# Grok Pattern works in Grok debugger but fails in the parsing

**URL:** https://discuss.elastic.co/t/grok-pattern-works-in-grok-debugger-but-fails-in-the-parsing/189115
**Category:** Logstash
**Created:** [July 5, 2019, 1:38pm UTC](https://discuss.elastic.co/t/grok-pattern-works-in-grok-debugger-but-fails-in-the-parsing/189115 "2019-07-05T13:38:07Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![hyder](https://avatars.discourse-cdn.com/v4/letter/h/a183cd/32.png) [@hyder](https://discuss.elastic.co/u/hyder)
#### Post date: [July 5, 2019, 1:38pm UTC](https://discuss.elastic.co/t/grok-pattern-works-in-grok-debugger-but-fails-in-the-parsing/189115/1 "2019-07-05T13:38:07Z")

</div>

The Grok Patter works in Grok debugger but fails to parse in logstash. I need help not sure whats wrong, I need to sort out ERROR logs separate Index and regular Debug into different index, My trying to get parsing done, but not sure, need some help.

When I test the patter in debugger it works  
{  
"package": "util.IConveUtility ",  
"javaclass": "DAWSConnThread",  
"log": " domainInitRqst::1::null::DDS\_DATA\_SOURCE\_UNAVAILABLE::[[ERROR,Participant Error:null]]",  
"action": " DAError",  
"LEVEL": "ERROR",  
"timestamp": "2019-07-03 03:06:10,043"  
}

## Input data

## DEBUG 2019-07-03 02:58:42,024 [main] util.IConveUtility - Files are deleted.. DEBUG 2019-07-03 02:58:42,024 [main] util.IConveUtility - Output file created ERROR 2019-07-03 03:06:10,043 [DAWSConnThread] App.DAErrorHandler - DAError: domainInitRqst::1::null::DDS\_DATA\_SOURCE\_UNAVAILABLE::[[ERROR,Participant Error:null]]

input {  
file{  
path=\> "c:/tmp/test.log"  
start\_position=\>"beginning"  
sincedb\_path =\> "c:/tmp/null.sincedb"  
}  
}

filter {  
grok{   
match =\> { "message" =\> "%{LOGLEVEL:LEVEL} \*%{TIMESTAMP\_ISO8601:timestamp} [%{JAVACLASS:javaclass}] %{DATA:package}-%{DATA:action}\ \*:%{GREEDYDATA:log}" }  
}   
}

output {  
if "ERROR" in [LEVEL]  
{file { path =\> "c:/tmp/test-error.txt" }}   
file { path =\> "c:/tmp/test-error-2.txt" }  
}

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [July 5, 2019, 3:57pm UTC](https://discuss.elastic.co/t/grok-pattern-works-in-grok-debugger-but-fails-in-the-parsing/189115/2 "2019-07-05T15:57:50Z")

</div>

Your first problem is that your "JAVACLASS" does not match the JAVACLASS pattern, which requires two or more words separated using period.

I would use dissect to parse that.

```
dissect { mapping => { "message" => "%{LEVEL} %{timestamp} %{+timestamp} [%{javaclass}] %{package} - %{restOfLine}" } }

```

Then grok the [restOfLine] field.

If you want to go forward using grok make sure you [understand why](https://www.elastic.co/blog/do-you-grok-grok) you should anchor your patterns to start of line if possible.

---

<div class="post-metadata">

### Author: ![hyder](https://avatars.discourse-cdn.com/v4/letter/h/a183cd/32.png) [@hyder](https://discuss.elastic.co/u/hyder)
#### Post date: [July 6, 2019, 6:55pm UTC](https://discuss.elastic.co/t/grok-pattern-works-in-grok-debugger-but-fails-in-the-parsing/189115/3 "2019-07-06T18:55:05Z")

</div>

Thank you very much.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 3, 2019, 7:09pm UTC](https://discuss.elastic.co/t/grok-pattern-works-in-grok-debugger-but-fails-in-the-parsing/189115/4 "2019-08-03T19:09:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
