# Logtash Pattern not working

**URL:** <https://discuss.elastic.co/t/logtash-pattern-not-working/104553>\
**Category:** Logstash\
**Created:** [October 19, 2017, 12:56pm UTC](https://discuss.elastic.co/t/logtash-pattern-not-working/104553 "2017-10-19T12:56:17Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![mbvelo](https://avatars.discourse-cdn.com/v4/letter/m/59ef9b/32.png) [@mbvelo](https://discuss.elastic.co/u/mbvelo)\
**Post date:** [October 19, 2017, 12:56pm UTC](https://discuss.elastic.co/t/logtash-pattern-not-working/104553/1 "2017-10-19T12:56:17Z")

</div>

```
input {
 beats {
         port => 5044
   }    
}
filter {
    grok {
        match => ["mesage", "ts:(?<date>(([0-9]+)-*)+ ([0-9]+-*)+ [A-Z]+)\|INFO:%{{LOGLEVEL:LEVE}\|WebContainer:%{WORD:WebContainer}\|request:%{WORD:request}\|jsessionid:%{WORD:jsessionid}"]
    }
    date {
        match => ["ts","yyyy-MM-dd HH-mm-ss-SSS"]
        target => "@timestamp"
    }

date {
        match => ["date","yyyy-MM-dd HH-mm-ss-SSS z"]
        target => "@timestamp"
    }
  }
	
  output {
    elasticsearch {
    hosts => "localhost:9200"
    #index => "%{[@metadata]}-%{+YYYY.MM.dd}"
    index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
    document_type => "%{[@metadata][type]}"
}
}
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 19, 2017, 5:58pm UTC](https://discuss.elastic.co/t/logtash-pattern-not-working/104553/2 "2017-10-19T17:58:00Z")

</div>

Is the field that you want to parse with grok really named `mesage`?

---

<div class="post-metadata">

**Author:** ![mbvelo](https://avatars.discourse-cdn.com/v4/letter/m/59ef9b/32.png) [@mbvelo](https://discuss.elastic.co/u/mbvelo)\
**Post date:** [October 20, 2017, 6:43am UTC](https://discuss.elastic.co/t/logtash-pattern-not-working/104553/3 "2017-10-20T06:43:03Z")

</div>

My log snippet  
"input\_type": "log",  
"message": "2017-10-12 16:36:14,716 INFO [WebContainer : 2] x.x.x.x.x.OperationController [OperationController.java:113] processRequest UserInfo request: UserInfo{accessAccount='null', attributes={}, creationDate=Thu Oct 12 16:35:40 SAST 2017, userLocale=null, deviceLocalDateTime=null, deviceOSName='ANDROID', deviceOSVersion='null', appVersion='null', authenticated=false, userNumber='null', localCurrencyCode='x', timeZoneOffSet='0', phoneNumber=null, countryCode='null', activityRefNo='null', sessionId='xxxxxxxxxxx', lastLoginTime='null', deviceId='xxxxxxxxxxx', deviceModelName='null', originatorIPAddress='null', channel='S', ipAddress='xxxxxxxxxxx', localIpAddress='xxxxxxxxxxx', correlationId='null', email='null', iVal='null', jsessionid='xxxxxxxxxxx:xxxxxxxxx', enterpriseSessionId='null', wfpt='null', xfpt='null', nonce='ovLPayS4JzLaB3T6wCzIw-LpLaqJZe1uxm4UsoeVipw', userAgent='null', OpList=[]} ",`Preformatted text`

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 23, 2017, 5:35am UTC](https://discuss.elastic.co/t/logtash-pattern-not-working/104553/4 "2017-10-23T05:35:16Z")

</div>

So your event contains a `message` field but you've configured your grok filter to parse a `mesage` field that probably doesn't exist.

---

<div class="post-metadata">

**Author:** ![mbvelo](https://avatars.discourse-cdn.com/v4/letter/m/59ef9b/32.png) [@mbvelo](https://discuss.elastic.co/u/mbvelo)\
**Post date:** [October 23, 2017, 12:35pm UTC](https://discuss.elastic.co/t/logtash-pattern-not-working/104553/5 "2017-10-23T12:35:37Z")

</div>

> [@mbvelo](#):
>
> input {  
> beats {  
> port =\> 5044  
> }  
> }  
> filter {  
> grok {  
> match =\> ["mesage", "ts:(?\<date\>(([0-9]+)-_)+ ([0-9]+-_)+ [A-Z]+)|INFO:%{{LOGLEVEL:LEVE}|WebContainer:%{WORD:WebContainer}|request:%{WORD:request}|jsessionid:%{WORD:jsessionid}"]  
> }  
> date {  
> match =\> ["ts","yyyy-MM-dd HH-mm-ss-SSS"]  
> target =\> "@timestamp"  
> }
> 
> date {  
> match =\> ["date","yyyy-MM-dd HH-mm-ss-SSS z"]  
> target =\> "@timestamp"  
> }  
> }
> 
> output {  
> elasticsearch {  
> hosts =\> "localhost:9200"  
> #index =\> "%{[@metadata]}-%{+YYYY.MM.dd}"  
> index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
> document\_type =\> "%{[@metadata][type]}"  
> }  
> }

```
i updated the Grok filter 
I am getting this response

herewith my log - please help getting a pattern

```

2017 - 10 - 20 08: 53: 39, 785[WebContainer: 1] ACTIVITY OUT: xxxxxx ErrorCode = 00000 Field = 00000 Exception = null JSON = {  
"field1": "xxxxxx",  
"field2": "00000",  
"field3": "value",  
"field4": "value",  
"Parent": [{  
"child1": "value",  
"child2": "value",  
"child3": "value",  
"Parent": {  
"child1": "value",  
"child2": "value"  
},  
"Parent1": {  
"child1": "value",  
"child2": "value"  
},  
"field5": "value",  
"field6": "value",  
"field7": "value",  
"field8": "value",  
"field9": "value",  
"field10": "value",  
"Parent2": {  
"child1": "Value",  
"child2": "Value"  
}  
}, {  
"child1": "value",  
"child2": "value",  
"child3": "value",  
"Parent": {  
"child1": "value",  
"child2": "value"  
},  
"Parent1": {  
"child1": "value",  
"child2": "value"  
},  
"field5": "value",  
"field6": "value",  
"field7": "value",  
"field8": "value",  
"field9": "value",  
"field10": "value",  
"Parent3": {  
"child1": "value",  
"child2": "value"  
}  
}, {  
"child1": "value",  
"child2": "value",  
"child3": "value",  
"Parent": {  
"child1": "value",  
"child2": "value"  
},  
"Parent1": {  
"child1": "value",  
"child2": "value"  
},  
"field5": "value,  
"field5": "value",  
"field5": "value",  
"field5": "value",  
"field5": "value",  
"field5": "value",  
"Parent4": {  
"child1": "value",  
"child2": "value"  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 23, 2017, 1:13pm UTC](https://discuss.elastic.co/t/logtash-pattern-not-working/104553/6 "2017-10-23T13:13:41Z")

</div>

> match =\> ["mesage", "ts:(?(([0-9]+)-)+ ([0-9]+-)+ ...

No! Your configuration still says `mesage` instead of `message`. Over and out.

---

<div class="post-metadata">

**Author:** ![mbvelo](https://avatars.discourse-cdn.com/v4/letter/m/59ef9b/32.png) [@mbvelo](https://discuss.elastic.co/u/mbvelo)\
**Post date:** [October 23, 2017, 1:24pm UTC](https://discuss.elastic.co/t/logtash-pattern-not-working/104553/7 "2017-10-23T13:24:00Z")

</div>

> [@mbvelo](#):
>
> input {
> 
> beats {
> 
> port =\> 5044
> 
> }
> 
> }
> 
> filter {
> 
> grok {
> 
> match =\> ["mesage", "ts:(?\<date\>(([0-9]+)-)+ ([0-9]+-)+ [A-Z]+)|INFO:%{{LOGLEVEL:LEVE}|WebContainer:%{WORD:WebContainer}|request:%{WORD:request}|jsessionid:%{WORD:jsessionid}"]
> 
> }
> 
> date {
> 
> match =\> ["ts","yyyy-MM-dd HH-mm-ss-SSS"]
> 
> target =\> "@timestamp"
> 
> }
> 
> date {
> 
> match =\> ["date","yyyy-MM-dd HH-mm-ss-SSS z"]
> 
> target =\> "@timestamp"
> 
> }
> 
> }
> 
> output {
> 
> elasticsearch {
> 
> hosts =\> "localhost:9200"
> 
> #index =\> "%{[@metadata]}-%{+YYYY.MM.dd}"
> 
> index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
> 
> document\_type =\> "%{[@metadata][type]}"
> 
> }
> 
> }

```
rectified - uploaded the pattern

geytting this errror

	"tags": [
		"beats_input_codec_plain_applied",
		"_grokparsefailure",
		"_geoip_lookup_failure"

```

---

<div class="post-metadata">

**Author:** ![mbvelo](https://avatars.discourse-cdn.com/v4/letter/m/59ef9b/32.png) [@mbvelo](https://discuss.elastic.co/u/mbvelo)\
**Post date:** [October 23, 2017, 1:30pm UTC](https://discuss.elastic.co/t/logtash-pattern-not-working/104553/8 "2017-10-23T13:30:10Z")

</div>

```
 input {
 	beats {
 		port => 5044
 	}
 }
 filter {
 	grok {
 		match => ["message", "ts:(?<date>(([0-9]+)-)+ ([0-9]+-)+ [A-Z]+)|INFO:%{{LOGLEVEL:LEVE}|WebContainer:%{WORD:WebContainer}|request:%{WORD:request}|response:%{WORD:response}||jsessionid:%{WORD:jsessionid}"]
 	}
 	date {
 		match => ["ts", "yyyy-MM-dd HH-mm-ss-SSS"]
 		target => "@timestamp"
 	}

 	date {
 		match => ["date", "yyyy-MM-dd HH-mm-ss-SSS z"]
 		target => "@timestamp"
 	}
 }

 output {
 	elasticsearch {
 		hosts => "localhost:9200"
 		index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
 		document_type => "%{[@metadata][type]}"
 	}
 }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 20, 2017, 1:30pm UTC](https://discuss.elastic.co/t/logtash-pattern-not-working/104553/9 "2017-11-20T13:30:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
