# Grok processor in pipeline throws json\_parse\_exception

**URL:** <https://discuss.elastic.co/t/grok-processor-in-pipeline-throws-json-parse-exception/125251>\
**Category:** Elasticsearch\
**Created:** [March 22, 2018, 6:38pm UTC](https://discuss.elastic.co/t/grok-processor-in-pipeline-throws-json-parse-exception/125251 "2018-03-22T18:38:06Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sonia\_Gupta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sonia_gupta/32/49646_2.png) [@Sonia\_Gupta](https://discuss.elastic.co/u/Sonia_Gupta)\
**Post date:** [March 22, 2018, 6:38pm UTC](https://discuss.elastic.co/t/grok-processor-in-pipeline-throws-json-parse-exception/125251/1 "2018-03-22T18:38:07Z")

</div>

Unable to use regex for grok pattern:

when I give the following:  
POST \_ingest/pipeline/\_simulate  
{  
"pipeline": {  
"description" : "parse multiple patterns",  
"processors": [  
{  
"grok": {  
"field": "message",  
"patterns": ["\s\*%{LOGLEVEL:level}\s\*"]  
}  
}  
]  
},  
"docs":[  
{  
"\_source": {  
"message": "[2018-03-21T22:27:34,362] INFO [o.e.n.Node] [Lf9T-uu] starting ..."  
}  
}  
]  
}

I get this output:  
{  
"error": {  
"root\_cause": [  
{  
"type": "parse\_exception",  
"reason": "Failed to parse content to map"  
}  
],  
"type": "parse\_exception",  
"reason": "Failed to parse content to map",  
"caused\_by": {  
"type": "json\_parse\_exception",  
"reason": "Unrecognized character escape 's' (code 115)\n at [Source: org.elasticsearch.transport.netty4.ByteBufStreamInput@21fdd9ae; line: 8, column: 25]"  
}  
},  
"status": 400  
}

---

<div class="post-metadata">

**Author:** ![Bernt\_Rostad](https://avatars.discourse-cdn.com/v4/letter/b/3ab097/32.png) [@Bernt\_Rostad](https://discuss.elastic.co/u/Bernt_Rostad)\
**Post date:** [March 23, 2018, 6:33am UTC](https://discuss.elastic.co/t/grok-processor-in-pipeline-throws-json-parse-exception/125251/2 "2018-03-23T06:33:49Z")

</div>

The parser exception tells you what's wrong, the "\s" is an unknown escape sequence. Instead, just use space characters around the grok pattern for the file level:

```
POST _ingest/pipeline/_simulate
{
  "pipeline": {
    "description" : "parse multiple patterns",
    "processors": [
      {
        "grok": {
          "field": "message",
          "patterns": [" %{LOGLEVEL:level} "]
        }
      }
    ]
  },
  "docs":[
    {
      "_source": {
        "message": "[2018-03-21T22:27:34,362] INFO [o.e.n.Node] [Lf9T-uu] starting ..."
      }
    }
  ]
}

```

Output (in my Kibana):

```
{
  "docs": [
    {
      "doc": {
        "_index": "_index",
        "_type": "_type",
        "_id": "_id",
        "_source": {
          "message": "[2018-03-21T22:27:34,362] INFO [o.e.n.Node] [Lf9T-uu] starting ...",
          "level": "INFO"
        },
        "_ingest": {
          "timestamp": "2018-03-23T06:30:28.633Z"
        }
      }
    }
  ]
}
```

---

<div class="post-metadata">

**Author:** ![Sonia\_Gupta](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sonia_gupta/32/49646_2.png) [@Sonia\_Gupta](https://discuss.elastic.co/u/Sonia_Gupta)\
**Post date:** [March 27, 2018, 6:30pm UTC](https://discuss.elastic.co/t/grok-processor-in-pipeline-throws-json-parse-exception/125251/3 "2018-03-27T18:30:03Z")

</div>

Thanks that worked, but when I specify multiple patterns, it failed again:

```
POST _ingest/pipeline/_simulate

```

{  
"pipeline": {  
"description" : "parse multiple patterns",  
"processors": [  
{  
"grok": {  
"field": "message",  
"patterns": [" %{LOGLEVEL:level} ", "[%{LOGLEVEL:level}]", "level=%{LOGLEVEL:level} ", "level=\>:%{LOGLEVEL:level}"]  
}  
}  
]  
},  
"docs":[  
{  
"\_source": {  
"message": "[2018-03-21T22:27:34,362] INFO [o.e.n.Node] [Lf9T-uu] starting ..."  
}  
}  
]  
}

OUTPUT:

```
{

```

"docs": [  
{  
"doc": {  
"\_index": "\_index",  
"\_type": "\_type",  
"\_id": "\_id",  
"\_source": {  
"message": "[2018-03-21T22:27:34,362] INFO [o.e.n.Node] [Lf9T-uu] starting ..."  
},  
"\_ingest": {  
"timestamp": "2018-03-27T18:26:11.927Z"  
}  
}  
}  
]  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 24, 2018, 6:30pm UTC](https://discuss.elastic.co/t/grok-processor-in-pipeline-throws-json-parse-exception/125251/4 "2018-04-24T18:30:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
