Hi Stephen,
Hope you're doing well!
I tested the Grok pattern, and it worked in the test with all fields. However, now I started from scratch and applied it to the pipeline, it never worked.
POST _ingest/pipeline/logs-vsphere.log@custom/_simulate
{
"docs": [
{
"_source": {
"_index": ".ds-logs-vsphere.log-default-2025.03.02-000005",
"_id": "dtPIf5UBYuBgAluqaK6T",
"_version": 1,
"_score": 0,
"_source": {
"input": {
"type": "tcp"
},
"agent": {
"name": "x.xyz.local",
"id": "378ef5d0-3bfe-4304-8394-c96722767888",
"type": "filebeat",
"ephemeral_id": "3b51a122-db57-4de0-a2e6-d64c43fdb43b",
"version": "8.15.3"
},
"@timestamp": "2025-03-10T11:19:51.334Z",
"ecs": {
"version": "8.11.0"
},
"log": {
"source": {
"address": "10.10.0.83:58332"
}
},
"data_stream": {
"namespace": "default",
"type": "logs",
"dataset": "vsphere.log"
},
"elastic_agent": {
"id": "378ef5d0-3bfe-4304-8394-c96722767888",
"version": "8.15.3",
"snapshot": false
},
"host": {
"hostname": "x.xyz.local",
"os": {
"kernel": "6.8.0-47-generic",
"codename": "noble",
"name": "Ubuntu",
"type": "linux",
"family": "debian",
"version": "24.04.1 LTS (Noble Numbat)",
"platform": "ubuntu"
},
"containerized": false,
"ip": [
"10.10.0.237",
"fe80::250:56ff:fe9a:25bb"
],
"name": "x.xyz.local",
"id": "21aa5bdee5e2419cba57751eb5c6887c",
"mac": [
"00-50-56-9A-25-BB"
],
"architecture": "x86_64"
},
"event": {
"agent_id_status": "verified",
"ingested": "2025-03-10T11:19:55Z",
"dataset": "vsphere.log"
},
"error": {
"message": [
"Provided Grok expressions do not match field value: [<14>1 2025-03-10T12:19:51.315514+01:00 VEEAMMGMT01 Veeam_MP - - [origin enterpriseId=\\\"31023\\\"] [categoryId=0 instanceId=450 JobSessionID=\\\"01bed5e1-40f7-4ee4-a960-4aaaf2c26b71\\\" JobID=\\\"8f97b7bb-86ca-430b-a159-950f93a21434\\\" JobType=\\\"63\\\" TaskSessionID=\\\"eecb32ca-4481-4807-8be8-8d082c4c8d71\\\" OibID=\\\"1fe7254d-fe6f-42aa-870c-cff1d751daa4\\\" OriginalOibID=\\\"6612eaff-3251-4b59-87eb-311f2ed65012\\\" CreationTime=\\\"03/10/2025 11:15:34\\\" Status=\\\"5\\\" SourceHostName=\\\"vmvc.xyz.local\\\" VmRef=\\\"vm-866847\\\" VmName=\\\"ADFS03\\\" TransferredGb=\\\"22.805\\\" Platform=\\\"0\\\" IsRetry=\\\"False\\\" VbrHostName=\\\"VEEAMMGMT01.xyz.local\\\" VbrVersion=\\\"12.2.0.334\\\" Version=\\\"1\\\" Description=\\\"VM ADFS03 task has finished with 'InProgress' state.\\\"]]"
]
},
"tags": [
"vmware-vsphere"
]
},
"fields": {
"elastic_agent.version": [
"8.15.3"
],
"host.os.name.text": [
"Ubuntu"
],
"host.name.text": [
"x.xyz.local"
],
"host.hostname": [
"x.xyz.local"
],
"host.mac": [
"00-50-56-9A-25-BB"
],
"host.ip": [
"10.10.0.237",
"fe80::250:56ff:fe9a:25bb"
],
"agent.type": [
"filebeat"
],
"event.module": [
"vsphere"
],
"agent.name.text": [
"x.xyz.local"
],
"host.os.version": [
"24.04.1 LTS (Noble Numbat)"
],
"host.os.kernel": [
"6.8.0-47-generic"
],
"host.os.name": [
"Ubuntu"
],
"agent.name": [
"x.xyz.local"
],
"elastic_agent.snapshot": [
false
],
"host.name": [
"x.xyz.local"
],
"event.agent_id_status": [
"verified"
],
"host.id": [
"21aa5bdee5e2419cba57751eb5c6887c"
],
"host.os.type": [
"linux"
],
"elastic_agent.id": [
"378ef5d0-3bfe-4304-8394-c96722767888"
],
"data_stream.namespace": [
"default"
],
"host.os.codename": [
"noble"
],
"input.type": [
"tcp"
],
"data_stream.type": [
"logs"
],
"tags": [
"vmware-vsphere"
],
"host.architecture": [
"x86_64"
],
"event.ingested": [
"2025-03-10T11:19:55.000Z"
],
"@timestamp": [
"2025-03-10T11:19:51.334Z"
],
"agent.id": [
"378ef5d0-3bfe-4304-8394-c96722767888"
],
"ecs.version": [
"8.11.0"
],
"host.containerized": [
false
],
"host.os.platform": [
"ubuntu"
],
"error.message": [
"Provided Grok expressions do not match field value: [<14>1 2025-03-10T12:19:51.315514+01:00 VEEAMMGMT01 Veeam_MP - - [origin enterpriseId=\\\"31023\\\"] [categoryId=0 instanceId=450 JobSessionID=\\\"01bed5e1-40f7-4ee4-a960-4aaaf2c26b71\\\" JobID=\\\"8f97b7bb-86ca-430b-a159-950f93a21434\\\" JobType=\\\"63\\\" TaskSessionID=\\\"eecb32ca-4481-4807-8be8-8d082c4c8d71\\\" OibID=\\\"1fe7254d-fe6f-42aa-870c-cff1d751daa4\\\" OriginalOibID=\\\"6612eaff-3251-4b59-87eb-311f2ed65012\\\" CreationTime=\\\"03/10/2025 11:15:34\\\" Status=\\\"5\\\" SourceHostName=\\\"vmvc.xyz.local\\\" VmRef=\\\"vm-866847\\\" VmName=\\\"ADFS03\\\" TransferredGb=\\\"22.805\\\" Platform=\\\"0\\\" IsRetry=\\\"False\\\" VbrHostName=\\\"VEEAMMGMT01.xyz.local\\\" VbrVersion=\\\"12.2.0.334\\\" Version=\\\"1\\\" Description=\\\"VM ADFS03 task has finished with 'InProgress' state.\\\"]]"
],
"log.source.address": [
"10.10.0.83:58332"
],
"data_stream.dataset": [
"vsphere.log"
],
"agent.ephemeral_id": [
"3b51a122-db57-4de0-a2e6-d64c43fdb43b"
],
"agent.version": [
"8.15.3"
],
"host.os.family": [
"debian"
],
"event.dataset": [
"vsphere.log"
]
}
}
}
]
}
That gives me error:
{
"error": {
"root_cause": [
{
"type": "illegal_argument_exception",
"reason": "unexpected metadata [_id:dtPIf5UBYuBgAluqaK6T, _index:.ds-logs-vsphere.log-default-2025.03.02-000005, _version:1] in source"
}
],
"type": "illegal_argument_exception",
"reason": "unexpected metadata [_id:dtPIf5UBYuBgAluqaK6T, _index:.ds-logs-vsphere.log-default-2025.03.02-000005, _version:1] in source"
},
"status": 400
}