# Logstash dissect and grok pattern matching issue

**URL:** <https://discuss.elastic.co/t/logstash-dissect-and-grok-pattern-matching-issue/270983>\
**Category:** Logstash\
**Created:** [April 22, 2021, 3:49pm UTC](https://discuss.elastic.co/t/logstash-dissect-and-grok-pattern-matching-issue/270983 "2021-04-22T15:49:48Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![mohsin106](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohsin106/32/65203_2.png) [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Post date:** [April 22, 2021, 3:49pm UTC](https://discuss.elastic.co/t/logstash-dissect-and-grok-pattern-matching-issue/270983/1 "2021-04-22T15:49:48Z")

</div>

Hi, I'm trying to use dissect and grok pattern matching together in order to get the desired field:value pair that I want. However, I don't understand why it's not working.

I'm parsing the description field which can come in multiple ways like this:

"description"=\>"SERVERNAME.TC.AT;LOCATION COLLECTOR"  
"description"=\>"SERVERNAME"  
"description"=\>"WORDS WITH SPACES IN BETWEEN THEM"  
"description"=\>"SERVERNAME.TC.AT  
"description"=\>"TEXT;DELIMITED;BY;SEMICOLONS"

I want to target the **last** description pattern with the "text;delimited;by;semicolons" pattern so I'm using dissect to grab the second value from the delimited string.

But as you can see from above, the description comes in a few different formats. So for those other formats, I just want to use grok and store the whole string as-is into my description field.

Here is what Logstash data looks like:

```
if [description] {
  dissect {
    mapping => {"description" => "%{};%{node-name};%{};%{};%{}"}
  }
  if ("_dissectfailure" in [tags]) {
        grok {
            match => {"message" => "%{(?<description>.+)}"}
            remove_field => ["tags"]
        }
  }
}

```

I keep receiving \_dissect and \_grokparsefailures and not sure why.

Thank you.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 22, 2021, 4:00pm UTC](https://discuss.elastic.co/t/logstash-dissect-and-grok-pattern-matching-issue/270983/2 "2021-04-22T16:00:04Z")

</div>

The remove\_field option on the grok filter is only applied if the grok filter matches, otherwise a \_grokparsefailure tag is added. The grok will only match if your [message] field contains %{ and }. I think you meant

```
match => {"message" => "(?<description>.+)"}

```

but to do that it would be cheaper to use mutate

```
mutate {
    add_field => { "description" => "%{message}" }
    remove_field => ["tags"]
}
```

---

<div class="post-metadata">

**Author:** ![mohsin106](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohsin106/32/65203_2.png) [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Post date:** [April 22, 2021, 4:52pm UTC](https://discuss.elastic.co/t/logstash-dissect-and-grok-pattern-matching-issue/270983/3 "2021-04-22T16:52:11Z")

</div>

> [@Badger](#):
>
> I think you meant
> 
> ```auto
> match => {"message" => "(?<description>.+)"}
> 
> ```

Yes, that is what I meant. Couldn't figure out when or when not to use {}.

I also noticed a mistake with my initial grok filter. I was matching on a field called "message" when it should have been "description". This appers to be working now:

```
if ("_dissectfailure" in [tags]) {
    grok {
        match => {"description" => "(?<description>.+)"}
        remove_field => ["tags"]
    }
}

```

I believe your recommendation was to do this:

```
if ("_dissectfailure" in [tags]) {
    mutate {
        add_field => { "description" => "%{description}" }
        remove_field => ["tags"]
    }
}

```

However, that was taking the contents of the description field and appending it to itself. Basically duplicating it.

Ex: I was seeing this in the JSON output in Kibana

```
"description": [
    "NODE1.RD.OM",
    "NODE1.RD.OM"
],

```

Is that what is supposed to happen?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 22, 2021, 5:12pm UTC](https://discuss.elastic.co/t/logstash-dissect-and-grok-pattern-matching-issue/270983/4 "2021-04-22T17:12:29Z")

</div>

Yes, if a field already exists add\_field will turn it into an array.

But `match => {"description" => "(?<description>.+)"}` does not make any sense. It just sets the description field to have the value of the description field. It is a no-op. Perhaps replace

```
dissect {
    mapping => {"description" => "%{};%{node-name};%{};%{};%{}"}
}
if ("_dissectfailure" in [tags]) {
    grok {
        match => {"message" => "%{(?<description>.+)}"}
        remove_field => ["tags"]
    }
}

```

with

```
dissect {
    mapping => {"description" => "%{};%{node-name};%{};%{};%{}"}
    tag_on_failure => []
}
```

---

<div class="post-metadata">

**Author:** ![mohsin106](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohsin106/32/65203_2.png) [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Post date:** [April 22, 2021, 7:50pm UTC](https://discuss.elastic.co/t/logstash-dissect-and-grok-pattern-matching-issue/270983/5 "2021-04-22T19:50:11Z")

</div>

> [@Badger](#):
>
> But `match => {"description" => "(?<description>.+)"}` does not make any sense. It just sets the description field to have the value of the description field. It is a no-op. Perhaps replace

That was my intention, so that I stop seeing the \_dissectfailure tags and also to stop seeing the "Dissector mapping, pattern not found" [WARN] messages in the logs.

> [@Badger](#):
>
> ```auto
> dissect {
> mapping => {"description" => "%{};%{node-name};%{};%{};%{}"}
> tag_on_failure => []
> }
> 
> ```

When I implement this, the \_dissectfailure tags go away but the [WARN] messages are still logging.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 22, 2021, 8:05pm UTC](https://discuss.elastic.co/t/logstash-dissect-and-grok-pattern-matching-issue/270983/6 "2021-04-22T20:05:47Z")

</div>

> [@mohsin106](#):
>
> the [WARN] messages are still logging

Yes, the [logging](https://github.com/logstash-plugins/logstash-filter-dissect/blob/7aac48d6131a4e5c991d8e7b801ca0ea81e32dfb/src/main/java/org/logstash/dissect/JavaDissectorLibrary.java#L190) is unconditional.

What you can do is

```
if [description] =~ /(.+;){4}.+/ {
    dissect { ...

```

---

<div class="post-metadata">

**Author:** ![mohsin106](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohsin106/32/65203_2.png) [@mohsin106](https://discuss.elastic.co/u/mohsin106)\
**Post date:** [April 22, 2021, 8:38pm UTC](https://discuss.elastic.co/t/logstash-dissect-and-grok-pattern-matching-issue/270983/7 "2021-04-22T20:38:47Z")

</div>

> [@Badger](#):
>
> `if [description] =~ /(.+;){4}.+/ {`

Thanks, the regex magic works like a charm. Much cleaner looking too. 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 20, 2021, 8:39pm UTC](https://discuss.elastic.co/t/logstash-dissect-and-grok-pattern-matching-issue/270983/8 "2021-05-20T20:39:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
