# Grok unable to parse message field

**URL:** <https://discuss.elastic.co/t/grok-unable-to-parse-message-field/228822>\
**Category:** Logstash\
**Created:** [April 20, 2020, 9:11am UTC](https://discuss.elastic.co/t/grok-unable-to-parse-message-field/228822 "2020-04-20T09:11:03Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rschirin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rschirin/32/45283_2.png) [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Post date:** [April 20, 2020, 9:11am UTC](https://discuss.elastic.co/t/grok-unable-to-parse-message-field/228822/1 "2020-04-20T09:11:03Z")

</div>

Hi guys,  
using an Ansible's plugin I'm trying to send data to Logstash.  
Eveything seems ok but grok is not able to parse `message` field; I mean, I'm not able to configure it to work correctly ☹  
this is the content of my document:

```auto
{
  "_index": "jenkins-build-2020.04.20",
  "_type": "_doc",
  "_id": "3TnUlnEBnHvd3wub4nHB",
  "_version": 1,
  "_score": null,
  "_source": {
    "source_host": "https://jenkins.net.com/",
    "host": "xxxxx",
    "source": "jenkins",
    "@version": 1,
    "message": [
      "Started by user Mario Rossi",
      "Running as Mario Rossi",
      "Running in Durability level: MAX_SURVIVABILITY"

```

I'm trying to extract user and I tried a lot of combination on grok but everytime I face a `_grokparsefailure`. is there anyone that can help me?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 20, 2020, 3:20pm UTC](https://discuss.elastic.co/t/grok-unable-to-parse-message-field/228822/2 "2020-04-20T15:20:41Z")

</div>

What have you tried?

---

<div class="post-metadata">

**Author:** ![rschirin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rschirin/32/45283_2.png) [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Post date:** [April 20, 2020, 3:40pm UTC](https://discuss.elastic.co/t/grok-unable-to-parse-message-field/228822/3 "2020-04-20T15:40:09Z")

</div>

This is my filter section

```
filter {
       grok {
        break_on_match => false
            match => [
                                "message", " \"Started by user\s%{GREEDYDATA:username.start}\",",
                                "message", "\"Started by user %{DATA:username.start}\","
            ]
       }
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 20, 2020, 3:47pm UTC](https://discuss.elastic.co/t/grok-unable-to-parse-message-field/228822/4 "2020-04-20T15:47:01Z")

</div>

> [@rschirin](#):
>
> "message", " "Started by user\s%{GREEDYDATA:username.start}","

The quotes around "Started by user Mario Rossi" are not part of the field, they are the way rubydebug tells you it is a string. Try

```
grok { match => { "message" => "Started by user %{GREEDYDATA:username.start}" } }

```

---

<div class="post-metadata">

**Author:** ![rschirin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rschirin/32/45283_2.png) [@rschirin](https://discuss.elastic.co/u/rschirin)\
**Post date:** [April 20, 2020, 3:53pm UTC](https://discuss.elastic.co/t/grok-unable-to-parse-message-field/228822/5 "2020-04-20T15:53:01Z")

</div>

I tried also without the double quote but it fails anyway.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 18, 2020, 3:53pm UTC](https://discuss.elastic.co/t/grok-unable-to-parse-message-field/228822/6 "2020-05-18T15:53:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
