# Logstash GROK

**URL:** <https://discuss.elastic.co/t/logstash-grok/384394>\
**Category:** Logstash\
**Created:** [January 6, 2026, 5:35pm UTC](https://discuss.elastic.co/t/logstash-grok/384394 "2026-01-06T17:35:06Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Elk\_huh](https://avatars.discourse-cdn.com/v4/letter/e/d26b3c/32.png) [@Elk\_huh](https://discuss.elastic.co/u/Elk_huh)\
**Post date:** [January 6, 2026, 5:35pm UTC](https://discuss.elastic.co/t/logstash-grok/384394/1 "2026-01-06T17:35:06Z")

</div>

```auto
      "<190>606524: 876342: Jan 6 2026 17:27:24.835 UTC: %SEC-6-IPACCESSLOGP: list BLOCK-Wifi denied udp 11.12.2.75(51811) -> 111.22.13.60(5246), 2 packets "

```

Grok Parser succeeds but i am getting grok error in Elasticsearch

```auto
       grok {
        pattern_definitions => {
            "MYTIMESTAMP" => "%{MONTH:month}\s+%{MONTHDAY:day}\s+%{YEAR:year}\s+%{TIME:time}\s+%{WORD:timezone}"
             }
         match => { "message" => "<%{INT:syslog_priority}>%{INT:log1}: %{INT:log2}: %{MYTIMESTAMP:timestamp}: %%{DATA:syslog_message_type}: %{DATA:log3} %{DATA:DeviceType} %{DATA:Action} %{DATA:protocol} %{IP:src_ip}\(%{INT:src_port}\) %{GREEDYDATA:remove}%{IP:dst_ip}\(%{INT:dst_port}\), %{GREEDYDATA:packet}}
     }

     mutate {
       add_field => { "devicevendor" => "cisco" }
       add_field => { "deviceproduct" => "switch" }
       }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 6, 2026, 9:55pm UTC](https://discuss.elastic.co/t/logstash-grok/384394/2 "2026-01-06T21:55:54Z")

</div>

> [@Elk\_huh](#):
>
> ```auto
> match => { "message" => "<%{INT:syslog_priority}>%{INT:log1}: %{INT:log2}: %{MYTIMESTAMP:timestamp}: %%{DATA:syslog_message_type}: %{DATA:log3} %{DATA:DeviceType} %{DATA:Action} %{DATA:protocol} %{IP:src_ip}\(%{INT:src_port}\) %{GREEDYDATA:remove}%{IP:dst_ip}\(%{INT:dst_port}\), %{GREEDYDATA:packet}}
> 
> ```

That’s an invalid configuration, so the logstash pipeline will not even start. It is missing the closing double quote. If you add the quote it will successfully grok the message.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 7, 2026, 12:00pm UTC](https://discuss.elastic.co/t/logstash-grok/384394/3 "2026-01-07T12:00:00Z")

</div>

+ grok is not correct

Should be like this:

```auto
       grok {
        pattern_definitions => {
            # "MYTIMESTAMP" => "%{MONTH:month}\s+%{MONTHDAY:day}\s+%{YEAR:year}\s+%{TIME:time}\s+%{WORD:timezone}"
            "MYTIMESTAMP" => "MYTIMESTAMP %{MONTH}\s+%{MONTHDAY}\s+%{YEAR}\s+%{TIME}\s+%{WORD}"
             }
         match => { "message" => "<%{INT:syslog_priority}>%{INT:log1}: %{INT:log2}: %{MYTIMESTAMP:timestamp}: \%%{DATA:syslog_message_type}: %{DATA:log3} %{DATA:DeviceType} %{DATA:Action} %{DATA:protocol} %{IP:src_ip}\(%{INT:src_port}\) %{DATA} %{IP:dst_ip}\(%{INT:dst_port}\), %{GREEDYDATA:packet}"
     }

```

Note: From MYTIMESTAMP has been removed date&time fields, and the "remove" field has been removed, just not assigned to any field.
