# Logstash 7.1.1 grokparsefailure despite match pattern

**URL:** <https://discuss.elastic.co/t/logstash-7-1-1-grokparsefailure-despite-match-pattern/185075>\
**Category:** Logstash\
**Created:** [June 11, 2019, 12:04am UTC](https://discuss.elastic.co/t/logstash-7-1-1-grokparsefailure-despite-match-pattern/185075 "2019-06-11T00:04:42Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [June 11, 2019, 12:04am UTC](https://discuss.elastic.co/t/logstash-7-1-1-grokparsefailure-despite-match-pattern/185075/1 "2019-06-11T00:04:42Z")

</div>

I have upgraded logstash to 7.1.1 and I am receiving a grokparsefailure despite my pattern matching. See below.

{"log":{"file":{"path":"/var/log/cassandra/system.log"},"offset":18875190},"input":{"type":"log"},"tags":["cassandra\_log","b-gp2-cassdb2-5","beats\_input\_codec\_plain\_applied","\_grokparsefailure"],"ecs":{"version":"1.0.0"},"agent":{"id":"dfbddef6-0564-4d06-9ec2-d857fc46d2a3","version":"7.1.1","hostname":"b-gp2-cassdb2-5","type":"filebeat","ephemeral\_id":"7b292ba5-248c-4d94-a916-07bfee432a3c"},"message":"INFO [RMI TCP Connection(478136)-127.0.0.1] 2019-06-10 23:26:38,176 NoSpamLogger.java:94 - Maximum memory usage reached (12666798080), cannot allocate chunk of 1048576","@timestamp":"2019-06-10T23:26:38.671Z","@version":"1","host":{"name":"b-gp2-cassdb2-5"}}

INFO [RMI TCP Connection(478136)-127.0.0.1] 2019-06-10 23:26:38,176 NoSpamLogger.java:94 - Maximum memory usage reached (12666798080), cannot allocate chunk of 1048576

%{WORD:status}%{SPACE}[(?[^(]\*)(%{NUMBER:pid})-%{IP:ipaddress}]%{SPACE}%{TIMESTAMP\_ISO8601:timestamp},%{NUMBER:lineno}%{SPACE}%{GREEDYDATA:statement}

{  
"ipaddress": "127.0.0.1",  
"lineno": "176",  
"statement": "NoSpamLogger.java:94 - Maximum memory usage reached (12666798080), cannot allocate chunk of 1048576",  
"pid": "478136",  
"program": "RMI TCP Connection",  
"status": "INFO",  
"timestamp": "2019-06-10 23:26:38"  
}

---

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [June 11, 2019, 12:06am UTC](https://discuss.elastic.co/t/logstash-7-1-1-grokparsefailure-despite-match-pattern/185075/2 "2019-06-11T00:06:00Z")

</div>

![grokPattern](https://us1.discourse-cdn.com/elastic/original/3X/5/0/506065403528e1d209e88055c9ce4b29bbae3210.png)

---

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [June 11, 2019, 12:06am UTC](https://discuss.elastic.co/t/logstash-7-1-1-grokparsefailure-despite-match-pattern/185075/3 "2019-06-11T00:06:52Z")

</div>

some how I keep receiving a log file with these patterns not matching. doesn't make sense unless there is a bug in logstash 7.1.1

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 11, 2019, 12:33am UTC](https://discuss.elastic.co/t/logstash-7-1-1-grokparsefailure-despite-match-pattern/185075/4 "2019-06-11T00:33:32Z")

</div>

Please do not post pictures of text, just post the text and format it using markdown so that spacing and other important information is preserved. You can select a block of text and select the \</\> option in the toolbar above the edit pane.

If you have something like

Foo Bar  
Baz ...

then that will change it to

```
Foo Bar
Baz ...
```

---

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [June 11, 2019, 1:04am UTC](https://discuss.elastic.co/t/logstash-7-1-1-grokparsefailure-despite-match-pattern/185075/5 "2019-06-11T01:04:40Z")

</div>

I did put the text along with the image. do you have a response to my question?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 11, 2019, 1:26am UTC](https://discuss.elastic.co/t/logstash-7-1-1-grokparsefailure-despite-match-pattern/185075/6 "2019-06-11T01:26:58Z")

</div>

Your post is not properly formatted, which may result in the browser consuming characters as markup when they are actually part of the event, and the grok needs to match it. I currently have no way of knowing what your event looks like.

---

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [June 11, 2019, 1:44am UTC](https://discuss.elastic.co/t/logstash-7-1-1-grokparsefailure-despite-match-pattern/185075/7 "2019-06-11T01:44:22Z")

</div>

```
INFO [RMI TCP Connection(478136)-127.0.0.1] 2019-06-10 23:26:38,176 NoSpamLogger.java:94 - Maximum memory usage reached (12666798080), cannot allocate chunk of 1048576

%{WORD:status}%{SPACE}\[(?<program>[^(]*)\(%{NUMBER:pid}\)-%{IP:ipaddress}\]%{SPACE}%{TIMESTAMP_ISO8601:timestamp},%{NUMBER:lineno}%{SPACE}%{GREEDYDATA:statement}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 11, 2019, 9:28am UTC](https://discuss.elastic.co/t/logstash-7-1-1-grokparsefailure-despite-match-pattern/185075/8 "2019-06-11T09:28:07Z")

</div>

With that message and pattern I get

```
   "program" => "RMI TCP Connection",
       "pid" => "478136",
 "ipaddress" => "127.0.0.1",
   "message" => "INFO [RMI TCP Connection(478136)-127.0.0.1] 2019-06-10 23:26:38,176 NoSpamLogger.java:94 - Maximum memory usage reached (12666798080), cannot allocate chunk of 1048576",
"@timestamp" => 2019-06-11T09:24:42.613Z,
    "lineno" => "176",
    "status" => "INFO",
 "statement" => "NoSpamLogger.java:94 - Maximum memory usage reached (12666798080), cannot allocate chunk of 1048576"

```

and I do not get a \_grokparsefailure tag. Is it possible you pointed path.config at a directory and you have a something.conf.bck or something.conf- that contains a different grok? logstash will concatentate all the files in path.config to form the configuration.

---

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [June 11, 2019, 1:08pm UTC](https://discuss.elastic.co/t/logstash-7-1-1-grokparsefailure-despite-match-pattern/185075/9 "2019-06-11T13:08:09Z")

</div>

I have one config file

root@d-gp2-es46-4:/etc/logstash/conf.d# ls -ltrh  
total 12K  
-rwxr-xr-x 1 root root 12K Jun 4 23:05 ls\_fb\_postgres.conf

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 11, 2019, 2:23pm UTC](https://discuss.elastic.co/t/logstash-7-1-1-grokparsefailure-despite-match-pattern/185075/10 "2019-06-11T14:23:43Z")

</div>

That suggests that there is another grok filter in that file. One that does not match.

---

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [June 11, 2019, 2:27pm UTC](https://discuss.elastic.co/t/logstash-7-1-1-grokparsefailure-despite-match-pattern/185075/11 "2019-06-11T14:27:16Z")

</div>

this is the filter i have for cassandra. i have several patterns and it should just go one by one until it matches one. am i doing something wrong?

```
  else if "cassandra_log" in [tags] {
grok {
  match => { "message" => ["%{WORD:status}%{SPACE}\[%{WORD:program}:%{NUMBER:pid}\]%{SPACE}%{TIMESTAMP_ISO8601:timestamp},%{NUMBER:lineno}%{SPACE}%{GREEDYDATA:statement}"] }
  match => { "message" => ["%{WORD:status}%{SPACE}\[%{WORD:program}#%{NUMBER:pid}:%{NUMBER:pid2}\]%{SPACE}%{TIMESTAMP_ISO8601:timestamp},%{NUMBER:lineno}%{SPACE}%{GREEDYDATA:statement}"] }
  match => { "message" => ["%{WORD:status}%{SPACE}\[%{USERNAME:program}-%{INT:pid}\]%{SPACE}%{TIMESTAMP_ISO8601:timestamp},%{NUMBER:lineno}%{SPACE}%{GREEDYDATA:statement}"] }
  match => { "message" => ["%{WORD:status}%{SPACE}\[(?<program>[^(]*)\(%{NUMBER:pid}\)-%{IP:ipaddress}\]%{SPACE}%{TIMESTAMP_ISO8601:timestamp},%{NUMBER:lineno}%{SPACE}%{GREEDYDATA:statement}"] }
  match => { "message" => ["%{WORD:status}%{SPACE}\[(?<program>[^(]*)\]%{SPACE}%{TIMESTAMP_ISO8601:timestamp},%{NUMBER:lineno}%{SPACE}%{GREEDYDATA:statement}"] }
  remove_field => "message"
}
date {
  match => ["timestamp", "YY-MM-dd HH:mm:ss"]
  locale => en
  remove_field => "timestamp"
}

if "_grokparsefailure" not in [tags] {
  mutate {
    remove_field => ["message", "@version"]
  }
}

```

}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 11, 2019, 2:53pm UTC](https://discuss.elastic.co/t/logstash-7-1-1-grokparsefailure-despite-match-pattern/185075/12 "2019-06-11T14:53:07Z")

</div>

> [@kyle\_che](#):
>
> am i doing something wrong?

Not that I can see. For me that gets a match and no \_grokparsefailure. Is it possible the event does not have the tag that you expect?

---

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [June 11, 2019, 3:42pm UTC](https://discuss.elastic.co/t/logstash-7-1-1-grokparsefailure-despite-match-pattern/185075/13 "2019-06-11T15:42:14Z")

</div>

this all worked on 6.x without any issues. it's just when i went to 7.x that it's not working correctly sometimes. i'm getting messages from logstash into my indexes but not sure why random ones don't get processed correctly. I verified the tag and it's cassandra\_log so it is correct.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 11, 2019, 3:49pm UTC](https://discuss.elastic.co/t/logstash-7-1-1-grokparsefailure-despite-match-pattern/185075/14 "2019-06-11T15:49:56Z")

</div>

I can get a \_grokparsefailure if I set

```
pipeline.java_execution: true

```

in logstash.yml. I normally have that set to false. Setting it to true became the default in v7.

```
    grok {
        match => { "message" => [
            "%{WORD:status}%{SPACE}\[%{WORD:program}:%{NUMBER:pid}\]%{SPACE}%{TIMESTAMP_ISO8601:timestamp},%{NUMBER:lineno}%{SPACE}%{GREEDYDATA:statement}",
            "%{WORD:status}%{SPACE}\[%{WORD:program}#%{NUMBER:pid}:%{NUMBER:pid2}\]%{SPACE}%{TIMESTAMP_ISO8601:timestamp},%{NUMBER:lineno}%{SPACE}%{GREEDYDATA:statement}",
            "%{WORD:status}%{SPACE}\[(?<program>[^(]*)\(%{NUMBER:pid}\)-%{IP:ipaddress}\]%{SPACE}%{TIMESTAMP_ISO8601:timestamp},%{NUMBER:lineno}%{SPACE}%{GREEDYDATA:statement}",
            "%{WORD:status}%{SPACE}\[%{USERNAME:program}-%{INT:pid}\]%{SPACE}%{TIMESTAMP_ISO8601:timestamp},%{NUMBER:lineno}%{SPACE}%{GREEDYDATA:statement}",
            "%{WORD:status}%{SPACE}\[(?<program>[^(]*)\]%{SPACE}%{TIMESTAMP_ISO8601:timestamp},%{NUMBER:lineno}%{SPACE}%{GREEDYDATA:statement}"
    ] }
    remove_field => "message"
}

```

works.

---

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [June 11, 2019, 4:46pm UTC](https://discuss.elastic.co/t/logstash-7-1-1-grokparsefailure-despite-match-pattern/185075/15 "2019-06-11T16:46:18Z")

</div>

I tried setting in logstash.yml file but the service keeps bouncing on me.

```
pipeline.java_execution: false

```

[2019-06-11T16:43:30,831][ERROR][org.logstash.Logstash] java.lang.IllegalStateException: Logstash stopped processing because of an error: (SystemExit) exit

---

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [June 11, 2019, 4:52pm UTC](https://discuss.elastic.co/t/logstash-7-1-1-grokparsefailure-despite-match-pattern/185075/16 "2019-06-11T16:52:52Z")

</div>

[2019-06-11T16:51:07,962][INFO][org.logstash.beats.Server] Starting server on port: 5044  
[2019-06-11T16:51:08,394][INFO][logstash.agent] Pipelines running {:count=\>1, :running\_pipelines=\>[:main], :non\_running\_pipelines=\>}  
[2019-06-11T16:51:10,678][WARN][logstash.outputs.elasticsearch] You are using a deprecated config setting "document\_type" set in elasticsearch. Deprecated settings will continue to work, but are scheduled for removal from logstash in the future. Document types are being deprecated in Elasticsearch 6.0, and removed entirely in 7.0. You should avoid this feature If you have any questions about this, please visit the #logstash channel on freenode irc. {:name=\>"document\_type", :plugin=\>\<LogStash::Outputs::ElasticSearch bulk\_path=\>"/\_monitoring/bulk?system\_id=logstash&system\_api\_version=7&interval=1s", password=\>, hosts=\>[[//d-gp2-es46-1.imovetv.com:9200](https://d-gp2-es46-1.imovetv.com:9200), [//d-gp2-es46-2.imovetv.com:9200](https://d-gp2-es46-2.imovetv.com:9200), [//d-gp2-es46-3.imovetv.com:9200](https://d-gp2-es46-3.imovetv.com:9200)], sniffing=\>false, manage\_template=\>false, id=\>"6a55002c9e602408bc41ca0aa07151d93e7f5327d249d825a3a6989256a1c111", user=\>"logstash\_system", document\_type=\>"%{[@metadata][document\_type]}", enable\_metric=\>true, codec=\>\<LogStash::Codecs::Plain id=\>"plain\_2678d30c-98ca-4672-aa5f-8f20e6533bbb", enable\_metric=\>true, charset=\>"UTF-8"\>, workers=\>1, template\_name=\>"logstash", template\_overwrite=\>false, doc\_as\_upsert=\>false, script\_type=\>"inline", script\_lang=\>"painless", script\_var\_name=\>"event", scripted\_upsert=\>false, retry\_initial\_interval=\>2, retry\_max\_interval=\>64, retry\_on\_conflict=\>1, ilm\_enabled=\>"auto", ilm\_rollover\_alias=\>"logstash", ilm\_pattern=\>"{now/d}-000001", ilm\_policy=\>"logstash-policy", action=\>"index", ssl\_certificate\_verification=\>true, sniffing\_delay=\>5, timeout=\>60, pool\_max=\>1000, pool\_max\_per\_route=\>100, resurrect\_delay=\>5, validate\_after\_inactivity=\>10000, http\_compression=\>false\>}  
[2019-06-11T16:51:10,725][INFO][logstash.pipeline] Starting pipeline {:pipeline\_id=\>".monitoring-logstash", "pipeline.workers"=\>1, "pipeline.batch.size"=\>2, "pipeline.batch.delay"=\>50}  
[2019-06-11T16:51:10,840][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>, :added=\>[[http://logstash\_system:xxxxxx@d-gp2-es46-1.imovetv.com:9200/](http://logstash_system:xxxxxx@d-gp2-es46-1.imovetv.com:9200/), [http://logstash\_system:xxxxxx@d-gp2-es46-2.imovetv.com:9200/](http://logstash_system:xxxxxx@d-gp2-es46-2.imovetv.com:9200/), [http://logstash\_system:xxxxxx@d-gp2-es46-3.imovetv.com:9200/](http://logstash_system:xxxxxx@d-gp2-es46-3.imovetv.com:9200/)]}}  
[2019-06-11T16:51:10,862][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://logstash\_system:xxxxxx@d-gp2-es46-1.imovetv.com:9200/](http://logstash_system:xxxxxx@d-gp2-es46-1.imovetv.com:9200/)"}  
[2019-06-11T16:51:10,876][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es\_version=\>7}  
[2019-06-11T16:51:10,876][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>7}  
[2019-06-11T16:51:10,884][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://logstash\_system:xxxxxx@d-gp2-es46-2.imovetv.com:9200/](http://logstash_system:xxxxxx@d-gp2-es46-2.imovetv.com:9200/)"}  
[2019-06-11T16:51:10,893][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://logstash\_system:xxxxxx@d-gp2-es46-3.imovetv.com:9200/](http://logstash_system:xxxxxx@d-gp2-es46-3.imovetv.com:9200/)"}  
[2019-06-11T16:51:10,899][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[//d-gp2-es46-1.imovetv.com:9200](https://d-gp2-es46-1.imovetv.com:9200)", "[//d-gp2-es46-2.imovetv.com:9200](https://d-gp2-es46-2.imovetv.com:9200)", "[//d-gp2-es46-3.imovetv.com:9200](https://d-gp2-es46-3.imovetv.com:9200)"]}  
[2019-06-11T16:51:11,191][INFO][logstash.pipeline] Pipeline started successfully {:pipeline\_id=\>".monitoring-logstash", :thread=\>"#\<Thread:0xaa31b4d sleep\>"}  
[2019-06-11T16:51:11,232][INFO][logstash.agent] Pipelines running {:count=\>2, :running\_pipelines=\>[:main, :".monitoring-logstash"], :non\_running\_pipelines=\>}  
[2019-06-11T16:51:13,194][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[2019-06-11T16:51:56,902][FATAL][logstash.runner] An unexpected error occurred! {:error=\>java.nio.channels.ClosedByInterruptException, :backtrace=\>["java.nio.channels.spi.AbstractInterruptibleChannel.end(AbstractInterruptibleChannel.java:202)", "sun.nio.ch.FileChannelImpl.write(FileChannelImpl.java:216)", "org.logstash.ackedqueue.io.FileCheckpointIO.write(FileCheckpointIO.java:79)", "org.logstash.ackedqueue.Page.forceCheckpoint(Page.java:205)", "org.logstash.ackedqueue.Page.headPageCheckpoint(Page.java:170)", "org.logstash.ackedqueue.Page.checkpoint(Page.java:159)", "org.logstash.ackedqueue.Queue.ack(Queue.java:643)", "org.logstash.ackedqueue.Batch.close(Batch.java:37)", "org.logstash.ackedqueue.AckedBatch.close(AckedBatch.java:33)", "org.logstash.ackedqueue.AckedReadBatch.close(AckedReadBatch.java:77)", "org.logstash.execution.QueueReadClientBase.closeBatch(QueueReadClientBase.java:111)", "org.logstash.execution.QueueReadClientBase.rubyCloseBatch(QueueReadClientBase.java:130)", "org.logstash.execution.QueueReadClientBase$INVOKER$i$1$0$rubyCloseBatch.call(QueueReadClientBase$INVOKER$i$1$0$rubyCloseBatch.gen)", "org.jruby.runtime.callsite.CachingCallSite.call(CachingCallSite.java:168)", "org.jruby.ir.interpreter.InterpreterEngine.processCall(InterpreterEngine.java:317)", "org.jruby.ir.interpreter.StartupInterpreterEngine.interpret(StartupInterpreterEngine.java:72)", "org.jruby.ir.interpreter.InterpreterEngine.interpret(InterpreterEngine.java:92)", "org.jruby.internal.runtime.methods.MixedModeIRMethod.INTERPRET\_METHOD(MixedModeIRMethod.java:204)", "org.jruby.internal.runtime.methods.MixedModeIRMethod.call(MixedModeIRMethod.java:191)", "org.jruby.internal.runtime.methods.DynamicMethod.call(DynamicMethod.java:208)", "usr.share.logstash.logstash\_minus\_core.lib.logstash.pipeline.RUBY$block$start\_workers$2(/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:304)", "org.jruby.runtime.CompiledIRBlockBody.callDirect(CompiledIRBlockBody.java:136)", "org.jruby.runtime.IRBlockBody.call(IRBlockBody.java:77)", "org.jruby.runtime.Block.call(Block.java:124)", "org.jruby.RubyProc.call(RubyProc.java:295)", "org.jruby.RubyProc.call(RubyProc.java:274)", "org.jruby.RubyProc.call(RubyProc.java:270)", "org.jruby.internal.runtime.RubyRunnable.run(RubyRunnable.java:105)", "java.lang.Thread.run(Thread.java:748)"]}  
[2019-06-11T16:51:57,013][ERROR][org.logstash.Logstash] java.lang.IllegalStateException: Logstash stopped processing because of an error: (SystemExit) exit

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 11, 2019, 5:04pm UTC](https://discuss.elastic.co/t/logstash-7-1-1-grokparsefailure-despite-match-pattern/185075/17 "2019-06-11T17:04:00Z")

</div>

> [@kyle\_che](#):
>
> java.nio.channels.ClosedByInterruptException

That is covered by [this](https://github.com/elastic/logstash/issues/10612) open issue.

---

<div class="post-metadata">

**Author:** ![kyle\_che](https://avatars.discourse-cdn.com/v4/letter/k/ce73a5/32.png) [@kyle\_che](https://discuss.elastic.co/u/kyle_che)\
**Post date:** [June 11, 2019, 5:07pm UTC](https://discuss.elastic.co/t/logstash-7-1-1-grokparsefailure-despite-match-pattern/185075/18 "2019-06-11T17:07:29Z")

</div>

ok, seems that open issue is not resolved. i'm confused. i'm not doing anything special and it's rather simple. why would they change the java execution to true if it doesn't work? at this point is there anything i can do to get this working or am i waiting for basically another release 7.1.2?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 11, 2019, 5:10pm UTC](https://discuss.elastic.co/t/logstash-7-1-1-grokparsefailure-despite-match-pattern/185075/19 "2019-06-11T17:10:58Z")

</div>

> [@kyle\_che](#):
>
> am i waiting for basically another release 7.1.2?

I think you will have to delay your V7 migration until something gets fixed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 9, 2019, 5:11pm UTC](https://discuss.elastic.co/t/logstash-7-1-1-grokparsefailure-despite-match-pattern/185075/20 "2019-07-09T17:11:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
