Logstash grok pattern: Unexpected output

(Rahul Nama) #1


This is the sample log pattern I'm parsing. I'm using grok but it's not exactly as what I expected

180528 8:46:26 2 Query SELECT 1

To parse this log my grok pattern is

%{NUMBER:date} %{NOTSPACE:time}%{INT:pid}%{GREEDYDATA:message}

and output for this in grok debugger is

  "date": [
  "time": [
  "pid": [
  "message": [
      " 2 Query\tSELECT 1"

If you observe in the output, pid is being extracted from time and actual pid which is 2 is being merged in the message. Not sure what went wrong here

Please help, Thanks for your time

(Magnus Bäck) #2

You need spaces between your NOTSPACE, INT, and GREEDYDATA patterns.

(Rahul Nama) #3


Still I'm not able to make it

Any suggestions?

(Magnus Bäck) #4

There are two spaces between the timestamp and "2 Query". You can use \s+ to match one or more whitespace characters.

(Rahul Nama) #5

It worked :slight_smile:

Thankyou much @magnusbaeck

(system) #6

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.