# Ingest Pipeline Dissect Pattern unable to match Append modifiers

**URL:** <https://discuss.elastic.co/t/ingest-pipeline-dissect-pattern-unable-to-match-append-modifiers/342765>\
**Category:** Elasticsearch\
**Tags:** ingest-pipeline\
**Created:** [September 11, 2023, 9:13pm UTC](https://discuss.elastic.co/t/ingest-pipeline-dissect-pattern-unable-to-match-append-modifiers/342765 "2023-09-11T21:13:37Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![paolovalladolid](https://avatars.discourse-cdn.com/v4/letter/p/edb3f5/32.png) [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Post date:** [September 11, 2023, 9:13pm UTC](https://discuss.elastic.co/t/ingest-pipeline-dissect-pattern-unable-to-match-append-modifiers/342765/1 "2023-09-11T21:13:37Z")

</div>

This is is the dissect pattern

```auto
%{+dateStr} %(+dateStr) %{logLevel} %{className} %{httpNio} %{+messageContent} %{+messageContent} %{+messageContent} %{}

```

This is a sample line from the document that the dissect is failing on:

```auto
2023-09-11 20:43:56,987 ERROR c.i.a.c.GlobalExceptionHandler [http-nio-9095-exec-39] exception : No value present for 

```

This is the error message:

```auto
Unable to find match for dissect pattern: %{+dateStr} %(+dateStr) %{logLevel} %{className} %{httpNio} %{+messageContent} %{+messageContent} %{+messageContent} %{} against source: 2023-09-11 20:43:56,987 ERROR c.i.a.c.GlobalExceptionHandler [http-nio-9095-exec-39] exception : No value present for

```

My understanding is that ${messageContent} should have matched and appended "exception : No value present for ". However this is not the case.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 12, 2023, 3:30am UTC](https://discuss.elastic.co/t/ingest-pipeline-dissect-pattern-unable-to-match-append-modifiers/342765/2 "2023-09-12T03:30:36Z")

</div>

Hi @paolovalladolid

You have a couple issues

1. You can not use the same variable name for different fields they will just be overridden
2. you have a typo on the 2nd date string `%(+dateStr)` should be `%{+dateStr2}`
3. You are not accounting for literal characters

Here is my example

```auto
POST _ingest/pipeline/_simulate
{
  "pipeline": {
    "processors": [
      {
        "dissect": {
          "field": "message",
          "pattern": "%{+dateStr} %{+dateStr2} %{logLevel} %{className} [%{httpNio}] %{+messageContent}"
        }
      }
    ]
  },
  "docs": [
    {
      "_source": {
        "message": "2023-09-11 20:43:56,987 ERROR c.i.a.c.GlobalExceptionHandler [http-nio-9095-exec-39] exception : No value present for"
      }
    }
  ]
}

```

Results

```auto
{
  "docs": [
    {
      "doc": {
        "_index": "_index",
        "_id": "_id",
        "_version": "-3",
        "_source": {
          "logLevel": "ERROR",
          "dateStr": "2023-09-11",
          "dateStr2": "20:43:56,987",
          "className": "c.i.a.c.GlobalExceptionHandler",
          "message": "2023-09-11 20:43:56,987 ERROR c.i.a.c.GlobalExceptionHandler [http-nio-9095-exec-39] exception : No value present for",
          "httpNio": "http-nio-9095-exec-39",
          "messageContent": "exception : No value present for"
        },
        "_ingest": {
          "timestamp": "2023-09-12T03:27:33.435670498Z"
        }
      }
    }
  ]
}

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 12, 2023, 3:43am UTC](https://discuss.elastic.co/t/ingest-pipeline-dissect-pattern-unable-to-match-append-modifiers/342765/3 "2023-09-12T03:43:36Z")

</div>

> [@stephenb](#):
>
> - You can not use the same variable name for different fields they will just be overridden
> - you have a typo on the 2nd date string `%(+dateStr)` should be `%{+dateStr2}`

Not exactly, you can use the same variable name if you use the [append modifier](https://www.elastic.co/guide/en/elasticsearch/reference/current/dissect-processor.html#append-modifier), the + sign, as it was used in the pattern.

The issue here was basically the literals not being accounted for.

One thing, that should be added is the `append_separator` config, per default it will be an empty string (in logstash it is a single space).

I think this is close of what the OP wants:

```auto

POST _ingest/pipeline/_simulate
{
  "pipeline": {
    "processors": [
      {
        "dissect": {
          "field": "message",
          "pattern": "%{+dateStr} %{+dateStr} %{logLevel} %{className} [%{httpNio}] %{+messageContent}",
          "append_separator": " "
        }
      }
    ]
  },
  "docs": [
    {
      "_source": {
        "message": "2023-09-11 20:43:56,987 ERROR c.i.a.c.GlobalExceptionHandler [http-nio-9095-exec-39] exception : No value present for"
      }
    }
  ]
}

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 12, 2023, 3:59am UTC](https://discuss.elastic.co/t/ingest-pipeline-dissect-pattern-unable-to-match-append-modifiers/342765/4 "2023-09-12T03:59:41Z")

</div>

Ahhh did Not get that. I wasn't sure what he was trying to accomplish.

There was still a typo with the wrong `(` versus braces `{` and missing literals

Thank @leandrojmp now I get it!

---

<div class="post-metadata">

**Author:** ![paolovalladolid](https://avatars.discourse-cdn.com/v4/letter/p/edb3f5/32.png) [@paolovalladolid](https://discuss.elastic.co/u/paolovalladolid)\
**Post date:** [September 12, 2023, 2:20pm UTC](https://discuss.elastic.co/t/ingest-pipeline-dissect-pattern-unable-to-match-append-modifiers/342765/5 "2023-09-12T14:20:31Z")

</div>

Thank you Stephen and Leandro. I had the below typed in last night but forgot to click the Reply button. I appreciate the feedback about the [and] literals and the append\_separator.

I ended up replacing the Dissect Processor with a Grok Processor with this pattern

```auto
%{TIMESTAMP_ISO8601:timestamp} %{LOGLEVEL:logLevel} %{JAVACLASS:javaClass} %{DATA:thread_id} %{JAVALOGMESSAGE:content}

```

This processed the document without issue. Our main priority is to be able to find this document by querying on the ```logLevel" field, so this is satisfied.

I was reluctant to switch to Grok but I've been getting burned lately by changes in the structure of the log text. Still, I'll keep your advice in mind if performance becomes an issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 10, 2023, 2:21pm UTC](https://discuss.elastic.co/t/ingest-pipeline-dissect-pattern-unable-to-match-append-modifiers/342765/6 "2023-10-10T14:21:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
