# Grok regex don't match

**URL:** <https://discuss.elastic.co/t/grok-regex-dont-match/170188>\
**Category:** Logstash\
**Created:** [February 27, 2019, 3:03pm UTC](https://discuss.elastic.co/t/grok-regex-dont-match/170188 "2019-02-27T15:03:38Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![elastic\_trg](https://avatars.discourse-cdn.com/v4/letter/e/5e9695/32.png) [@elastic\_trg](https://discuss.elastic.co/u/elastic_trg)\
**Post date:** [February 27, 2019, 3:03pm UTC](https://discuss.elastic.co/t/grok-regex-dont-match/170188/1 "2019-02-27T15:03:38Z")

</div>

Hi everybody,

I'm asking for your help because I can not perform a correct parsing of one of my log. Indeed my original log include regex pattern and I would to delete them. I made a regex whish working fine on [https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/) but when I operate on production I have a grok parse failure.

Below an example of my original message log :

**[wabaudit] action="list" type="approvals" user="k789db" client\_ip="10.10.10.10" infos=""\n**

... and below my filter config file :

```auto
    filter {
                    grok {
                            match => { "message" => "\[wabaudit\] action=(\\\")%{GREEDYDATA:action}(\\\") type=(\\\")%{GREEDYDATA:type}(\\\") user=(\\\")%{GREEDYDATA:user}(\\\") client_ip=(\\\")%{GREEDYDATA:client_ip}(\\\") infos=(\\\")%{GREEDYDATA:infos}(\\\"\\n)" }
                            tag_on_failure => ["_grokparsefailure_F090-WAB.conf"]
                            add_field => { "ES_systemtype" => "WAB" }
                     }
    }

```

Thank you for your help.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 27, 2019, 3:47pm UTC](https://discuss.elastic.co/t/grok-regex-dont-match/170188/2 "2019-02-27T15:47:47Z")

</div>

It will be a lot easier to write the regexp if you use single quotes. And you do not need GREEDYDATA.

```
match => { "message" => '\[wabaudit\] action="%{DATA:action}" type="%{DATA:type}" user="%{DATA:user}" client_ip="%{DATA:client_ip}" infos="%{DATA:infos}"' }

```

Personally I would switch all the patterns to (?[^"]+). And you can anchor the pattern itself

```
match => { "message" => '^\[wabaudit\] action="(?<action>[^"]+)" type="(?<type>[^"]+)" user="(?<user>[^"]+)" client_ip="(?<client_ip>[^"]+)" infos="(?<infos>[^"]+)"' }
```

---

<div class="post-metadata">

**Author:** ![elastic\_trg](https://avatars.discourse-cdn.com/v4/letter/e/5e9695/32.png) [@elastic\_trg](https://discuss.elastic.co/u/elastic_trg)\
**Post date:** [February 27, 2019, 5:42pm UTC](https://discuss.elastic.co/t/grok-regex-dont-match/170188/3 "2019-02-27T17:42:12Z")

</div>

Hello Badger,

I made a mistake on my original message. The message to parse is :

```auto
[wabaudit] action=\"list\" type=\"approvals\" user=\"k789db\" client_ip=\"10.10.10.10\" infos=\"\"\n

```

I would to have in my rubydebug output these fields :

_"message" =\> "[wabaudit] action="list" type="approvals" user=" k789db" client\_ip="10.10.10.10" infos=""\n"_  
_"action" =\> "list"_  
_"type" =\> "approvals"_  
_"user" =\> "k789db"_  
_"client\_ip" =\> "10.10.10.10"_  
_"infos" =\> ""_

Grok debuger working fine :

 ![CaptureGrok](https://us1.discourse-cdn.com/elastic/original/3X/e/b/eb5fbc3ab4a60579e635e214f56818e1ed84fe78.png)

Ragards.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 27, 2019, 6:11pm UTC](https://discuss.elastic.co/t/grok-regex-dont-match/170188/4 "2019-02-27T18:11:06Z")

</div>

Try

```
    grok { match => { "message" => '^\[wabaudit\] action="(?<action>[^"]*)" type="(?<type>[^"]*)" user="(?<user>[^"]*)" client_ip="(?<client_ip>[^"]*)" infos="%{GREEDYDATA:infos}' } }
```

---

<div class="post-metadata">

**Author:** ![elastic\_trg](https://avatars.discourse-cdn.com/v4/letter/e/5e9695/32.png) [@elastic\_trg](https://discuss.elastic.co/u/elastic_trg)\
**Post date:** [February 27, 2019, 6:51pm UTC](https://discuss.elastic.co/t/grok-regex-dont-match/170188/5 "2019-02-27T18:51:52Z")

</div>

Don't working 😕

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 27, 2019, 7:19pm UTC](https://discuss.elastic.co/t/grok-regex-dont-match/170188/6 "2019-02-27T19:19:10Z")

</div>

Wait, do you actually have backslashes in the log message? I assumed that was an artifact of the way you were outputting the message.

To parse a line that looks like this

```
[wabaudit] action=\"list\" type=\"approvals\" user=\"k789db\" client_ip=\"10.10.10.10\" infos=\"\"

```

You can use

```
grok { match => { "message" => '^\[wabaudit\] action=\\"(?<action>[^"]*)\\" type=\\"(?<type>[^"]*)\\" user=\\"(?<user>[^"]*)\\" client_ip=\\"(?<client_ip>[^"]*)\\" infos=\\"%{GREEDYDATA:infos}' } }

```

which will get you

```
     "infos" => "\\\"\n",
      "user" => "k789db",
    "action" => "list",
 "client_ip" => "10.10.10.10",
   "message" => "[wabaudit] action=\\\"list\\\" type=\\\"approvals\\\" user=\\\"k789db\\\" client_ip=\\\"10.10.10.10\\\" infos=\\\"\\\"\n",
      "type" => "approvals"
```

---

<div class="post-metadata">

**Author:** ![elastic\_trg](https://avatars.discourse-cdn.com/v4/letter/e/5e9695/32.png) [@elastic\_trg](https://discuss.elastic.co/u/elastic_trg)\
**Post date:** [March 1, 2019, 5:51pm UTC](https://discuss.elastic.co/t/grok-regex-dont-match/170188/7 "2019-03-01T17:51:13Z")

</div>

I don't have this result with your grok pattern.  
Indeed, I have backslashes in the log message.  
I have performed a tcpdump on the ethernet logstash interface, and I don't have these backslashes. I think Logstash insert these backslashes when the log crossing the udp input plugin. Now I would delete these backslashes to extract the informations.

Below the complete config file :

```auto
input {
   udp {
      port => 2514
      codec => plain { charset => "UTF-8" }
   }
}

filter {
   grok {
      match => { "message" => "\[wabaudit\] action=(\\\")%{GREEDYDATA:action}(\\\") type=(\\\")%{GREEDYDATA:type}(\\\") user=(\\\")%{GREEDYDATA:user}(\\\") client_ip=(\\\")%{GREEDYDATA:client_ip}(\\\") infos=(\\\")%{GREEDYDATA:infos}(\\\"\\n)" }
      match => { "message" => '^\[wabaudit\] action=\\"(?<action>[^"]*)\\" type=\\"(?<type>[^"]*)\\" user=\\"(?<user>[^"]*)\\" client_ip=\\"(?<client_ip>[^"]*)\\" infos=\\"%{GREEDYDATA:infos}' }
      tag_on_failure => ["_grokparsefailure_F090-WAB.conf"]
      add_field => { "ES_systemtype" => "WAB" }
   }
}

output {
   file {
      codec => rubydebug
      path => "/var/log/logstash/1.log"
   }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 1, 2019, 6:01pm UTC](https://discuss.elastic.co/t/grok-regex-dont-match/170188/8 "2019-03-01T18:01:04Z")

</div>

That suggest you do not have backslashes in your message. The rubydebug codec adds them. If you run this configuration

```
input { generator { count => 1 message => '[wabaudit] action=\"list\"' } }
input { generator { count => 1 message => '[wabaudit] action="list"' } }

output { stdout { codec => rubydebug { metadata => false } } }

```

you will get

```
   "message" => "[wabaudit] action=\\\"list\\\""
   "message" => "[wabaudit] action=\"list\""
```

---

<div class="post-metadata">

**Author:** ![elastic\_trg](https://avatars.discourse-cdn.com/v4/letter/e/5e9695/32.png) [@elastic\_trg](https://discuss.elastic.co/u/elastic_trg)\
**Post date:** [March 4, 2019, 12:07pm UTC](https://discuss.elastic.co/t/grok-regex-dont-match/170188/9 "2019-03-04T12:07:30Z")

</div>

Hello Badger,

Thank you for your help ! I was conviced that the backslashes were add in input plugin.  
I rewrite my grok pattern like this :

```auto
match => { "message" => '\[wabaudit\] action="(?<action>[^"]*)" type="(?<type>[^"]*)" user="(?<user>[^"]*)" client_ip="(?<client_ip>[^"]*)" infos="(?<infos>[^"]*)"' }

```

It works perfectly !

Have a good day.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 1, 2019, 12:12pm UTC](https://discuss.elastic.co/t/grok-regex-dont-match/170188/10 "2019-04-01T12:12:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
