# Grok works in debugger but not in Logstash

**URL:** <https://discuss.elastic.co/t/grok-works-in-debugger-but-not-in-logstash/272509>\
**Category:** Logstash\
**Created:** [May 9, 2021, 3:59pm UTC](https://discuss.elastic.co/t/grok-works-in-debugger-but-not-in-logstash/272509 "2021-05-09T15:59:26Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![therealjack404](https://avatars.discourse-cdn.com/v4/letter/t/53a042/32.png) [@therealjack404](https://discuss.elastic.co/u/therealjack404)\
**Post date:** [May 9, 2021, 3:59pm UTC](https://discuss.elastic.co/t/grok-works-in-debugger-but-not-in-logstash/272509/1 "2021-05-09T15:59:26Z")

</div>

Hi. I am struggling to write a grok pattern for Modsecurity Logs from the apache error log. I have included a sample log and the grok pattern. I isolated the timestamp creation which works on its own. However the rest works on the debugger but not in logstash. If anyone could help I would appreciate it.

```auto
[Sat May 08 13:18:27.123886 2021] [:error] [pid 8239] [client 192.168.1.1:55894] ModSecurity: Warning. detected SQLi using libinjection with fingerprint 's&sos' [file "/etc/apache2/modsecurity-crs/coreruleset-3.3.0/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf"] [line "65"] [id "942100"] [msg "SQL Injection Attack Detected via libinjection"] [data "Matched Data: s&sos found within ARGS:id: %' OR '0' ='0"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-sqli"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/152/248/66"] [tag "PCI/6.5.2"] [hostname "192.168.1.2"] [uri "/DVWA/vulnerabilities/sqli/"] [unique_id "YJaPo-358QACmukNh@pOhAAAAAQ"], referer: http://192.168.1.2/DVWA/vulnerabilities/sqli/

```

```auto
(?<modsecuritytimestamp> %{MONTH} %{MONTHDAY} %{TIME} %{YEAR})\] \[\:%{LOGLEVEL:loglevel}\].*client\s%{IP:src_ip}.*ModSecurity:(?<alert_message>.*)

```

The logs are shipped from Filebeat to my Elastic Stack machine.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 9, 2021, 4:58pm UTC](https://discuss.elastic.co/t/grok-works-in-debugger-but-not-in-logstash/272509/2 "2021-05-09T16:58:52Z")

</div>

That grok pattern works for me

```
            "loglevel" => "error",
"modsecuritytimestamp" => " May 08 13:18:27.123886 2021",
              "src_ip" => "192.168.1.1",
       "alert_message" => " Warning. detected SQLi using libinjection with fingerprint \\'s&sos\\' [file \"/etc/apache2/modsecurity-crs/coreruleset-3.3.0/rules/REQUEST-942-APPLICATION-ATTACK-SQLI.conf\"] [line \"65\"] [id \"942100\"] [msg \"SQL Injection Attack Detected via libinjection\"] [data \"Matched Data: s&sos found within ARGS:id: %\\' OR \\'0\\' =\\'0\"] [severity \"CRITICAL\"] [ver \"OWASP_CRS/3.3.0\"] [tag \"application-multi\"] [tag \"language-multi\"] [tag \"platform-multi\"] [tag \"attack-sqli\"] [tag \"paranoia-level/1\"] [tag \"OWASP_CRS\"] [tag \"capec/1000/152/248/66\"] [tag \"PCI/6.5.2\"] [hostname \"192.168.1.2\"] [uri \"/DVWA/vulnerabilities/sqli/\"] [unique_id \"YJaPo-358QACmukNh@pOhAAAAAQ\"], referer: http://192.168.1.2/DVWA/vulnerabilities/sqli/",
```

---

<div class="post-metadata">

**Author:** ![therealjack404](https://avatars.discourse-cdn.com/v4/letter/t/53a042/32.png) [@therealjack404](https://discuss.elastic.co/u/therealjack404)\
**Post date:** [May 9, 2021, 5:30pm UTC](https://discuss.elastic.co/t/grok-works-in-debugger-but-not-in-logstash/272509/3 "2021-05-09T17:30:31Z")

</div>

Thank you for responding. That's interesting. Would it be okay if I posted a screenshot of my configuration file? I would just copy the file but it's on a VM and difficult to get. Maybe it's something I'm missing? I can get the timestamp working but none of the rest. Anything else it could be?

---

<div class="post-metadata">

**Author:** ![therealjack404](https://avatars.discourse-cdn.com/v4/letter/t/53a042/32.png) [@therealjack404](https://discuss.elastic.co/u/therealjack404)\
**Post date:** [May 10, 2021, 1:41pm UTC](https://discuss.elastic.co/t/grok-works-in-debugger-but-not-in-logstash/272509/4 "2021-05-10T13:41:39Z")

</div>

In case someone is looking back on this the pattern works I forgot a space after the timestamp field. Thanks for helping badger

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 7, 2021, 1:42pm UTC](https://discuss.elastic.co/t/grok-works-in-debugger-but-not-in-logstash/272509/5 "2021-06-07T13:42:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
