# My grok debugger pattern output doesn't look like the kibana output!

**URL:** <https://discuss.elastic.co/t/my-grok-debugger-pattern-output-doesnt-look-like-the-kibana-output/175738>\
**Category:** Kibana\
**Created:** [April 7, 2019, 9:29pm UTC](https://discuss.elastic.co/t/my-grok-debugger-pattern-output-doesnt-look-like-the-kibana-output/175738 "2019-04-07T21:29:41Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![markov](https://avatars.discourse-cdn.com/v4/letter/m/f1d935/32.png) [@markov](https://discuss.elastic.co/u/markov)\
**Post date:** [April 7, 2019, 9:29pm UTC](https://discuss.elastic.co/t/my-grok-debugger-pattern-output-doesnt-look-like-the-kibana-output/175738/1 "2019-04-07T21:29:42Z")

</div>

hello guys,  
my grok debugger pattern output doesn't look like the kibana output !! any idea !

 ![Selection_007](https://us1.discourse-cdn.com/elastic/original/3X/6/1/6155894852d9882d139127479d39a4dc7c615848.png)  
here is in kibana :

 ![Selection_009](https://us1.discourse-cdn.com/elastic/original/3X/f/2/f2b4dee32092711c52d4ff33f9f15b73e4fee6c9.png)

i think is a multiline problem! i added the multiline codec in the input of logstash also i tried with filebeat.yml but not working!

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 8, 2019, 4:58am UTC](https://discuss.elastic.co/t/my-grok-debugger-pattern-output-doesnt-look-like-the-kibana-output/175738/2 "2019-04-08T04:58:33Z")

</div>

Based on what you have shown I find it hard to see what the problem is. It might help if you show the full JSON of a ducument that has been incorrectly parsed.

---

<div class="post-metadata">

**Author:** ![markov](https://avatars.discourse-cdn.com/v4/letter/m/f1d935/32.png) [@markov](https://discuss.elastic.co/u/markov)\
**Post date:** [April 8, 2019, 9:18am UTC](https://discuss.elastic.co/t/my-grok-debugger-pattern-output-doesnt-look-like-the-kibana-output/175738/3 "2019-04-08T09:18:01Z")

</div>

```
2019-03-11 11:12:40,670 ERROR [org.hibernate.util.JDBCExceptionReporter] ORA-28144: Echec de l'exécution du gestionnaire d'audit détaillé
ORA-20417: ERROR SECURITY DATA
ORA-06512: à "PRODUCTION_AUDIT", ligne 39
ORA-06512: à ligne 1

```

and this is the pattern used that correctly match in grok debugger:

```
%{TIMESTAMP_ISO8601:timestamp} %{LOGLEVEL:Loglevel} \[(?<classname>[^\]]+)\] %{GREEDYDATA:Error}(?<msg>[^\)]+)
```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [April 8, 2019, 9:24am UTC](https://discuss.elastic.co/t/my-grok-debugger-pattern-output-doesnt-look-like-the-kibana-output/175738/4 "2019-04-08T09:24:34Z")

</div>

What does the resulting JSON documents in Elasticsearch look like?

---

<div class="post-metadata">

**Author:** ![markov](https://avatars.discourse-cdn.com/v4/letter/m/f1d935/32.png) [@markov](https://discuss.elastic.co/u/markov)\
**Post date:** [April 8, 2019, 10:11am UTC](https://discuss.elastic.co/t/my-grok-debugger-pattern-output-doesnt-look-like-the-kibana-output/175738/5 "2019-04-08T10:11:41Z")

</div>

```
{
  "_index": "filebeat-2019.04.08",
  "_type": "doc",
  "_id": "ZQJe_GkBGmfQmneQJD3j",
  "_version": 1,
  "_score": null,
  "_source": {
    "prospector": {},
    "classname": "org.hibernate.util.JDBCExceptionReporter",
    "beat": {},
    "@version": "1",
    "Loglevel": "ERROR",
    "timestamp": "2019-03-11 09:12:16,070",
    "Error": "ORA-28144: Echec de l'exécution du gestionnaire d'audit détaill",
    "@timestamp": "2019-04-08T09:51:57.219Z",
    "msg": "é",
    "log": {
      "file": {},
      "flags": [
        "multiline"
      ]
    },
    "input": {},
    "host": {
      "os": {}
    }
  },
  "fields": {
    "@timestamp": [
      "2019-04-08T09:51:57.219Z"
    ]
  },
  "sort": [
    1554717117219
  ]
}

```

it should look like this :

```
{
  "timestamp": [
    "2019-03-11 11:12:40,670"
  ],
  "Loglevel": [
    "ERROR"
  ],
  "classname": [
    "org.hibernate.util.JDBCExceptionReporter"
  ],
  "Error": [
    "ORA-28144: Echec de l'exécution du gestionnaire d'audit détaillé"
  ],
  "msg": [
    "\nORA-20417: ERROR SECURITY DATA\nORA-06512: à "GID_PRODUCTION.GID_SEC_AUDIT_PKG", ligne 39\nORA-06512: à ligne 1"
  ]
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 6, 2019, 10:11am UTC](https://discuss.elastic.co/t/my-grok-debugger-pattern-output-doesnt-look-like-the-kibana-output/175738/6 "2019-05-06T10:11:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
