# Lumberjack loosing grokked fields?

**URL:** <https://discuss.elastic.co/t/lumberjack-loosing-grokked-fields/18597>\
**Category:** Elasticsearch\
**Created:** [July 11, 2014, 9:38am UTC](https://discuss.elastic.co/t/lumberjack-loosing-grokked-fields/18597 "2014-07-11T09:38:16Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Siddharth\_Trikha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/siddharth_trikha/32/133867_2.png) [@Siddharth\_Trikha](https://discuss.elastic.co/u/Siddharth_Trikha)\
**Post date:** [July 11, 2014, 9:38am UTC](https://discuss.elastic.co/t/lumberjack-loosing-grokked-fields/18597/1 "2014-07-11T09:38:16Z")

</div>

I am using logstash 1.4.1 on my client machine (where logs are present) and  
server machine (where logstash parses events).

On _client_ I read logs:

input {  
file{  
path =\> "/root/Desktop/Logstash-Input/\*\*/\*\_log"  
start\_position =\> "beginning"  
}  
}

filter {  
grok {

```
    match => ["path", 

```

"/root/Desktop/Logstash-Input/(?[^/]+)/(?[^/]+)/(?[\d]+.[\d]+.[\d]+)/(?.\*)\_log"]  
}  
}

output {

```
    lumberjack {
            hosts => ["192.168.105.71"]
            port => 4545
            ssl_certificate => "./logstash.pub"
}

    stdout { codec => rubydebug }

```

}

\*Console: \*

_filter received {:event=\>{"message"=\>"2014-05-26T00:00:01+05:30 bxas1  
crond[268]: (roooot) CMD (2014/05/31/server2/cron/log)", "@version"=\>"1",  
"@timestamp"=\>"2014-07-11T09:14:28.740Z", "host"=\>"cmd",  
"path"=\>"/root/Desktop/Logstash-Input/Server2/CronLog/2014.05.31/cron\_log"},  
:level=\>:debug, :file=\>"(eval)", :line=\>"18"}{ "message" =\>  
"2014-05-26T00:00:01+05:30 bxas1 crond[268]: (roooot) CMD  
(2014/05/31/server2/cron/log)", "@version" =\> "1", "@timestamp"  
=\> "2014-07-11T09:14:28.735Z", "host" =\> "cmd", "path"  
=\>  
"/root/Desktop/Logstash-Input/Server2/CronLog/2014.05.31/cron\_log",  
"server" =\> "Server2", "logtype" =\> "CronLog", "logdate" =\>  
"2014.05.31", "logfilename" =\> "cron"}_  
_On server:_

input {  
lumberjack {  
port =\> 4545  
ssl\_certificate =\> "/etc/ssl/logstash.pub"  
ssl\_key =\> "/etc/ssl/logstash.key"  
codec =\> "json"  
}  
}

filter {  
if [server] == "Server2" and [logtype] == "CronLog" {

```
grok{
match => ["message", "........Pattern......"]        
add_tag => "server2-cronlog"
}   

```

}else if [server] == "Server2" and [logtype] == "AuthLog"{

```
grok{
match => ["message", ".......Pattern......"]
}
}

```

_Server-Console:_

_filter received {:event=\>{"message"=\>"2014-07-11T09:29:59.730+0000 cmd  
2014-05-26T00:00:01+05:30 bx920as1 crond[268]: (rorit) CMD  
(2014/05/31/server2/cron/log)", "@version"=\>"1",  
"@timestamp"=\>"2014-07-11T09:30:41.772Z"}, :level=\>:debug, :file=\>"(eval)",  
:line=\>"30"}output received  
{:event=\>{"message"=\>"2014-07-11T09:29:59.730+0000 cmd  
2014-05-26T00:00:01+05:30 bx920as1 crond[26388]: (rorit) CMD  
(2014/05/31/server2/cron/log)", "@version"=\>"1",  
"@timestamp"=\>"2014-07-11T09:30:41.772Z"}, :level=\>:debug, :file=\>"(eval)",  
:line=\>"100"}{ "message" =\> "2014-07-11T09:29:59.730+0000 cmd  
2014-05-26T00:00:01+05:30 bx920as1 crond[268]: (rorit) CMD  
(2014/05/31/server2/cron/log)", "@version" =\> "1", "@timestamp" =\>  
"2014-07-11T09:30:41.772Z"}_  
So as one can see the grokked fields at the client machine are lost after  
shipping via lumberjack. Is this a bug??

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/136d308e-3f02-42cd-bf8d-0bcd9d665e74%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/136d308e-3f02-42cd-bf8d-0bcd9d665e74%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:16am UTC](https://discuss.elastic.co/t/lumberjack-loosing-grokked-fields/18597/2 "2017-07-06T01:16:34Z")

</div>


