# Grok pattern not working in Logstast

**URL:** <https://discuss.elastic.co/t/grok-pattern-not-working-in-logstast/171289>\
**Category:** Logstash\
**Created:** [March 7, 2019, 11:33am UTC](https://discuss.elastic.co/t/grok-pattern-not-working-in-logstast/171289 "2019-03-07T11:33:08Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vijay\_Khadia](https://avatars.discourse-cdn.com/v4/letter/v/aeb1de/32.png) [@Vijay\_Khadia](https://discuss.elastic.co/u/Vijay_Khadia)\
**Post date:** [March 7, 2019, 11:33am UTC](https://discuss.elastic.co/t/grok-pattern-not-working-in-logstast/171289/1 "2019-03-07T11:33:08Z")

</div>

I have to parse the java Error logs and pass the result to elastic-search. The pattern that I created is working fine when tested on the site '[https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/)'. However the same grok-pattern when I am copying to the xx-xx.conf file its giving error. I am newbie to ELK stack hence unable to detect issue. Could anyone help.  
Below is the content of my file:  
input {  
file {  
path =\> "C:/Users/xx/Downloads/logstash-tutorial/logstash-tutorial-dataset.log"  
start\_position =\> "beginning"  
ignore\_older =\> 0  
sincedb\_path =\> "nil"  
type =\> "javaStackTrace"  
codec =\> multiline {  
pattern =\> "^%{TIMESTAMP\_ISO8601}"  
negate =\> true  
what =\> previous}}}  
filter {  
grok{  
match=\>{  
"message"=\>"%{TIMESTAMP\_ISO8601:timestamp} %{SPACE}[%{LOGLEVEL:loglevel}]%{SPACE}[%{DATA:thread}] %{SPACE}%{JAVACLASS:class} - %{GREEDYDATA:logmessage}\n%{GREEDYDATA:Exception}%{SPACE}(?m)%{JAVASTACKTRACEPART}"}}}

The error that I am getting when executing the logstash is

[2019-03-07T16:25:51,085][INFO][logstash.pipeline] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>4, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50}  
[2019-03-07T16:25:51,239][ERROR][logstash.pipeline] Error registering plugin {:pipeline\_id=\>"main", :plugin=\>"#\<LogStash::FilterDelegator:0x5471213c @metric\_events\_out=org.jruby.proxy.org.logstash.instrument.metrics.counter.LongCounter$Proxy2 - name: out value:0, @metric\_events\_in=org.jruby.proxy.org.logstash.instrument.metrics.counter.LongCounter$Proxy2 - name: in value:0, @metric\_events\_time=org.jruby.proxy.org.logstash.instrument.metrics.counter.LongCounter$Proxy2 - name: duration\_in\_millis value:0, @id="ad9d8390560c5ea3f43e059a39c73a014ed8e17e5df5a8c6c1320088aae6ceab", @klass=LogStash::Filters::Grok, @metric\_events=#LogStash::Instrument::NamespacedMetric:0x4edab5d7, @filter=\<LogStash::Filters::Grok match=\>{"message"=\>"%{TIMESTAMP\_ISO8601:timestamp} %{SPACE}\\[%{LOGLEVEL:loglevel}\\]%{SPACE}\\[%{DATA:thread}\\] %{SPACE}%{JAVACLASS:class} \\- %{GREEDYDATA:logmessage}\\n%{GREEDYDATA:Exception}%{SPACE}(?m)%{JAVASTACKTRACEPART}"}, id=\>"ad9d8390560c5ea3f43e059a39c73a014ed8e17e5df5a8c6c1320088aae6ceab", enable\_metric=\>true, periodic\_flush=\>false, patterns\_files\_glob=\>"_", break\_on\_match=\>true, named\_captures\_only=\>true, keep\_empty\_captures=\>false, tag\_on\_failure=\>["\_grokparsefailure"], timeout\_millis=\>30000, tag\_on\_timeout=\>"\_groktimeout"\>\>", :error=\>"target of repeat operator is not specified: /(?\<TIMESTAMP\_ISO8601:timestamp\>(?:(?\>\d\d){1,2})-(?:(?:0?[1-9]|1[0-2]))-(?:(?:(?:0[1-9])|(?:[12][0-9])|(?:3[01])|[1-9]))T :?(?:(?:[0-5][0-9]))(?::?(?:(?:(?:[0-5]?[0-9]|60)(?:[:.,][0-9]+)?)))?(?:(?:Z|+-(?::?(?:(?:[0-5][0-9])))))?) (?:\s_)\(?LOGLEVEL:loglevel([Aa]lert|ALERT|[Tt]race|TRACE|[Dd]ebug|DEBUG|[Nn]otice|NOTICE|[Ii]nfo|INFO|[Ww]arn?(?:ing)?|WARN?(?:ING)?|[Ee]rr?(?:or)?|ERR?(?:OR)?|[Cc]rit?(?:ical)?|CRIT?(?:ICAL)?|[Ff]atal|FATAL|[Ss]evere|SEVERE|EMERG(?:ENCY)?|[Ee]merg(?:ency)?))\\[(?\<DATA:thread\>._?)\] (?:\s_)(?JAVACLASS:class(?:+\.)+[A-Za-z0-9$]+) \- (?GREEDYDATA:logmessage._)\n(?GREEDYDATA:Exception._)(?:\s\*)(?m)(?:(?:\s\*)at (?JAVACLASS:class(?:+\.)+[A-Za-z0-9$]+)\.(?JAVAMETHOD:method(?:(\<(?:cl)?init\>)|[a-zA-Z$_][a-zA-Z$0-9]\*))\((?JAVAFILE:file(?:[A-Za-z0-9.-]+))(?::(?NUMBER:line(?:(?:(?\<![0-9.+-])(?\>[+-]?(?:(?:[0-9]+(?:\.[0-9]+)?)|(?:\.[0-9]+)))))))?\))/m", :thread=\>"#\<Thread:0xbd47599 run\>"}  
[2019-03-07T16:25:51,244][ERROR][logstash.pipeline] Pipeline aborted due to error {:pipeline\_id=\>"main", :exception=\>#\<RegexpError: target of repeat operator is not specified: /(?\<TIMESTAMP\_ISO8601:timestamp\>(?:(?\>\d\d){1,2})-(?:(?:0?[1-9]|1[0-2]))-(?:(?:(?:0[1-9])|(?:[12][0-9])|(?:3[01])|[1-9]))T :?(?:(?:[0-5][0-9]))(?::?(?:(?:(?:[0-5]?[0-9]|60)(?:[:.,][0-9]+)?)))?(?:(?:Z|+-(?::?(?:(?:[0-5][0-9])))))?) (?:\s\*)[(?LOGLEVEL:loglevel([Aa]lert|ALERT|[Tt]race|TRACE|[Dd]ebug|DEBUG|[Nn]otice|NOTICE|[Ii]nfo|INFO|[Ww]arn?(?:ing)?|WARN?(?:ING)?|[Ee]rr?(?:or)?|ERR?(?:OR)?|[Cc]rit?(?:ical)?|CRIT?(?:ICAL)?|[Ff]atal|FATAL|[Ss]evere|SEVERE|EMERG(?:ENCY)?|[Ee]merg(?:ency)?))](?:\s\*)[(?\<DATA:thread\>.?)] (?:\s)(?JAVACLASS:class(?:+.)+[A-Za-z0-9$]+) - (?GREEDYDATA:logmessage.)\n(?GREEDYDATA:Exception.)(?:\s\*)(?m)(?:(?:\s\*)at (?JAVACLASS:class(?:+.)+[A-Za-z0-9$]+).(?JAVAMETHOD:method(?:(\<(?:cl)?init\>)|[a-zA-Z$_][a-zA-Z$_0-9]\*))((?JAVAFILE:file(?:[A-Za-z0-9_.-]+))(?::(?NUMBER:line(?:(?:(?\<![0-9.+-])(?\>[+-]?(?:(?:[0-9]+(?:.[0-9]+)?)|(?:.[0-9]+)))))))?))/m\>, :backtrace=\>["org/jruby/RubyRegexp.java:928:in `initialize'", "C:/Users/Documents/logstash-6.5.1/vendor/bundle/jruby/2.3.0/gems/jls-grok-0.11.5/lib/grok-pure.rb:127:in`compile'", "C:/Users/Documents/logstash-6.5.1/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.4/lib/logstash/filters/grok.rb:281:in `block in register'", "org/jruby/RubyArray.java:1734:in`each'", "C:/Users/Documents/logstash-6.5.1/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.4/lib/logstash/filters/grok.rb:275:in `block in register'", "org/jruby/RubyHash.java:1343:in`each'", "C:/Users/Documents/logstash-6.5.1/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.4/lib/logstash/filters/grok.rb:270:in `register'", "C:/Users/Documents/logstash-6.5.1/logstash-core/lib/logstash/pipeline.rb:242:in`register\_plugin'", "C:/Users/Documents/logstash-6.5.1/logstash-core/lib/logstash/pipeline.rb:253:in `block in register_plugins'", "org/jruby/RubyArray.java:1734:in`each'", "C:/Users/Documents/logstash-6.5.1/logstash-core/lib/logstash/pipeline.rb:253:in `register_plugins'", "C:/Users/Documents/logstash-6.5.1/logstash-core/lib/logstash/pipeline.rb:595:in`maybe\_setup\_out\_plugins'", "C:/Users/Documents/logstash-6.5.1/logstash-core/lib/logstash/pipeline.rb:263:in `start_workers'", "C:/Users/Documents/logstash-6.5.1/logstash-core/lib/logstash/pipeline.rb:200:in`run'", "C:/Users/Documents/logstash-6.5.1/logstash-core/lib/logstash/pipeline.rb:160:in `block in start'"], :thread=\>"#\<Thread:0xbd47599 run\>"}  
[2019-03-07T16:25:51,269][ERROR][logstash.agent] Failed to execute action {:id=\>:main, :action\_type=\>LogStash::ConvergeResult::FailedAction, :message=\>"Could not execute action: PipelineAction::Create, action\_result: false", :backtrace=\>nil}  
[2019-03-07T16:25:51,706][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

Sample Log I tested in the above mentioned url:  
2019-01-09 15:00:05.800 [ERROR] [http-nio-9096-exec-1] com.exapmle.exception.GlobalExceptionFacade - Application encountered as unexpected error  
java.lang.NullPointerException: null  
at com.exapmle.service.impl.DashboardOverviewServiceImpl.contBusinessSpend(DashboardOverviewServiceImpl.java:2149)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 4, 2019, 11:35am UTC](https://discuss.elastic.co/t/grok-pattern-not-working-in-logstast/171289/2 "2019-04-04T11:35:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
