# Logstash grok second row is parsed incorrectly

**URL:** <https://discuss.elastic.co/t/logstash-grok-second-row-is-parsed-incorrectly/138805>\
**Category:** Logstash\
**Created:** [July 5, 2018, 10:58pm UTC](https://discuss.elastic.co/t/logstash-grok-second-row-is-parsed-incorrectly/138805 "2018-07-05T22:58:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![databeata](https://avatars.discourse-cdn.com/v4/letter/d/5e9695/32.png) [@databeata](https://discuss.elastic.co/u/databeata)\
**Post date:** [July 5, 2018, 10:58pm UTC](https://discuss.elastic.co/t/logstash-grok-second-row-is-parsed-incorrectly/138805/1 "2018-07-05T22:58:31Z")

</div>

The first row is parsed correctly. The second row is parsed incorrectly. What is wrong with my grok pattern?

These are the two rows.

2018-07-05 17:57:11,373 ERROR Failed  
2018-07-05 17:57:11,373 ERROR [Timer-Driven Process Thread-6] o.apache.nifi.processors.standard.PutSQL PutSQL[id=ae5119af-3bea-1cba-8309-dc5ffd3f199b] Failed

sudo /path/logstash -e 'input { file { path =\> "/path/test.log" start\_position =\> beginning sincedb\_path =\> "/dev/null" } } filter { grok { match =\> { "message" =\> "%{GREEDYDATA:log\_date} %{GREEDYDATA:log\_time} %{EMAILLOCALPART:log\_level} %{GREEDYDATA:log\_text}" } } }'

{  
"path" =\> "/path/test.log",  
"@timestamp" =\> 2018-07-05T22:33:53.185Z,  
"log\_date" =\> "2018-07-05",  
"@version" =\> "1",  
"host" =\> "host",  
"log\_level" =\> "ERROR",  
"message" =\> "2018-07-05 17:57:11,373 ERROR Failed",  
"log\_time" =\> "17:57:11,373",  
"log\_text" =\> "Failed"  
}  
{  
"path" =\> "/path/test.log",  
"@timestamp" =\> 2018-07-05T22:33:53.189Z,  
"log\_date" =\> "2018-07-05 17:57:11,373 ERROR [Timer-Driven Process",  
"@version" =\> "1",  
"host" =\> "host",  
"log\_level" =\> "o.apache.nifi.processors.standard.PutSQL",  
"message" =\> "2018-07-05 17:57:11,373 ERROR [Timer-Driven Process Thread-6] o.apache.nifi.processors.standard.PutSQL PutSQL[id=ae5119af-3bea-1cba-8309-dc5ffd3f199b] Failed",  
"log\_time" =\> "Thread-6]",  
"log\_text" =\> "PutSQL[id=ae5119af-3bea-1cba-8309-dc5ffd3f199b] Failed"  
}

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 6, 2018, 5:36am UTC](https://discuss.elastic.co/t/logstash-grok-second-row-is-parsed-incorrectly/138805/2 "2018-07-06T05:36:21Z")

</div>

`GREEDYDATA` tries to match as much as possible. As the message in the second line has more parts separated by space than grok fields the first expression grabs as much as possible and then just releases to the other fields what is needed to make the pattern match. You should always try to use as specific patterns as possible and use of one or more `GREEDYDATA` or `DATA` patterns in the same expression can cause this type of problems. I would recommend replacing the first three fields with `NOTSPACE` to see if that helps.

[This blog post](https://www.elastic.co/blog/do-you-grok-grok) contains a guide to efficient use of grok, and is well worth reading.

---

<div class="post-metadata">

**Author:** ![databeata](https://avatars.discourse-cdn.com/v4/letter/d/5e9695/32.png) [@databeata](https://discuss.elastic.co/u/databeata)\
**Post date:** [July 6, 2018, 4:09pm UTC](https://discuss.elastic.co/t/logstash-grok-second-row-is-parsed-incorrectly/138805/3 "2018-07-06T16:09:46Z")

</div>

How do I handle second line in this example?

line 1:  
2018-07-05 17:57:11,373 ERROR [Timer-Driven Process Thread-6] o.apache.nifi.processors.standard.PutSQL

line 2:  
java.sql.SQLException: [JDBC Driver]String index out of range: 3

sudo /path/logstash -e 'input { file { path =\> "/path/test.log" start\_position =\> beginning sincedb\_path =\> "/dev/null" } } filter { grok { match =\> { "message" =\> "%{NOTSPACE:log\_date} %{NOTSPACE:log\_time} %{NOTSPACE:log\_level} %{GREEDYDATA:log\_text}" } } }'

{  
"path" =\> "/path/test.log",  
"@timestamp" =\> 2018-07-06T15:27:18.449Z,  
"log\_date" =\> "2018-07-05",  
"@version" =\> "1",  
"host" =\> "host",  
"log\_level" =\> "ERROR",  
"message" =\> "2018-07-05 17:57:11,373 ERROR [Timer-Driven Process Thread-6] o.apache.nifi.processors.standard.PutSQL",  
"log\_time" =\> "17:57:11,373",  
"log\_text" =\> "[Timer-Driven Process Thread-6] o.apache.nifi.processors.standard.PutSQL"  
}  
{  
"path" =\> "/path/test.log",  
"@timestamp" =\> 2018-07-06T15:27:18.452Z,  
"log\_date" =\> "java.sql.SQLException:",  
"@version" =\> "1",  
"host" =\> "host",  
"log\_level" =\> "Driver]String",  
"message" =\> "java.sql.SQLException: [JDBC Driver]String index out of range: 3",  
"log\_time" =\> "[JDBC",  
"log\_text" =\> "index out of range: 3"  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 3, 2018, 4:09pm UTC](https://discuss.elastic.co/t/logstash-grok-second-row-is-parsed-incorrectly/138805/4 "2018-08-03T16:09:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
