# Ingest Pipeline for parsing multiline fields giving provided Grok expressions do not match field value error error

**URL:** <https://discuss.elastic.co/t/ingest-pipeline-for-parsing-multiline-fields-giving-provided-grok-expressions-do-not-match-field-value-error-error/337699>\
**Category:** Elasticsearch\
**Created:** [July 5, 2023, 4:33pm UTC](https://discuss.elastic.co/t/ingest-pipeline-for-parsing-multiline-fields-giving-provided-grok-expressions-do-not-match-field-value-error-error/337699 "2023-07-05T16:33:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![SecretAsianMan](https://avatars.discourse-cdn.com/v4/letter/s/cdc98d/32.png) [@SecretAsianMan](https://discuss.elastic.co/u/SecretAsianMan)\
**Post date:** [July 5, 2023, 4:33pm UTC](https://discuss.elastic.co/t/ingest-pipeline-for-parsing-multiline-fields-giving-provided-grok-expressions-do-not-match-field-value-error-error/337699/1 "2023-07-05T16:33:53Z")

</div>

I am trying to parse a multiline log file as shown below.  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/1/81b27bfd3cef009dfdc8beb0b761379c578962d2.png)

This is the processor that I have currently configured for the multiline log file.

```auto
[
  {
    "grok": {
      "field": "message",
      "patterns": [
        "%{GREEDYMULTILINE}%{ROW_TITLE}%{GREEDYDATA:name}"
      ],
      "pattern_definitions": {
        "GREEDYMULTILINE": "(.|\n)*",
        "ROW_TITLE": "name: "
      },
      "description": "extracts name from message"
    }
  },
  {
    "grok": {
      "field": "message",
      "patterns": [
        "%{GREEDYMULTILINE}%{ROW_TITLE}%{GREEDYDATA:txt}"
      ],
      "pattern_definitions": {
        "GREEDYMULTILINE": "(.|\n)*",
        "ROW_TITLE": "txt: "
      }
    }
  }
]

```

The pipeline tries to process the log file that is aggregated from the custom log integration plug-in. However, I get an error saying that the Grok expressions does not match field value. I have tried to test the pipeline with same message via console and is successful. Is there something that I'm doing wrong that can be done differently? Is the issue coming from the log file itself?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 9, 2023, 9:40pm UTC](https://discuss.elastic.co/t/ingest-pipeline-for-parsing-multiline-fields-giving-provided-grok-expressions-do-not-match-field-value-error-error/337699/2 "2023-07-09T21:40:24Z")

</div>

Hi @SecretAsianMan Welcome to the community...

Please share a sample of the `_source` document in JSON that is being passed to this ingest processor.

Make sure it is not changed when you paste it here

Have you tried the `_simulate` API for ingest pipeline in Kibana Dev Tools?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 6, 2023, 9:40pm UTC](https://discuss.elastic.co/t/ingest-pipeline-for-parsing-multiline-fields-giving-provided-grok-expressions-do-not-match-field-value-error-error/337699/3 "2023-08-06T21:40:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
