# \_grokparsefailure but it works fine in dubugger

**URL:** <https://discuss.elastic.co/t/grokparsefailure-but-it-works-fine-in-dubugger/125233>\
**Category:** Logstash\
**Created:** [March 22, 2018, 4:21pm UTC](https://discuss.elastic.co/t/grokparsefailure-but-it-works-fine-in-dubugger/125233 "2018-03-22T16:21:56Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![miovinelli](https://avatars.discourse-cdn.com/v4/letter/m/8e8cbc/32.png) [@miovinelli](https://discuss.elastic.co/u/miovinelli)\
**Post date:** [March 22, 2018, 4:21pm UTC](https://discuss.elastic.co/t/grokparsefailure-but-it-works-fine-in-dubugger/125233/1 "2018-03-22T16:21:56Z")

</div>

Hi all,  
there is a strange situation cause my pattern works fine in [grokdebug.herokuapp.com](http://grokdebug.herokuapp.com) and also in a debugger offered by X-Pack, but at runtime ingestion events are tagged with "\_grokparsefailure" and I don't understand why. Please can someone help me? Thanks in advance

**pipeline conf:**  
input {  
beats {  
port =\> "5043"  
}  
}  
filter {  
if "WLS-log" in [tags] {  
grok {  
patterns\_dir =\> "./patterns"  
match =\> ["message", "\<%{TIMESTAMP\_ISO8601:timestamp\_log}\>\s-\s%{DATA:element}\s-\s%{DATA:id}\s-\s%{DATA:log\_level}\s\s%{MSG:msglog}?"]

```
}
mutate {
  	add_field => { "Application" => "WLS-INTRA" }
  	add_field => { "log_type" => "service-log" }
}

```

}  
}

**Pattern:**  
MSG (.|\r|\n|._)_

**Follow 3 lines of our log file:**

\<2018-03-21 14:33:16.717\> - SEU - [rJFIp41ZPB4Oc0T0dxkGAjj0Eza2Z4SVW46HEMkaKxuEgpDc6fwr!-172047753!1521637363033] - INFO it.gse.seu.web.task.TasksBean - creating task filters for intranet user: a852197seu  
\<2018-03-21 14:33:33.056\> - SEU - [y\_FIw8fl31L85jubyIyZLRASen-7ja\_9GjM7C-th61F-YrJwxaoS!-172047753!1521639213029] - INFO i.g.s.w.a.IntranetAuthenticationFilter - user: Mariachiara is logged in  
LdapUser {  
userId=a852514,  
name=Mariachiara,  
surname=Cusano,  
email=mariachiara.cusano@gse.it,  
officeName=Sistemi di Produzione e Consumo,  
roles=[TL\_INT, ASSIGNER]  
}  
\<2018-03-21 14:33:33.171\> - SEU - [y\_FIw8fl31L85jubyIyZLRASen-7ja\_9GjM7C-th61F-YrJwxaoS!-172047753!1521639213029] - INFO it.gse.seu.web.task.TasksBean - creating task filters for intranet user: a852514

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 22, 2018, 4:39pm UTC](https://discuss.elastic.co/t/grokparsefailure-but-it-works-fine-in-dubugger/125233/2 "2018-03-22T16:39:00Z")

</div>

I cannot speak to why grok is not working, but I would do that using dissect.

```auto
dissect { mapping => { "message" => "<%{ts} %{+ts}> - %{element} - %{id} - %{log_level} %{msglog} " } }

```

---

<div class="post-metadata">

**Author:** ![vitich](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitich/32/65611_2.png) [@vitich](https://discuss.elastic.co/u/vitich)\
**Post date:** [March 22, 2018, 4:53pm UTC](https://discuss.elastic.co/t/grokparsefailure-but-it-works-fine-in-dubugger/125233/3 "2018-03-22T16:53:39Z")

</div>

Had the same problem...  
Try `patterns_dir => "./patterns/YOUR_FILE_WITH_PATTERNS"` instead.  
Worked for me.

---

<div class="post-metadata">

**Author:** ![miovinelli](https://avatars.discourse-cdn.com/v4/letter/m/8e8cbc/32.png) [@miovinelli](https://discuss.elastic.co/u/miovinelli)\
**Post date:** [March 23, 2018, 8:32am UTC](https://discuss.elastic.co/t/grokparsefailure-but-it-works-fine-in-dubugger/125233/4 "2018-03-23T08:32:37Z")

</div>

Thanks but result is the same...\_grokparsefailure

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 23, 2018, 8:42am UTC](https://discuss.elastic.co/t/grokparsefailure-but-it-works-fine-in-dubugger/125233/5 "2018-03-23T08:42:37Z")

</div>

> [@miovinelli](#):
>
> \s\s%{MSG:msglog}

Are you sure you always have exactly 2 spaces ahead of `%{MSG:msglog}` ?

---

<div class="post-metadata">

**Author:** ![miovinelli](https://avatars.discourse-cdn.com/v4/letter/m/8e8cbc/32.png) [@miovinelli](https://discuss.elastic.co/u/miovinelli)\
**Post date:** [March 23, 2018, 8:57am UTC](https://discuss.elastic.co/t/grokparsefailure-but-it-works-fine-in-dubugger/125233/6 "2018-03-23T08:57:58Z")

</div>

> [@Christian\_Dahlqvist](#):
>
> sure you always

Thanks but result is the same. \_grokparsefailure

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 23, 2018, 9:01am UTC](https://discuss.elastic.co/t/grokparsefailure-but-it-works-fine-in-dubugger/125233/7 "2018-03-23T09:01:18Z")

</div>

I would recommend configuring a `stdout` output plugin with a `rubydebug` codec to troubleshoot this. It would probably help if you could show us the exact result for your 3 example events. make sure you format the data correctly using the UI tools.

---

<div class="post-metadata">

**Author:** ![vitich](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vitich/32/65611_2.png) [@vitich](https://discuss.elastic.co/u/vitich)\
**Post date:** [March 23, 2018, 9:22am UTC](https://discuss.elastic.co/t/grokparsefailure-but-it-works-fine-in-dubugger/125233/8 "2018-03-23T09:22:27Z")

</div>

Did you check the pattern on these sites?

[http://grokconstructor.appspot.com/do/match#result](http://grokconstructor.appspot.com/do/match#result)  
[https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/)

---

<div class="post-metadata">

**Author:** ![miovinelli](https://avatars.discourse-cdn.com/v4/letter/m/8e8cbc/32.png) [@miovinelli](https://discuss.elastic.co/u/miovinelli)\
**Post date:** [March 23, 2018, 11:37am UTC](https://discuss.elastic.co/t/grokparsefailure-but-it-works-fine-in-dubugger/125233/9 "2018-03-23T11:37:41Z")

</div>

Stdout doesn't help us with more info.....

{  
"log\_level" =\> "INFO",  
"id" =\> "[y\_FIw8fl31L85jubyIyZLRASen-7ja\_9GjM7C-th61F-YrJwxaoS!-172047753!1521639213029]",  
"Application" =\> "WLS-INTRA",  
"timestamp\_log" =\> "2018-03-21 14:33:33.056",  
"message" =\> "\<2018-03-21 14:33:33.056\> - SEU - [y\_FIw8fl31L85jubyIyZLRASen-7ja\_9GjM7C-th61F-YrJwxaoS!-172047753!1521639213029] - INFO i.g.s.w.a.IntranetAuthenticationFilter - user: Mariachiara is logged in",  
"@version" =\> "1",  
"offset" =\> 400,  
"host" =\> "MacBookPro.local",  
"msglog" =\> " i.g.s.w.a.IntranetAuthenticationFilter - user: Mariachiara is logged in",  
"log\_type" =\> "service-log",  
"@timestamp" =\> 2018-03-23T11:01:24.388Z,  
"tags" =\> [  
[0] "WLS-log",  
[1] "beats\_input\_codec\_plain\_applied"  
],  
"prospector" =\> {  
"type" =\> "log"  
},  
"element" =\> "SEU",  
"beat" =\> {  
"hostname" =\> "MacBookPro.local",  
"version" =\> "6.2.2",  
"name" =\> "MacBookPro.local"  
},  
"source" =\> "/Users/kp/Progetti/GSE/input da Cliente/seu.log"  
}  
{  
"source" =\> "/Users/kp/Progetti/GSE/input da Cliente/seu.log",  
"message" =\> " LdapUser {",  
"@version" =\> "1",  
"offset" =\> 412,  
"host" =\> "MacBookPro.local",  
"log\_type" =\> "service-log",  
"@timestamp" =\> 2018-03-23T11:01:24.388Z,  
"tags" =\> [  
[0] "WLS-log",  
[1] "beats\_input\_codec\_plain\_applied",  
[2] "\_grokparsefailure"  
],  
"prospector" =\> {  
"type" =\> "log"  
},  
"beat" =\> {  
"version" =\> "6.2.2",  
"hostname" =\> "MacBookPro.local",  
"name" =\> "MacBookPro.local"  
},  
"Application" =\> "WLS-INTRA"  
}

---

<div class="post-metadata">

**Author:** ![miovinelli](https://avatars.discourse-cdn.com/v4/letter/m/8e8cbc/32.png) [@miovinelli](https://discuss.elastic.co/u/miovinelli)\
**Post date:** [March 23, 2018, 11:42am UTC](https://discuss.elastic.co/t/grokparsefailure-but-it-works-fine-in-dubugger/125233/10 "2018-03-23T11:42:21Z")

</div>

Pattern works fine with [https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/) but not with [http://grokconstructor.appspot.com/do/match#result](http://grokconstructor.appspot.com/do/match#result). Below there is a part of the output

MATCHED  
element SEU  
log\_level INFO  
msglog ·i.g.s.w.a.IntranetAuthenticationFilter·-·user:·Mariachiara·is·logged·in  
id [y\_FIw8fl31L85jubyIyZLRASen-7ja\_9GjM7C-th61F-YrJwxaoS!-172047753!1521639213029]  
timestamp\_log 2018-03-21·14:33:33.056  
LdapUser {  
NOT MATCHED. The longest regex prefix matching the beginning of this line is as follows:

prefix   
after match: LdapUser {  
userId=a852514,

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 23, 2018, 11:48am UTC](https://discuss.elastic.co/t/grokparsefailure-but-it-works-fine-in-dubugger/125233/11 "2018-03-23T11:48:53Z")

</div>

> [@miovinelli](#):
>
> {  
> "log\_level" =\> "INFO",  
> "id" =\> "[y\_FIw8fl31L85jubyIyZLRASen-7ja\_9GjM7C-th61F-YrJwxaoS!-172047753!1521639213029]",  
> "Application" =\> "WLS-INTRA",  
> "timestamp\_log" =\> "2018-03-21 14:33:33.056",  
> "message" =\> "\<2018-03-21 14:33:33.056\> - SEU - [y\_FIw8fl31L85jubyIyZLRASen-7ja\_9GjM7C-th61F-YrJwxaoS!-172047753!1521639213029] - INFO i.g.s.w.a.IntranetAuthenticationFilter - user: Mariachiara is logged in",  
> "@version" =\> "1",  
> "offset" =\> 400,  
> "host" =\> "MacBookPro.local",  
> "msglog" =\> " i.g.s.w.a.IntranetAuthenticationFilter - user: Mariachiara is logged in",  
> "log\_type" =\> "service-log",  
> "@timestamp" =\> 2018-03-23T11:01:24.388Z,  
> "tags" =\> [  
> [0] "WLS-log",  
> [1] "beats\_input\_codec\_plain\_applied"  
> ],  
> "prospector" =\> {  
> "type" =\> "log"  
> },

This event seem to parse fine.

> [@miovinelli](#):
>
> {  
> "source" =\> "/Users/kp/Progetti/GSE/input da Cliente/seu.log",  
> "message" =\> " LdapUser {",  
> "@version" =\> "1",  
> "offset" =\> 412,  
> "host" =\> "MacBookPro.local",  
> "log\_type" =\> "service-log",  
> "@timestamp" =\> 2018-03-23T11:01:24.388Z,  
> "tags" =\> [  
> [0] "WLS-log",  
> [1] "beats\_input\_codec\_plain\_applied",  
> [2] "\_grokparsefailure"  
> ],  
> "prospector" =\> {  
> "type" =\> "log"  
> },

When one looks at this event it however looks like you are not handling the multiline event correctly, which is why grok fails.

---

<div class="post-metadata">

**Author:** ![miovinelli](https://avatars.discourse-cdn.com/v4/letter/m/8e8cbc/32.png) [@miovinelli](https://discuss.elastic.co/u/miovinelli)\
**Post date:** [March 23, 2018, 2:11pm UTC](https://discuss.elastic.co/t/grokparsefailure-but-it-works-fine-in-dubugger/125233/12 "2018-03-23T14:11:07Z")

</div>

Yes is true, it's multiline case, but should be allow cause my extra pattern MSG is defined like:

MSG (.|\r|\n|\t|\s|\f|\v|\x20|\N)\*

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 23, 2018, 2:13pm UTC](https://discuss.elastic.co/t/grokparsefailure-but-it-works-fine-in-dubugger/125233/13 "2018-03-23T14:13:09Z")

</div>

If you do not have multiline processing configured correctly in Filebeat, each line will come in as a separate event (which seems to be the case based on the output you provided), in which case it grok will never see the full event.

---

<div class="post-metadata">

**Author:** ![miovinelli](https://avatars.discourse-cdn.com/v4/letter/m/8e8cbc/32.png) [@miovinelli](https://discuss.elastic.co/u/miovinelli)\
**Post date:** [March 23, 2018, 2:32pm UTC](https://discuss.elastic.co/t/grokparsefailure-but-it-works-fine-in-dubugger/125233/14 "2018-03-23T14:32:01Z")

</div>

Right clue! I add these new lines to filebeat.yml

multiline.pattern: '^\<'  
multiline.negate: true  
multiline.match: after

but still the same....

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 23, 2018, 2:38pm UTC](https://discuss.elastic.co/t/grokparsefailure-but-it-works-fine-in-dubugger/125233/15 "2018-03-23T14:38:31Z")

</div>

> [@miovinelli](#):
>
> but still the same....

That looks correct. Are the lines now merged into full events? Can you show us the output?

---

<div class="post-metadata">

**Author:** ![miovinelli](https://avatars.discourse-cdn.com/v4/letter/m/8e8cbc/32.png) [@miovinelli](https://discuss.elastic.co/u/miovinelli)\
**Post date:** [March 23, 2018, 2:44pm UTC](https://discuss.elastic.co/t/grokparsefailure-but-it-works-fine-in-dubugger/125233/16 "2018-03-23T14:44:23Z")

</div>

{  
"host" =\> "MacBookPro.local",  
"offset" =\> 206,  
"beat" =\> {  
"name" =\> "MacBookPro.local",  
"hostname" =\> "MacBookPro.local",  
"version" =\> "6.2.2"  
},  
"message" =\> " LdapUser {",  
"@timestamp" =\> 2018-03-23T14:43:27.991Z,  
"tags" =\> [  
[0] "WLS-log",  
[1] "beats\_input\_codec\_plain\_applied",  
[2] "\_grokparsefailure"  
],  
"prospector" =\> {  
"type" =\> "log"  
},  
"Application" =\> "WLS-INTRA",  
"source" =\> "/Users/kp/Progetti/GSE/input da Cliente/seu.log",  
"@version" =\> "1",  
"log\_type" =\> "service-log"  
}  
{  
"host" =\> "MacBookPro.local",  
"offset" =\> 297,  
"beat" =\> {  
"name" =\> "MacBookPro.local",  
"hostname" =\> "MacBookPro.local",  
"version" =\> "6.2.2"  
},  
"message" =\> "\temail=mariachiara.cusano@gse.it, ",  
"@timestamp" =\> 2018-03-23T14:43:27.991Z,  
"tags" =\> [  
[0] "WLS-log",  
[1] "beats\_input\_codec\_plain\_applied",  
[2] "\_grokparsefailure"  
],  
"prospector" =\> {  
"type" =\> "log"  
},  
"Application" =\> "WLS-INTRA",  
"source" =\> "/Users/kp/Progetti/GSE/input da Cliente/seu.log",  
"@version" =\> "1",  
"log\_type" =\> "service-log"  
}  
{  
"host" =\> "MacBookPro.local",  
"offset" =\> 244,  
"beat" =\> {  
"name" =\> "MacBookPro.local",  
"hostname" =\> "MacBookPro.local",  
"version" =\> "6.2.2"  
},  
"message" =\> "\tname=Mariachiara, ",  
"@timestamp" =\> 2018-03-23T14:43:27.991Z,  
"tags" =\> [  
[0] "WLS-log",  
[1] "beats\_input\_codec\_plain\_applied",  
[2] "\_grokparsefailure"  
],  
"prospector" =\> {  
"type" =\> "log"  
},  
"Application" =\> "WLS-INTRA",  
"source" =\> "/Users/kp/Progetti/GSE/input da Cliente/seu.log",  
"@version" =\> "1",  
"log\_type" =\> "service-log"  
}  
{  
"host" =\> "MacBookPro.local",  
"offset" =\> 369,  
"beat" =\> {  
"name" =\> "MacBookPro.local",  
"hostname" =\> "MacBookPro.local",  
"version" =\> "6.2.2"  
},  
"message" =\> "\troles=[TL\_INT, ASSIGNER]",  
"@timestamp" =\> 2018-03-23T14:43:27.991Z,  
"tags" =\> [  
[0] "WLS-log",  
[1] "beats\_input\_codec\_plain\_applied",  
[2] "\_grokparsefailure"  
],  
"prospector" =\> {  
"type" =\> "log"  
},  
"Application" =\> "WLS-INTRA",  
"source" =\> "/Users/kp/Progetti/GSE/input da Cliente/seu.log",  
"@version" =\> "1",  
"log\_type" =\> "service-log"  
}  
{  
"host" =\> "MacBookPro.local",  
"log\_level" =\> "INFO",  
"offset" =\> 194,  
"beat" =\> {  
"name" =\> "MacBookPro.local",  
"hostname" =\> "MacBookPro.local",  
"version" =\> "6.2.2"  
},  
"id" =\> "[y\_FIw8fl31L85jubyIyZLRASen-7ja\_9GjM7C-th61F-YrJwxaoS!-172047753!1521639213029]",  
"message" =\> "\<2018-03-21 14:33:33.056\> - SEU - [y\_FIw8fl31L85jubyIyZLRASen-7ja\_9GjM7C-th61F-YrJwxaoS!-172047753!1521639213029] - INFO i.g.s.w.a.IntranetAuthenticationFilter - user: Mariachiara is logged in",  
"@timestamp" =\> 2018-03-23T14:43:27.991Z,  
"tags" =\> [  
[0] "WLS-log",  
[1] "beats\_input\_codec\_plain\_applied"  
],  
"prospector" =\> {  
"type" =\> "log"  
},  
"Application" =\> "WLS-INTRA",  
"source" =\> "/Users/kp/Progetti/GSE/input da Cliente/seu.log",  
"@version" =\> "1",  
"log\_type" =\> "service-log",  
"element" =\> "SEU",  
"timestamp\_log" =\> "2018-03-21 14:33:33.056",  
"msglog" =\> " i.g.s.w.a.IntranetAuthenticationFilter - user: Mariachiara is logged in"  
}  
{  
"host" =\> "MacBookPro.local",  
"offset" =\> 262,  
"beat" =\> {  
"name" =\> "MacBookPro.local",  
"hostname" =\> "MacBookPro.local",  
"version" =\> "6.2.2"  
},  
"message" =\> "\tsurname=Cusano, ",  
"@timestamp" =\> 2018-03-23T14:43:27.991Z,  
"tags" =\> [  
[0] "WLS-log",  
[1] "beats\_input\_codec\_plain\_applied",  
[2] "\_grokparsefailure"  
],  
"prospector" =\> {  
"type" =\> "log"  
},  
"Application" =\> "WLS-INTRA",  
"source" =\> "/Users/kp/Progetti/GSE/input da Cliente/seu.log",  
"@version" =\> "1",  
"log\_type" =\> "service-log"  
}  
{  
"host" =\> "MacBookPro.local",  
"offset" =\> 224,  
"beat" =\> {  
"name" =\> "MacBookPro.local",  
"hostname" =\> "MacBookPro.local",  
"version" =\> "6.2.2"  
},  
"message" =\> "\tuserId=a852514, ",  
"@timestamp" =\> 2018-03-23T14:43:27.991Z,  
"prospector" =\> {  
"type" =\> "log"  
},  
"tags" =\> [  
[0] "WLS-log",  
[1] "beats\_input\_codec\_plain\_applied",  
[2] "\_grokparsefailure"  
],  
"Application" =\> "WLS-INTRA",  
"source" =\> "/Users/kp/Progetti/GSE/input da Cliente/seu.log",  
"@version" =\> "1",  
"log\_type" =\> "service-log"  
}  
{  
"host" =\> "MacBookPro.local",  
"offset" =\> 343,  
"beat" =\> {  
"name" =\> "MacBookPro.local",  
"hostname" =\> "MacBookPro.local",  
"version" =\> "6.2.2"  
},  
"message" =\> "\tofficeName=Sistemi di Produzione e Consumo, ",  
"@timestamp" =\> 2018-03-23T14:43:27.991Z,  
"tags" =\> [  
[0] "WLS-log",  
[1] "beats\_input\_codec\_plain\_applied",  
[2] "\_grokparsefailure"  
],  
"prospector" =\> {  
"type" =\> "log"  
},  
"Application" =\> "WLS-INTRA",  
"source" =\> "/Users/kp/Progetti/GSE/input da Cliente/seu.log",  
"@version" =\> "1",  
"log\_type" =\> "service-log"  
}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 23, 2018, 2:46pm UTC](https://discuss.elastic.co/t/grokparsefailure-but-it-works-fine-in-dubugger/125233/17 "2018-03-23T14:46:21Z")

</div>

> [@miovinelli](#):
>
> "message" =\> " LdapUser {",

It does not look like your multiline config is working.

---

<div class="post-metadata">

**Author:** ![miovinelli](https://avatars.discourse-cdn.com/v4/letter/m/8e8cbc/32.png) [@miovinelli](https://discuss.elastic.co/u/miovinelli)\
**Post date:** [March 23, 2018, 2:47pm UTC](https://discuss.elastic.co/t/grokparsefailure-but-it-works-fine-in-dubugger/125233/18 "2018-03-23T14:47:28Z")

</div>

filebeat.yml is:

```auto
filebeat.prospectors:

####### OHS INTRA LOG #######
- type: log
  tags: ["OHS-INTRA-access-log"]
  paths:
    - /Users/kp/Progetti/GSE/input da Cliente/*access*log
    
    
####### WLS LOG #######
- type: log
  tags: ["WLS-log"]
  paths:
    - /Users/kp/Progetti/GSE/input da Cliente/seu*.log
    
####### OAM LOG #######
- type: log
  tags: ["OAM-log"]
  paths:
    - /Users/kp/Progetti/GSE/input da Cliente/*diagnostic.log

multiline.pattern: '^\<'
multiline.negate: true
multiline.match: after

output.logstash:
  hosts: ["localhost:5043"]

```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 23, 2018, 2:49pm UTC](https://discuss.elastic.co/t/grokparsefailure-but-it-works-fine-in-dubugger/125233/19 "2018-03-23T14:49:13Z")

</div>

Please format that correctly as yml files are sensitive to indentation. I believe the multiline config should be under each prospector it applies to, which does not necessarily seem to be the case here.

---

<div class="post-metadata">

**Author:** ![miovinelli](https://avatars.discourse-cdn.com/v4/letter/m/8e8cbc/32.png) [@miovinelli](https://discuss.elastic.co/u/miovinelli)\
**Post date:** [March 23, 2018, 2:53pm UTC](https://discuss.elastic.co/t/grokparsefailure-but-it-works-fine-in-dubugger/125233/20 "2018-03-23T14:53:19Z")

</div>

Works fine with this configuration:

filebeat.prospectors:

####### OHS INTRA LOG #######

- type: log  
tags: ["OHS-INTRA-access-log"]  
paths:
  - /Users/kp/Progetti/GSE/input da Cliente/_access_log

####### WLS LOG #######

- type: log  
tags: ["WLS-log"]  
paths:

####### OAM LOG #######

- type: log  
tags: ["OAM-log"]  
paths:
  - /Users/kp/Progetti/GSE/input da Cliente/\*diagnostic.log

output.logstash:  
hosts: ["localhost:5043"]

Thank you so much for your help. Really appreciate! Thanks again

[Next page](https://discuss.elastic.co/t/grokparsefailure-but-it-works-fine-in-dubugger/125233.md?page=2)
