# Logstash Grok pattern not working

**URL:** <https://discuss.elastic.co/t/logstash-grok-pattern-not-working/181317>\
**Category:** Logstash\
**Created:** [May 16, 2019, 6:40am UTC](https://discuss.elastic.co/t/logstash-grok-pattern-not-working/181317 "2019-05-16T06:40:04Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 16, 2019, 1:35pm UTC](https://discuss.elastic.co/t/logstash-grok-pattern-not-working/181317/4 "2019-05-16T13:35:12Z")

</div>

You have an extra % at the start of the line which should probably be ^

You do not need to escape K or \> with backslash.

That said, I think you should capture the K along with the number, because your code is going to break when it sees B or M or G there. If you capture 9728K using something like (?\<someSize\>[0-9]+[BKMGT]).

You then need to convert that to a number. I once did that will a mutate filter (replacing K with 000 etc -- good enough for what I needed right then). I thought I recently saw a filter that could do that, but I cannot find it now. It may have been an elasticsearch mapper, but I cannot find that either. [This](https://discuss.elastic.co/t/convert-strings-with-different-data-units-mb-gb-tb-to-byte/55064) thread has some suggestions around that, including ruby code.

---

_[View the full topic](https://discuss.elastic.co/t/logstash-grok-pattern-not-working/181317)._
