# How do you analyze logstash grok parsing for errors?

**URL:** <https://discuss.elastic.co/t/how-do-you-analyze-logstash-grok-parsing-for-errors/197298>\
**Category:** Logstash\
**Created:** [August 29, 2019, 9:10am UTC](https://discuss.elastic.co/t/how-do-you-analyze-logstash-grok-parsing-for-errors/197298 "2019-08-29T09:10:36Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![wajika](https://avatars.discourse-cdn.com/v4/letter/w/977dab/32.png) [@wajika](https://discuss.elastic.co/u/wajika)\
**Post date:** [August 29, 2019, 9:10am UTC](https://discuss.elastic.co/t/how-do-you-analyze-logstash-grok-parsing-for-errors/197298/1 "2019-08-29T09:10:36Z")

</div>

I want to get systemname and typelog in the path

sample：  
/usr/local/xxx-springboot/logs/xxx/operator.log

Correct result  
systemname =\> xxx  
typelog =\> operator

![grok2](https://us1.discourse-cdn.com/elastic/original/3X/3/5/35746e37d6bcf126945cafe1f23707846be3085d.png)

filter {  
grok {  
match =\> {  
"source" =\> "/%{WORD}/%{WORD}/%{GREEDYDATA}/%{WORD}/%{WORD:servicename}/%{WORD:typelog}"  
}  
}  
}

output{  
elasticsearch{  
hosts =\> ["10.81.176.31","10.27.69.118"]  
index =\> "%{[servicename]}-%{+YYYY.MM.dd}"  
}

 ![grok](https://us1.discourse-cdn.com/elastic/original/3X/2/4/24bca970ba9f377c05b72e516e9859dbcc550634.png)

But it failed to parse, i can't find the wrong place

---

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [August 29, 2019, 11:03am UTC](https://discuss.elastic.co/t/how-do-you-analyze-logstash-grok-parsing-for-errors/197298/2 "2019-08-29T11:03:52Z")

</div>

Hi,

I assume that your path structure always looks like this:

`/usr/local/<SYSTEMNAME>-springboot/logs/<SYSTEMNAME>/<LOGTYPE>.log`

Then I would parse it like this:

grok pattern:

```
^/usr/local/%{NOT_DASH:systemname}-springboot/logs/%{GREEDYDATA:typelog}.log

```

And you need to add this custom pattern:  
`NOT_DASH [^\-]+`

![image](https://us1.discourse-cdn.com/elastic/original/3X/3/6/36a8f478bd898d2b11181b9245ec6908f4adf0bd.png)

Regards, Andreas

---

<div class="post-metadata">

**Author:** ![wajika](https://avatars.discourse-cdn.com/v4/letter/w/977dab/32.png) [@wajika](https://discuss.elastic.co/u/wajika)\
**Post date:** [August 30, 2019, 1:33am UTC](https://discuss.elastic.co/t/how-do-you-analyze-logstash-grok-parsing-for-errors/197298/3 "2019-08-30T01:33:03Z")

</div>

> [@wajika](#):
>
> %{GREEDYDATA}

Thanks for your advice. I found the cause of the problem.I need to use as little %{WORD} as possible.  
The %{WORD} used earlier may have mapped to the latter

---

<div class="post-metadata">

**Author:** ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)\
**Post date:** [August 30, 2019, 6:35am UTC](https://discuss.elastic.co/t/how-do-you-analyze-logstash-grok-parsing-for-errors/197298/4 "2019-08-30T06:35:11Z")

</div>

But be careful with greedydata. It is an eqivalent vor \* in underlying regex. If you have very long fields like stacktraces and you want to search something with greedydata, it may happen that logstash needs to parse the whole file and may fail at the end because it finds no match.  
For all regex / grok try to set anchors like ^ or $ or static text if possible. Make it fail as fast as possible.

If you want to tune regex I can recommend [regex101.com](http://regex101.com). It shows the number of steps needed. So you can find out wrong usage of greedydata (\*) easily. But you have to convert grok to regex, which syntax is a bit different on defining the variables / regex groups.

I always try to to use greedydata as few as possible and rather use patterns like NOT\_DASH to have anything until the given character.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 27, 2019, 6:35am UTC](https://discuss.elastic.co/t/how-do-you-analyze-logstash-grok-parsing-for-errors/197298/5 "2019-09-27T06:35:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
