# Logstash Filter error

**URL:** <https://discuss.elastic.co/t/logstash-filter-error/115655>\
**Category:** Logstash\
**Created:** [January 16, 2018, 7:40am UTC](https://discuss.elastic.co/t/logstash-filter-error/115655 "2018-01-16T07:40:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![rijinmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rijinmp/32/24634_2.png) [@rijinmp](https://discuss.elastic.co/u/rijinmp)\
**Post date:** [January 16, 2018, 7:40am UTC](https://discuss.elastic.co/t/logstash-filter-error/115655/1 "2018-01-16T07:40:27Z")

</div>

## My Log

198.0.200.105 - - [14/Jan/2014:09:36:50 -0800] "GET /svds.com/rockandroll HTTP/1.1" 301 241 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10\_9\_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/31.0.1650.63 Safari/537.36"

## Filter is created from [https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/)

%{HOSTNAME:vhost} - - [%{HTTPDATE:timestamp}] "%{WORD:Method} %{DATA:request} HTTP/%{BASE10NUM:version}" %{INT:response} %{GREEDYDATA:Details}

## My Logstash conf

input{

file {  
path =\> "/home/elastic/elk/samplelog/access.log"  
start\_position =\> "beginning"  
}  
}  
filter {

grok { match =\> { "message" =\> "%{HOSTNAME:vhost} - - [%{HTTPDATE:timestamp}] "%{WORD:Method} %{DATA:request} HTTP/%{BASE10NUM:version}" %{INT:response} %{GREEDYDATA:Details}" }  
}

date {  
locale =\> "en"  
match =\> ["timestamp", "dd/MMM/yyyy:HH:mm:ss Z"]  
timezone =\> "Europe/Rome"  
}

}  
output {  
stdout{ codec =\> rubydebug }  
}

## When I am using the whole filter, Logstash showing error

%{HOSTNAME:vhost} - - [%{HTTPDATE:timestamp}] "%{WORD:Method} %{DATA:request} HTTP/%{BASE10NUM:version}" %{INT:response} %{GREEDYDATA:Details}

Output :

Error : Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, {, -, ", ', } at line 15, column 143 (byte 325) after filter { \n\n \n grok { match =\> { "message" =\> "%{HOSTNAME:vhost} - - \[%{HTTPDATE:timestamp}\] \"%{WORD:Method} %{DATA:request} HTTP/%{BASE10NUM:version}" ", :backtrace=\>["/home/elastic/elk/logstash/logstash-6.1.1/logstash-core/lib/logstash/compiler.rb:42:

## When I am using half of the filter , no error ... Logstash is parsing the log.

filter {

grok { match =\> { "message" =\> "%{HOSTNAME:vhost} - - [%{HTTPDATE:timestamp}] "%{WORD:Method}" }  
}

Output :  
{  
"@version" =\> "1",  
"timestamp" =\> "23/Jan/2014:11:42:58 -0800",  
"host" =\> "localhost.localdomain",  
"@timestamp" =\> 2014-01-23T19:42:58.000Z,  
"message" =\> "198.0.200.105 - - [23/Jan/2014:11:42:58 -0800] "GET /svds.com/rockandroll/img/12.jpg HTTP/1.1" 200 3832 "[http://www.svds.com/rockandroll/](http://www.svds.com/rockandroll/)" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10\_9\_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.77 Safari/537.36"",  
"path" =\> "/home/elastic/elk/samplelog/access.log",  
"vhost" =\> "198.0.200.105",  
"Method" =\> "GET"  
}

May be because of " " in filter .

Please healp me to solve this

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [January 16, 2018, 5:04pm UTC](https://discuss.elastic.co/t/logstash-filter-error/115655/2 "2018-01-16T17:04:59Z")

</div>

Use single quotes to define the pattern if the pattern itself contains double quotes.

```auto
grok {
  match => {
    "message" => '%{HOSTNAME:vhost} - - [%{HTTPDATE:timestamp}] "%{WORD:Method} %{DATA:request} HTTP/%{BASE10NUM:version}" %{INT:response} %{GREEDYDATA:Details}'
  }
}

```

---

<div class="post-metadata">

**Author:** ![rijinmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rijinmp/32/24634_2.png) [@rijinmp](https://discuss.elastic.co/u/rijinmp)\
**Post date:** [January 21, 2018, 12:00pm UTC](https://discuss.elastic.co/t/logstash-filter-error/115655/3 "2018-01-21T12:00:31Z")

</div>

Thank you @guyboertje . I will check

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 18, 2018, 12:00pm UTC](https://discuss.elastic.co/t/logstash-filter-error/115655/4 "2018-02-18T12:00:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
