# Logstash Grok pattern GREEDYDATA does not match

**URL:** <https://discuss.elastic.co/t/logstash-grok-pattern-greedydata-does-not-match/158535>\
**Category:** Logstash\
**Created:** [November 28, 2018, 10:09am UTC](https://discuss.elastic.co/t/logstash-grok-pattern-greedydata-does-not-match/158535 "2018-11-28T10:09:31Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rani](https://avatars.discourse-cdn.com/v4/letter/r/f4b2a3/32.png) [@rani](https://discuss.elastic.co/u/rani)\
**Post date:** [November 28, 2018, 10:09am UTC](https://discuss.elastic.co/t/logstash-grok-pattern-greedydata-does-not-match/158535/1 "2018-11-28T10:09:32Z")

</div>

Hello there

I'm currently building a pipeline with different grok patterns. For the most part it's properly working already but I'm having issues with some Jira logs:

Log Message:  
2018-11-21 12:50:23,950 http-nio-8080-exec-4 INFO anonymous 769x323x1 1hhvqv1 10.195.161.19 /secure/SetupLicense.jspa [c.a.j.p.devstatus.upgrade.UpgradeTask\_Build02] Running Upgrade task to add searcher for development field.

Grok Pattern:  
(?%{YEAR}-%{MONTHNUM}-%{MONTHDAY}%{SPACE}%{TIME}) %{JIRA\_THREAD:thread} %{WORD:loglevel} %{WORD:user} %{JIRA\_HTTP\_ID:http\_request\_id} %{JIRA\_HTTP\_ID:http\_session\_id} %{IP:ip} %{UNIXPATH:path} %{JIRA\_CLASS:class} %{GREEDYDATA:message}

Custom Patterns:  
JIRA\_THREAD [A-Za-z0-9-/:]+  
JIRA\_HTTP\_ID [A-Za-z0-9-]+  
JIRA\_CLASS [A-Za-z0-9.]+

The GREEDYDATA:message part doesn't match and I don't understand why. I've checked it with the inbuilt Kibana grok debugger. Can someone please explain this behavior to me?

Thanks in advance!

---

<div class="post-metadata">

**Author:** ![Eniqmatic](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@Eniqmatic](https://discuss.elastic.co/u/Eniqmatic)\
**Post date:** [November 28, 2018, 11:18am UTC](https://discuss.elastic.co/t/logstash-grok-pattern-greedydata-does-not-match/158535/2 "2018-11-28T11:18:35Z")

</div>

What does the result look like?

---

<div class="post-metadata">

**Author:** ![rani](https://avatars.discourse-cdn.com/v4/letter/r/f4b2a3/32.png) [@rani](https://discuss.elastic.co/u/rani)\
**Post date:** [November 28, 2018, 11:32am UTC](https://discuss.elastic.co/t/logstash-grok-pattern-greedydata-does-not-match/158535/3 "2018-11-28T11:32:29Z")

</div>

The grok debugger output? It's empty and the error is: "Provided Grok patterns do not match data in the input"

---

<div class="post-metadata">

**Author:** ![Eniqmatic](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@Eniqmatic](https://discuss.elastic.co/u/Eniqmatic)\
**Post date:** [November 28, 2018, 11:48am UTC](https://discuss.elastic.co/t/logstash-grok-pattern-greedydata-does-not-match/158535/4 "2018-11-28T11:48:59Z")

</div>

Try this:

```
%{TIMESTAMP_ISO8601:date} %{JIRA_THREAD:thread} %{WORD:loglevel} %{WORD:user} %{JIRA_HTTP_ID:http_request_id} %{JIRA_HTTP_ID:http_session_id} %{IP:ip} %{URIPATH:path} %{JIRA_CLASS:class} %{GREEDYDATA:message}

```

Custom pattern:

```
JIRA_THREAD %{WORD}-%{WORD}-%{INT}-%{WORD}-%{INT}
JIRA_HTTP_ID [A-Za-z0-9-]+
JIRA_CLASS [A-Za-z0-9.\[\]_]+
```

---

<div class="post-metadata">

**Author:** ![rani](https://avatars.discourse-cdn.com/v4/letter/r/f4b2a3/32.png) [@rani](https://discuss.elastic.co/u/rani)\
**Post date:** [November 28, 2018, 12:28pm UTC](https://discuss.elastic.co/t/logstash-grok-pattern-greedydata-does-not-match/158535/5 "2018-11-28T12:28:05Z")

</div>

Oh, I missed the underscore in the JIRA\_CLASS pattern. Thank you for the fast help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2018, 12:28pm UTC](https://discuss.elastic.co/t/logstash-grok-pattern-greedydata-does-not-match/158535/6 "2018-12-26T12:28:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
