# Ingest grok not behaving as expected

**URL:** <https://discuss.elastic.co/t/ingest-grok-not-behaving-as-expected/65244>\
**Category:** Elasticsearch\
**Created:** [November 7, 2016, 3:57pm UTC](https://discuss.elastic.co/t/ingest-grok-not-behaving-as-expected/65244 "2016-11-07T15:57:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nezzerscape](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@Nezzerscape](https://discuss.elastic.co/u/Nezzerscape)\
**Post date:** [November 7, 2016, 3:57pm UTC](https://discuss.elastic.co/t/ingest-grok-not-behaving-as-expected/65244/1 "2016-11-07T15:57:19Z")

</div>

I am trying to parse a FQDN from winlogbeat. A normal (logstash) grok pattern would be:

"%{DATA:Host}.%{GREEDYDATA:Domain}"

But this errors out when uploading:

PUT \_ingest/pipeline/HOST  
{  
"description" : "Convert computer name",  
"processors" : [  
{  
"grok": {  
"field": "computer\_name",  
"patterns": ["%{DATA:Host}.%{GREEDYDATA:Domain}"]  
}  
}  
]  
}

Leads to:  
{  
"error": {  
"root\_cause": [  
{  
"type": "parse\_exception",  
"reason": "Failed to parse content to map"  
}  
],  
"type": "parse\_exception",  
"reason": "Failed to parse content to map",  
"caused\_by": {  
"type": "json\_parse\_exception",  
"reason": "Unrecognized character escape '.' (code 46)\n at [Source: org.elasticsearch.transport.netty4.ByteBufStreamInput@7fd41e9; line: 7, column: 38]"  
}  
},  
"status": 400  
}

Note I am using 5.0 of everything.

---

<div class="post-metadata">

**Author:** ![Nezzerscape](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@Nezzerscape](https://discuss.elastic.co/u/Nezzerscape)\
**Post date:** [November 7, 2016, 4:01pm UTC](https://discuss.elastic.co/t/ingest-grok-not-behaving-as-expected/65244/2 "2016-11-07T16:01:05Z")

</div>

I can get around the error with:  
"patterns": [ "%{DATA:Host}'.'%{GREEDYDATA:Domain}"  
but the results is the fqdn going into Domain and nothing in Host.

Parsing "[myhost.my.domain.com](http://myhost.my.domain.com)" should be:  
Host =\> "myhost"  
Domina =\> "[my.domain.com](http://my.domain.com)"

---

<div class="post-metadata">

**Author:** ![Nezzerscape](https://avatars.discourse-cdn.com/v4/letter/n/d78d45/32.png) [@Nezzerscape](https://discuss.elastic.co/u/Nezzerscape)\
**Post date:** [November 7, 2016, 4:22pm UTC](https://discuss.elastic.co/t/ingest-grok-not-behaving-as-expected/65244/3 "2016-11-07T16:22:12Z")

</div>

SO with even more playing the following gave me the results I was looking for:  
"patterns": ["%{DATA:Host}[.]%{GREEDYDATA:Domain}" ]

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 5, 2016, 4:22pm UTC](https://discuss.elastic.co/t/ingest-grok-not-behaving-as-expected/65244/4 "2016-12-05T16:22:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
