# Grokparsefailure with a pattern verified by grok debug

**URL:** <https://discuss.elastic.co/t/grokparsefailure-with-a-pattern-verified-by-grok-debug/98251>\
**Category:** Logstash\
**Created:** [August 24, 2017, 2:35pm UTC](https://discuss.elastic.co/t/grokparsefailure-with-a-pattern-verified-by-grok-debug/98251 "2017-08-24T14:35:09Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mehdi\_Mouslih](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehdi_mouslih/32/21344_2.png) [@Mehdi\_Mouslih](https://discuss.elastic.co/u/Mehdi_Mouslih)\
**Post date:** [August 24, 2017, 2:35pm UTC](https://discuss.elastic.co/t/grokparsefailure-with-a-pattern-verified-by-grok-debug/98251/1 "2017-08-24T14:35:09Z")

</div>

Hello i am using logstash to collect cisco logs like the following one 🙂  
2017-08-23T11:03:43.068Z 192.168.1.254 \<189\>79: \*Mar 1 01:17:53.151: %SYS-5-CONFIG\_I: Configured from console by console

this is my logstash configuration file:

input {  
udp {  
port =\> "8514"  
#type =\> "syslog-cisco"  
}

tcp {  
port =\> "8514"  
#type =\> "syslog-cisco"  
}  
}

filter {  
grok {

```
             match => {
                        "message" => "%{TIMESTAMP_ISO8601:syslog_ng_timestamp} %{IP:original_log_host} (?<seq_no><\d*>\d*): \*(?<C_timestamp>\b\w*\b \d* \d*:\d*:\d*.\d*): %(?<facility>\b\w*\b)-(?<severity>\d)-%{GREEDYDATA:MNEMONIC}:%{GREEDYDATA:message}"
                      }

     } #grok

```

}  
output {  
stdout{  
codec =\> "rubydebug"  
}  
}

* * *

the problem despite the positive response of grokdebug i have always grokparsefailure, i tried trying one pattern at the time to see whats wrong but it didn't work:

 ![1](https://us1.discourse-cdn.com/elastic/original/3X/f/1/f1fb3d4cc00e11e76d80492697109177e460f189.PNG)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 24, 2017, 8:16pm UTC](https://discuss.elastic.co/t/grokparsefailure-with-a-pattern-verified-by-grok-debug/98251/2 "2017-08-24T20:16:28Z")

</div>

Show the output from `stdout{ codec => "rubydebug" }`.

---

<div class="post-metadata">

**Author:** ![Mehdi\_Mouslih](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehdi_mouslih/32/21344_2.png) [@Mehdi\_Mouslih](https://discuss.elastic.co/u/Mehdi_Mouslih)\
**Post date:** [August 25, 2017, 7:47am UTC](https://discuss.elastic.co/t/grokparsefailure-with-a-pattern-verified-by-grok-debug/98251/3 "2017-08-25T07:47:54Z")

</div>

this is the output i get :  
 ![2](https://us1.discourse-cdn.com/elastic/original/3X/d/a/da82c3a6b352667856b503cd5bb422a9d383cd64.PNG)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 25, 2017, 7:53am UTC](https://discuss.elastic.co/t/grokparsefailure-with-a-pattern-verified-by-grok-debug/98251/4 "2017-08-25T07:53:44Z")

</div>

And does that message match this grok expression?

```
%{TIMESTAMP_ISO8601:syslog_ng_timestamp} %{IP:original_log_host} (?<seq_no><\d*>\d*): \*(?<C_timestamp>\b\w*\b \d* \d*:\d*:\d*.\d*): %(?<facility>\b\w*\b)-(?<severity>\d)-%{GREEDYDATA:MNEMONIC}:%{GREEDYDATA:message}
```

---

<div class="post-metadata">

**Author:** ![Mehdi\_Mouslih](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehdi_mouslih/32/21344_2.png) [@Mehdi\_Mouslih](https://discuss.elastic.co/u/Mehdi_Mouslih)\
**Post date:** [August 25, 2017, 8:10am UTC](https://discuss.elastic.co/t/grokparsefailure-with-a-pattern-verified-by-grok-debug/98251/5 "2017-08-25T08:10:01Z")

</div>

the pattern matches the syslog message but the output does not match at all the semantics .  
i deleted %{TIMESTAMP\_ISO8601:syslog\_ng\_timestamp} and the pattern worked but i have an overlap in the message field and there are some other field that took different names :  
original\_log\_host became host  
syslog\_ng\_timestamp became @timestamp

the following image shows the complete output with out %{TIMESTAMP\_ISO8601:syslog\_ng\_timestamp} :

 ![3](https://us1.discourse-cdn.com/elastic/original/3X/c/4/c4d1e23b9cbf8e0e44ccef426e3f4fff117b8f77.PNG)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 25, 2017, 8:44am UTC](https://discuss.elastic.co/t/grokparsefailure-with-a-pattern-verified-by-grok-debug/98251/6 "2017-08-25T08:44:46Z")

</div>

Show your complete configuration. Post it as text. Do not post screenshots.

> but i have an overlap in the message field

See the grok filter's `overwrite` option.

---

<div class="post-metadata">

**Author:** ![Mehdi\_Mouslih](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehdi_mouslih/32/21344_2.png) [@Mehdi\_Mouslih](https://discuss.elastic.co/u/Mehdi_Mouslih)\
**Post date:** [August 25, 2017, 8:54am UTC](https://discuss.elastic.co/t/grokparsefailure-with-a-pattern-verified-by-grok-debug/98251/7 "2017-08-25T08:54:39Z")

</div>

this is it :

# 

# INPUT - Logstash listens on port 8514 for these logs.

# 

input {

udp {

```
port => "8514"

#type => "syslog-cisco"

```

}

tcp {

```
port => "8514"

#type => "syslog-cisco"

```

}

}

filter {

```
grok {

	

	 match => { 

	    "message" => "%{TIMESTAMP_ISO8601:syslog_ng_timestamp} %{IP:original_log_host} (?<seq_no><\d*>\d*): \*(?<C_timestamp>\b\w*\b \d* \d*:\d*:\d*\.\d*): %(?<facility>\b\w*\b)-(?<severity>\d)-%{GREEDYDATA:MNEMONIC}:%{GREEDYDATA:message}"

	     overwrite => ["message"]

		  }

 } #grok

```

}

output {

```
stdout{

	codec => "rubydebug"

}

```

}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 25, 2017, 9:22am UTC](https://discuss.elastic.co/t/grokparsefailure-with-a-pattern-verified-by-grok-debug/98251/8 "2017-08-25T09:22:26Z")

</div>

> ```
> "message" => "%{TIMESTAMP_ISO8601:syslog_ng_timestamp} %{IP:original_log_host} (?<seq_no><\d*>\d*): \*(?<C_timestamp>\b\w*\b \d* \d*:\d*:\d*\.\d*): %(?<facility>\b\w*\b)-(?<severity>\d)-%{GREEDYDATA:MNEMONIC}:%{GREEDYDATA:message}"
> 
> ```

But this is the expression that is known to not match?

---

<div class="post-metadata">

**Author:** ![Mehdi\_Mouslih](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mehdi_mouslih/32/21344_2.png) [@Mehdi\_Mouslih](https://discuss.elastic.co/u/Mehdi_Mouslih)\
**Post date:** [August 25, 2017, 9:27am UTC](https://discuss.elastic.co/t/grokparsefailure-with-a-pattern-verified-by-grok-debug/98251/9 "2017-08-25T09:27:53Z")

</div>

it works well on GROKDebug , did you see some mistakes in it ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 25, 2017, 10:02am UTC](https://discuss.elastic.co/t/grokparsefailure-with-a-pattern-verified-by-grok-debug/98251/10 "2017-08-25T10:02:44Z")

</div>

> it works well on GROKDebug ,

That's irrelevant.

> did you see some mistakes in it ?

We're talking in circles. Good luck.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 22, 2017, 10:02am UTC](https://discuss.elastic.co/t/grokparsefailure-with-a-pattern-verified-by-grok-debug/98251/11 "2017-09-22T10:02:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
