 2016, 1:32pm UTC](https://discuss.elastic.co/t/grok-pattern-not-parsing/49750/5 "2016-05-11T13:32:06Z")

</div>

You can test your patterns with this debugger:

[http://grokdebug.herokuapp.com/](http://grokdebug.herokuapp.com/)

---

<div class="post-metadata">

**Author:** ![dlopez](https://avatars.discourse-cdn.com/v4/letter/d/bc79bd/32.png) [@dlopez](https://discuss.elastic.co/u/dlopez)\
**Post date:** [May 11, 2016, 1:46pm UTC](https://discuss.elastic.co/t/grok-pattern-not-parsing/49750/6 "2016-05-11T13:46:46Z")

</div>

Thanks, I've used that debugger to compose and test my pattern but unfortunately once I've moved into the system it doesn't work

---

<div class="post-metadata">

**Author:** ![diwertowski](https://avatars.discourse-cdn.com/v4/letter/d/ac91a4/32.png) [@diwertowski](https://discuss.elastic.co/u/diwertowski)\
**Post date:** [May 11, 2016, 2:03pm UTC](https://discuss.elastic.co/t/grok-pattern-not-parsing/49750/7 "2016-05-11T14:03:04Z")

</div>

Maybe something like this?

`%{TIMESTAMP_ISO8601:timestamp} %{WORD:level}\s*\[(?<className>[A-Z,a-z,.,0-9]*)] %{GREEDYDATA:message}`

---

<div class="post-metadata">

**Author:** ![dlopez](https://avatars.discourse-cdn.com/v4/letter/d/bc79bd/32.png) [@dlopez](https://discuss.elastic.co/u/dlopez)\
**Post date:** [May 11, 2016, 2:14pm UTC](https://discuss.elastic.co/t/grok-pattern-not-parsing/49750/8 "2016-05-11T14:14:50Z")

</div>

Ok, it seems the problem was here:

> \s+[%{DATA:className}]

I'm trying to parse the "class name" part of the message, I've tried the following as well but with no luck:

`%{TIMESTAMP_ISO8601:timestamp}%{SPACE} %{LOGLEVEL:level} %{SPACE} %{SPACE} \[%{JAVACLASS:class}\] %{SPACE} %{GREEDYDATA:message}`

Thanks

---

<div class="post-metadata">

**Author:** ![dlopez](https://avatars.discourse-cdn.com/v4/letter/d/bc79bd/32.png) [@dlopez](https://discuss.elastic.co/u/dlopez)\
**Post date:** [May 11, 2016, 2:43pm UTC](https://discuss.elastic.co/t/grok-pattern-not-parsing/49750/9 "2016-05-11T14:43:17Z")

</div>

Well, finally I got it working:

> { "message" =\> "%{TIMESTAMP\_ISO8601:timestamp} %{LOGLEVEL:level} \s+[%{JAVACLASS:class}] %{GREEDYDATA:message} " }

I removed all the ${SPACE} and now it can be parsed

Thanks a lot for your help and clues!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:58am UTC](https://discuss.elastic.co/t/grok-pattern-not-parsing/49750/10 "2017-07-06T04:58:11Z")

</div>


