# My grokstash pattern matches only the first match and skips the rest into the message body

**URL:** <https://discuss.elastic.co/t/my-grokstash-pattern-matches-only-the-first-match-and-skips-the-rest-into-the-message-body/186518>\
**Category:** Logstash\
**Created:** [June 19, 2019, 4:12pm UTC](https://discuss.elastic.co/t/my-grokstash-pattern-matches-only-the-first-match-and-skips-the-rest-into-the-message-body/186518 "2019-06-19T16:12:12Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![kganesan](https://avatars.discourse-cdn.com/v4/letter/k/c37758/32.png) [@kganesan](https://discuss.elastic.co/u/kganesan)\
**Post date:** [June 19, 2019, 4:12pm UTC](https://discuss.elastic.co/t/my-grokstash-pattern-matches-only-the-first-match-and-skips-the-rest-into-the-message-body/186518/1 "2019-06-19T16:12:12Z")

</div>

I am using logtsash grok filters for extracting useful information from the log files.  
I specifically need to extract recurring stopwatch lines from the log file info.

My grok filter does match the first set of stopwatch lines in my log file and parses it but it skips the rest of the log content where there are multiple stopwatch lines and they just appear in the message body.

My grokstash pattern is something like  
"message" =\> "%{DATESTAMP:endTime}%{SPACE}%{WORD}%{SPACE}%{NUMBER}%{SPACE}---%{SPACE}[%{NOTSPACE}]%{SPACE}-%{WORD}"

My logfile content is  
2019-06-17 13:49:20.761 INFO (pattern i want to extract)........  
2019-06-17 13:49:20.761 INFO (pattern i want to extract)........

My pattern captures the first line and structures into variable names i give in the grok. But it skips the next line and moves it to the message body.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 19, 2019, 4:19pm UTC](https://discuss.elastic.co/t/my-grokstash-pattern-matches-only-the-first-match-and-skips-the-rest-into-the-message-body/186518/2 "2019-06-19T16:19:42Z")

</div>

> [@kganesan](#):
>
> My grokstash pattern is something like

Can you show us the pattern you are using and actual log entries that you want it to match?

---

<div class="post-metadata">

**Author:** ![kganesan](https://avatars.discourse-cdn.com/v4/letter/k/c37758/32.png) [@kganesan](https://discuss.elastic.co/u/kganesan)\
**Post date:** [June 19, 2019, 6:06pm UTC](https://discuss.elastic.co/t/my-grokstash-pattern-matches-only-the-first-match-and-skips-the-rest-into-the-message-body/186518/3 "2019-06-19T18:06:35Z")

</div>

The problem is not with the logstash. While I try to run the ELK stack on local, my grok filter applies its pattern to all log lines and create multiple structured fields in elastic search.

But when I try to do it on server where filebeat is pushing multiple logfiles from differen servers to one logstash server, the problem occurs.

The problem is that my filter parses information correctly but it leaves out some of the log lines which matches the filter and filters out only a few. I don't know why.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 19, 2019, 6:19pm UTC](https://discuss.elastic.co/t/my-grokstash-pattern-matches-only-the-first-match-and-skips-the-rest-into-the-message-body/186518/4 "2019-06-19T18:19:53Z")

</div>

I do not think you have supplied enough information for anyone to even guess where the problem might be.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 17, 2019, 6:19pm UTC](https://discuss.elastic.co/t/my-grokstash-pattern-matches-only-the-first-match-and-skips-the-rest-into-the-message-body/186518/5 "2019-07-17T18:19:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
