# Help with grok filter on ingest pipeline

**URL:** <https://discuss.elastic.co/t/help-with-grok-filter-on-ingest-pipeline/321568>\
**Category:** Kibana\
**Created:** [December 19, 2022, 2:34pm UTC](https://discuss.elastic.co/t/help-with-grok-filter-on-ingest-pipeline/321568 "2022-12-19T14:34:22Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![RaonyO](https://avatars.discourse-cdn.com/v4/letter/r/5fc32e/32.png) [@RaonyO](https://discuss.elastic.co/u/RaonyO)\
**Post date:** [December 19, 2022, 2:34pm UTC](https://discuss.elastic.co/t/help-with-grok-filter-on-ingest-pipeline/321568/1 "2022-12-19T14:34:22Z")

</div>

Hello, I'm trying to use the following grok filter, but I'm getting a message saying it's in an invalid json format, but I think my filter is written correctly. can you help me with this?  
filter:

```auto
(%{TIMESTAMP_ISO8601:time})%{NOTSPACE} firewall: msg_id=\\"%{DATA:msg_id}\\" %{DATA:action} %{DATA:source} %{DATA:if} %{DATA:number1} %{DATA:protocol} %{DATA:number2} %{DATA:number3} %{IP:srcip} %{IP:destip} %{NUMBER:srcport} %{NUMBER:destport} offset %{NUMBER:number4} %{DATA:word1} %{NUMBER:number5} win %{NUMBER:number6}%{SPACE}signature_name=\\"%{DATA:signature_name}" signature_cat=\\"%{DATA:signature_cat}" signature_id=\\"%{DATA:signature_id}\\" severity=\\"%{NUMBER:severity}\\" sig_vers=\\"%{NUMBER:sig_vers}\\"%{SPACE}geo_src=\\"%{WORD:geo_src}\\"%{SPACE} geo_dst=\\"%{WORD:geo_dst}\\"%{SPACE}msg=\\"%{DATA:msg}\\"%{SPACE}%{GREEDYDATA:msg2}

```

obs: I'm using the ingest pipeline menu in kibana

---

<div class="post-metadata">

**Author:** ![drewdaemon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/drewdaemon/32/97779_2.png) [@drewdaemon](https://discuss.elastic.co/u/drewdaemon)\
**Post date:** [December 20, 2022, 9:44pm UTC](https://discuss.elastic.co/t/help-with-grok-filter-on-ingest-pipeline/321568/2 "2022-12-20T21:44:02Z")

</div>

Your pattern seems to pass validation for me. Did I miss something in your request?

![ezgif.com-gif-maker (3)](https://us1.discourse-cdn.com/elastic/original/3X/1/5/15163b908cc28df0a577504daf75739063aad506.gif)

---

<div class="post-metadata">

**Author:** ![RaonyO](https://avatars.discourse-cdn.com/v4/letter/r/5fc32e/32.png) [@RaonyO](https://discuss.elastic.co/u/RaonyO)\
**Post date:** [December 21, 2022, 2:27pm UTC](https://discuss.elastic.co/t/help-with-grok-filter-on-ingest-pipeline/321568/3 "2022-12-21T14:27:54Z")

</div>

I performed the same test and it didn't pass the validation, anyway I'm using an old version of elk (7.13) could that be the reason for not validating?

---

<div class="post-metadata">

**Author:** ![drewdaemon](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/drewdaemon/32/97779_2.png) [@drewdaemon](https://discuss.elastic.co/u/drewdaemon)\
**Post date:** [January 10, 2023, 2:46pm UTC](https://discuss.elastic.co/t/help-with-grok-filter-on-ingest-pipeline/321568/4 "2023-01-10T14:46:39Z")

</div>

Hmmm, yeah, that's possible. I'm on the latest (8.6).

---

<div class="post-metadata">

**Author:** ![RaonyO](https://avatars.discourse-cdn.com/v4/letter/r/5fc32e/32.png) [@RaonyO](https://discuss.elastic.co/u/RaonyO)\
**Post date:** [January 16, 2023, 8:17pm UTC](https://discuss.elastic.co/t/help-with-grok-filter-on-ingest-pipeline/321568/5 "2023-01-16T20:17:51Z")

</div>

I put the same filter on a newer version and it worked, that's probably it, thanks anyway!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 13, 2023, 8:17pm UTC](https://discuss.elastic.co/t/help-with-grok-filter-on-ingest-pipeline/321568/6 "2023-02-13T20:17:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
