# Grok patterns with ( { \[ . , \\ /

**URL:** <https://discuss.elastic.co/t/grok-patterns-with/117298>\
**Category:** Logstash\
**Created:** [January 27, 2018, 11:19am UTC](https://discuss.elastic.co/t/grok-patterns-with/117298 "2018-01-27T11:19:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Farhad\_Yousefi](https://avatars.discourse-cdn.com/v4/letter/f/b487fb/32.png) [@Farhad\_Yousefi](https://discuss.elastic.co/u/Farhad_Yousefi)\
**Post date:** [January 27, 2018, 11:19am UTC](https://discuss.elastic.co/t/grok-patterns-with/117298/1 "2018-01-27T11:19:53Z")

</div>

Hi . I want to catch my exception with ELK but my exception is full of ( { [ . , \ / , " ' character. How can I index them in grok .  
thank you

my log file:

```
Exception in ***CoreLevel*** occured. 
Date&Time: 2018-01-21 09:52:20.744092 
Root: 
 ( ['MQROOT' : 0x7f0a902b2d80]
  (0x01000000:Name ):Properties = ( ['MQPROPERTYPARSER' : 0x7f0a902bffa0]
    (0x03000000:NameValue):MessageFormat = 'jms_text' (CHARACTER) )
    (0x03000000:NameValue):MsgId = X'5059414d313339363131303234383030303238' (BLOB))
    (0x01000000:Name ):usr = (
      (0x03000000:NameValue):MessageName = 'SampleMessageName' (CHARACTER)
      (0x03000000:NameValue):MsgVersion = 'V1' (CHARACTER)
    )
  )
) 
***************************************************************************************** 
***************************************************************************************** 
ExceptionList:  
( ['MQROOT' : 0x7f0a9072b350]
  (0x01000000:Name):RecoverableException = (
    (0x03000000:NameValue):File = '/build/slot1/S800_P/src/DataFlowEngine/PluginInterface/ImbJniNode.cpp' (CHARACTER)
    (0x03000000:NameValue):Line = 1260 (INTEGER)
    (0x03000000:NameValue):Text = 'Caught exception and rethrowing' (CHARACTER)
    (0x01000000:Name ):Insert = (
      (0x03000000:NameValue):Type = 14 (INTEGER)
    )
          (0x03000000:NameValue):Label = '' (CHARACTER)
          (0x03000000:NameValue):Catalog = "BIPmsgs" (CHARACTER)
          (0x03000000:NameValue):Severity = 3 (INTEGER)
          (0x03000000:NameValue):Number = 4395 (INTEGER)
   )
  )
)

```

and I except to get this pattern into kibana

```
Exception in: CoreLevel, 
Date&Time: 2018-01-21 09:52:20.744092
message:{
  Root:".....",
  ExceptionList:"......"
}

```

and this is my grok block that doesn't work

```
 grok {
    patterns_dir => "/etc/logstash/patterns/"
    break_on_match => false
    keep_empty_captures => true
    
    match => {"message" => ["Exception in (?<msg_f> occured..) Date&Time: %{SYSLOGTIMESTAMP:timestamp}"]}
 }

  mutate {
        gsub => ["message", "\n", ""]
 }

```

I really appropriate if anyone can help me. thank you

---

<div class="post-metadata">

**Author:** ![Vladi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vladi/32/108686_2.png) [@Vladi](https://discuss.elastic.co/u/Vladi)\
**Post date:** [January 27, 2018, 1:38pm UTC](https://discuss.elastic.co/t/grok-patterns-with/117298/2 "2018-01-27T13:38:07Z")

</div>

Hi Farhad,

Just look into multiline grok | regular expressions carefully.

P.S. some questions just should go to freelance.  
V.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 24, 2018, 1:38pm UTC](https://discuss.elastic.co/t/grok-patterns-with/117298/3 "2018-02-24T13:38:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
