# Logstash Filter - Grok pattern not working as expected

**URL:** <https://discuss.elastic.co/t/logstash-filter-grok-pattern-not-working-as-expected/259271>\
**Category:** Logstash\
**Tags:** ingest-pipeline\
**Created:** [December 21, 2020, 2:29pm UTC](https://discuss.elastic.co/t/logstash-filter-grok-pattern-not-working-as-expected/259271 "2020-12-21T14:29:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![pavank](https://avatars.discourse-cdn.com/v4/letter/p/f0a364/32.png) [@pavank](https://discuss.elastic.co/u/pavank)\
**Post date:** [December 21, 2020, 2:29pm UTC](https://discuss.elastic.co/t/logstash-filter-grok-pattern-not-working-as-expected/259271/1 "2020-12-21T14:29:32Z")

</div>

Hi All,

We are trying to apply Grok filter patterns for our application logs. The logs are applied successfully on the grok debugger online as well as Kibana Dev Tool debugger, but is not getting applied properly in the Logstash.

Log sample:  
[12/21/20 9:07:30:884 UTC] 00000001 **WsServerImpl**** E ****WSVR0009E** : **Error occurred during startup**  
com.ibm.ws.exception.RuntimeError: com.ibm.ejs.EJSException: Could not register with Location Service Daemon, which could only reside in the NodeAgent. Make sure the NodeAgent for this node is up and running.; nested exception is:  
com.ibm.ejs.EJSException: Could not register with Location Service Daemon, which could only reside in the NodeAgent. Make sure the NodeAgent for this node is up and running.; nested exception is:  
java.lang.NullPointerException  
at com.ibm.ws.runtime.component.ORBImpl.start(ORBImpl.java:486)  
at com.ibm.ws.runtime.component.ContainerHelper.startComponents(ContainerHelper.java:540)  
at com.ibm.ws.runtime.component.ContainerImpl.startComponents(ContainerImpl.java:627)  
at com.ibm.ws.runtime.component.ContainerImpl.start(ContainerImpl.java:618)  
at com.ibm.ws.runtime.component.ServerImpl.start(ServerImpl.java:555)  
at com.ibm.ws.runtime.WsServerImpl.bootServerContainer(WsServerImpl.java:311)  
at com.ibm.ws.runtime.WsServerImpl.start(WsServerImpl.java:224)  
at com.ibm.ws.runtime.WsServerImpl.main(WsServerImpl.java:697)  
at com.ibm.ws.runtime.WsServer.main(WsServer.java:59)  
at sun.reflect.NativeMethodAccessorImpl.invoke0(Native Method)

Grok pattern:  
[%{GREEDYDATA}]%{SPACE}%{WORD}%{SPACE}%{WORD:ShortName}%{SPACE}%{WORD:Loglevel}%{SPACE}%{DATA:ErrorCode}:%{SPACE}%{GREEDYDATA:Description}\n%{GREEDYDATA}\n%{SPACE}%{GREEDYDATA}(?m)\n%{SPACE}%{GREEDYDATA}

 ![Kibana Fields Filtered](https://us1.discourse-cdn.com/elastic/original/3X/b/1/b1d1db961697d837850d82acfa02d714441ed160.png)

I need the **bold** parts of the logs to be captured under the fields respectively, but under Description (also attached screenshot) , I see that the entire log lines being captured when I check in Kibana.  
Any help pointing to any mistakes would be of great help.

Regards,  
Pavan

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 21, 2020, 4:26pm UTC](https://discuss.elastic.co/t/logstash-filter-grok-pattern-not-working-as-expected/259271/2 "2020-12-21T16:26:38Z")

</div>

> [@pavank](#):
>
> %{GREEDYDATA:Description}\n%{GREEDYDATA}\n%{SPACE}%{GREEDYDATA}(?m)\n%{SPACE}%{GREEDYDATA}

Your pattern has three newlines in it. In a grok filter, the [Description] field, because it is greedy, will capture as much as possible. Probably everything except the last two lines of the message, because they are used to match the other, unnamed fields.

You could change `%{GREEDYDATA:Description}\n` to `%{DATA:Description}\n`, which would capture the minumum required to match, which would be the rest of the line. Alternatively (and I think the intent is clearer) capture everything that is not a newline, up to the next newline `(?<Description>[^\n]+)\n`.

---

<div class="post-metadata">

**Author:** ![pavank](https://avatars.discourse-cdn.com/v4/letter/p/f0a364/32.png) [@pavank](https://discuss.elastic.co/u/pavank)\
**Post date:** [January 4, 2021, 7:15am UTC](https://discuss.elastic.co/t/logstash-filter-grok-pattern-not-working-as-expected/259271/3 "2021-01-04T07:15:11Z")

</div>

Hello Badger.

This helped. Using DATA for logs with information in a single line nand GREEDYDATA for logs with information spanning multiple lines worked for me.  
Thank you very much for the help.  
A very Happy New Year to you.

Regards,  
Pavan

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 1, 2021, 7:15am UTC](https://discuss.elastic.co/t/logstash-filter-grok-pattern-not-working-as-expected/259271/4 "2021-02-01T07:15:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
