# \_grokparsefailure as soon as space in field

**URL:** <https://discuss.elastic.co/t/grokparsefailure-as-soon-as-space-in-field/211711>\
**Category:** Logstash\
**Created:** [December 12, 2019, 6:36pm UTC](https://discuss.elastic.co/t/grokparsefailure-as-soon-as-space-in-field/211711 "2019-12-12T18:36:59Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 12, 2019, 11:26pm UTC](https://discuss.elastic.co/t/grokparsefailure-as-soon-as-space-in-field/211711/2 "2019-12-12T23:26:32Z")

</div>

The first pattern does not work because inside square brackets period does not mean "any character", it means a literal period. The other two work for me. For example,

```
input { generator { count => 1 lines => ['"foo bar"'] } }
filter {
    grok { match => { "message" => "\"(?<ip2>[\S\s]+)\"" } }
}
output { stdout { codec => rubydebug { metadata => false } } }

```

produces

```
       "ip2" => "foo bar",
   "message" => "\"foo bar\"",
```

---

_[View the full topic](https://discuss.elastic.co/t/grokparsefailure-as-soon-as-space-in-field/211711)._
