# Grok works (no grok parse failure) but doesnt create the fields

**URL:** <https://discuss.elastic.co/t/grok-works-no-grok-parse-failure-but-doesnt-create-the-fields/269203>\
**Category:** Logstash\
**Created:** [April 5, 2021, 3:35am UTC](https://discuss.elastic.co/t/grok-works-no-grok-parse-failure-but-doesnt-create-the-fields/269203 "2021-04-05T03:35:41Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![ElasticLiver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticliver/32/64869_2.png) [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Post date:** [April 5, 2021, 3:35am UTC](https://discuss.elastic.co/t/grok-works-no-grok-parse-failure-but-doesnt-create-the-fields/269203/1 "2021-04-05T03:35:41Z")

</div>

Hi I have a field called "if\_speed\_in\_out", this field contains strings like this "100 Mbps:100 Mbps" i have tested the grok on kibana devs tools and works, but never create the fields defined in the grok, just get the original field.

```auto
filter {
     grok {
         match => { "if_speed_in_out" => "%{DATA:if_speed_in} %{DATA:if_speed_unit_in}:%{DATA:if_speed_out} %{GREEDYDATA:if_speed_unit_out}" }
     }
}

```

the output

```auto
"if_speed_in_out":"100 Mbps:100 Mbps"

```

Any ideas on whats going on?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 5, 2021, 4:57am UTC](https://discuss.elastic.co/t/grok-works-no-grok-parse-failure-but-doesnt-create-the-fields/269203/2 "2021-04-05T04:57:31Z")

</div>

Does the input really have unbalanced` "` quotes

Your sample has 2 leading quotes and 1 trailing quote

`""100 Mbps:100 Mbps"`

Did you already parse into that field before?

Also your output has unbalanced quotes as well?

Also just use `DATA` on your last `if_speed_unit_out`

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 5, 2021, 5:01am UTC](https://discuss.elastic.co/t/grok-works-no-grok-parse-failure-but-doesnt-create-the-fields/269203/3 "2021-04-05T05:01:42Z")

</div>

I just tested this pattern

```
"%{DATA:if_speed_in} %{DATA:if_speed_unit_in}:%{DATA:if_speed_out} %{DATA:if_speed_unit_out}"

```

With this data

`"100 MBS:256 MBS"`

Looks good perhaps you have some other issue in your logstash conf.

---

<div class="post-metadata">

**Author:** ![ElasticLiver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticliver/32/64869_2.png) [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Post date:** [April 5, 2021, 5:45am UTC](https://discuss.elastic.co/t/grok-works-no-grok-parse-failure-but-doesnt-create-the-fields/269203/4 "2021-04-05T05:45:22Z")

</div>

Hi, @stephenb, sorry about the extra quotes, was a typo...the pipeline is for testing, so its really simple, I get data from de DB and I dont see any problem with it

```auto
input {
    jdbc {
        jdbc_connection_string => "connection-string"
        jdbc_user => "myuser"
        jdbc_password => "mypass"
        jdbc_driver_class => "Java::com.sybase.jdbc4.jdbc.SybDriver"
        jdbc_default_timezone => "America/Lima"
        statement => "SELECT [Node Name] as node_name, [Interface Speed (In:Out)] as if_speed_in_out
                FROM InterfaceMetrics;"
    }
}
filter {

     grok {
         match => { "if_speed_in_out" => "%{DATA:if_speed_in} %{DATA:if_speed_unit_in}:%{DATA:if_speed_out} %{GREEDYDATA:if_speed_unit_out}" }
     }

     if [if_speed_unit_in] == [if_speed_unit_out] {
          grok { match => ["if_speed_unit_in" , "%{DATA:if_speed_unit}"]}
          mutate {
             remove_field => ["if_speed_unit_in", "if_speed_unit_out"]
          }
     }

     if [if_speed_in] == [if_speed_out] {
           grok { match => ["if_speed_in" , "%{DATA:if_speed}"]}
           mutate {
              remove_field => ["if_speed_in", "if_speed_out"]
           }
       }
}
output {
   file { path => "/etc/logstash/conf.d/test_deleteme.json" codec => json_lines }
}
```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 5, 2021, 6:16am UTC](https://discuss.elastic.co/t/grok-works-no-grok-parse-failure-but-doesnt-create-the-fields/269203/5 "2021-04-05T06:16:09Z")

</div>

You don't need those 2nd and 3rd groks just use [mutate with copy](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-copy) much more efficient.

What does the output doc look like?

---

<div class="post-metadata">

**Author:** ![ElasticLiver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticliver/32/64869_2.png) [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Post date:** [April 5, 2021, 2:50pm UTC](https://discuss.elastic.co/t/grok-works-no-grok-parse-failure-but-doesnt-create-the-fields/269203/6 "2021-04-05T14:50:25Z")

</div>

this is the output:

```auto
{"@version":"1","if_speed_in_out":"1 Gbps:1 Gbps","node_name":"LMmp-02","@timestamp":"2021-04-05T14:37:23.829Z"}
{"@version":"1","if_speed_in_out":"1 Gbps:1 Gbps","node_name":"ANAGG-01","@timestamp":"2021-04-05T14:37:23.831Z"}
{"@version":"1","if_speed_in_out":"0 bps:0 bps","node_name":"C01-Default","@timestamp":"2021-04-05T14:37:23.834Z"}
{"@version":"1","if_speed_in_out":"1.41 Gbps:1.41 Gbps","node_name":"CORE-O1(2)","@timestamp":"2021-04-05T14:37:23.836Z"}

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 5, 2021, 3:24pm UTC](https://discuss.elastic.co/t/grok-works-no-grok-parse-failure-but-doesnt-create-the-fields/269203/7 "2021-04-05T15:24:15Z")

</div>

> [@ElasticLiver](#):
>
> ```auto
> {"@version":"1","if_speed_in_out":"1 Gbps:1 Gbps","node_name":"LMmp-02","@timestamp":"2021-04-05T14:37:23.829Z"}
> {"@version":"1","if_speed_in_out":"1 Gbps:1 Gbps","node_name":"ANAGG-01","@timestamp":"2021-04-05T14:37:23.831Z"}
> {"@version":"1","if_speed_in_out":"0 bps:0 bps","node_name":"C01-Default","@timestamp":"2021-04-05T14:37:23.834Z"}
> {"@version":"1","if_speed_in_out":"1.41 Gbps:1.41 Gbps","node_name":"CORE-O1(2)","@timestamp":"2021-04-05T14:37:23.836Z"}
> 
> ```

Try this

```
filter {

  dissect {
    mapping => {
      "if_speed_in_out" => "%{if_speed_in} %{if_speed_unit_in}:%{if_speed_out} %{if_speed_unit_out}"
    }
  }

  if [if_speed_unit_in] == [if_speed_unit_out] {
    mutate {
      add_field => { "if_speed_unit" => "%{if_speed_unit_in}" }
      remove_field => ["if_speed_unit_in", "if_speed_unit_out"]
    }
  }

  if [if_speed_in] == [if_speed_out] {
    mutate {
      add_field => { "if_speed" => "%{if_speed_in}" }
      remove_field => ["if_speed_in", "if_speed_out"]
    }
  }
}

```

I took your output above and ran it though so as long as the input fields are there it should work.

Sample output

```
{
         "@timestamp" => 2021-04-05T14:37:23.831Z,
           "if_speed" => "1",
          "node_name" => "ANAGG-01",
               "path" => "/Users/sbrown/workspace/elastic-install/7.12.0/logstash-7.12.0/test.json",
    "if_speed_in_out" => "1 Gbps:1 Gbps",
               "host" => "ceres",
      "if_speed_unit" => "Gbps",
           "@version" => "1"
}

```

---

<div class="post-metadata">

**Author:** ![ElasticLiver](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticliver/32/64869_2.png) [@ElasticLiver](https://discuss.elastic.co/u/ElasticLiver)\
**Post date:** [April 6, 2021, 3:15pm UTC](https://discuss.elastic.co/t/grok-works-no-grok-parse-failure-but-doesnt-create-the-fields/269203/8 "2021-04-06T15:15:45Z")

</div>

thanks @stephenb it works nicely. 👏 👏 👏

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 4, 2021, 3:16pm UTC](https://discuss.elastic.co/t/grok-works-no-grok-parse-failure-but-doesnt-create-the-fields/269203/9 "2021-05-04T15:16:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
