# No Matches for the grok filter

**URL:** <https://discuss.elastic.co/t/no-matches-for-the-grok-filter/122820>\
**Category:** Logstash\
**Created:** [March 7, 2018, 5:13am UTC](https://discuss.elastic.co/t/no-matches-for-the-grok-filter/122820 "2018-03-07T05:13:46Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![kavinda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kavinda/32/31586_2.png) [@kavinda](https://discuss.elastic.co/u/kavinda)\
**Post date:** [March 7, 2018, 5:13am UTC](https://discuss.elastic.co/t/no-matches-for-the-grok-filter/122820/1 "2018-03-07T05:13:46Z")

</div>

HI all

Im new to the ELK stack and i have face fallowing problem when i try to create a pattern for a custom log file

This is the custom log line

`INFO [01/Jul/2017:03:38:38 +0530]	REQUEST CarrierName Balance Check 15240273`

This is the filter i wrote

```
filter {
  grok {
     match => { "message" => "%{LOGLEVEL:Info} \[%{TIMESTAMP_ISO8601:time}\] %{URIPROTO:type} %{WORD:carrier} %{NOTSPACE:task} %{NUMBER:id}"}
}
}

```

But this return "no mathes " on grok debugger

Any suggestions ???

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [March 7, 2018, 7:44am UTC](https://discuss.elastic.co/t/no-matches-for-the-grok-filter/122820/2 "2018-03-07T07:44:22Z")

</div>

You are using the pattern NOTSPACE and "Balance Check" obviously has a space in it.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 7, 2018, 9:02am UTC](https://discuss.elastic.co/t/no-matches-for-the-grok-filter/122820/3 "2018-03-07T09:02:04Z")

</div>

- Your expression requires two spaces after the log level but your example indicates you only have one space.
- Your timestamp isn't ISO8601 so TIMESTAMP\_ISO8601 won't work.
- As previously mentioned NOTSPACE and "Balance Check" doesn't make sense.

---

<div class="post-metadata">

**Author:** ![kavinda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kavinda/32/31586_2.png) [@kavinda](https://discuss.elastic.co/u/kavinda)\
**Post date:** [March 8, 2018, 5:55am UTC](https://discuss.elastic.co/t/no-matches-for-the-grok-filter/122820/4 "2018-03-08T05:55:05Z")

</div>

Thnk you for your reply and any suggestion on how to capture that

```
WORD 
NOTSPACE 
SPACE 
DATA 
GREEDYDATA
```

---

<div class="post-metadata">

**Author:** ![kavinda](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kavinda/32/31586_2.png) [@kavinda](https://discuss.elastic.co/u/kavinda)\
**Post date:** [March 8, 2018, 6:14am UTC](https://discuss.elastic.co/t/no-matches-for-the-grok-filter/122820/5 "2018-03-08T06:14:15Z")

</div>

hi , Thank you for your feedback and what can i use for that time stamp

`\[%{HTTPDATE:timestamp}\]`

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 8, 2018, 7:22am UTC](https://discuss.elastic.co/t/no-matches-for-the-grok-filter/122820/6 "2018-03-08T07:22:43Z")

</div>

> hi , Thank you for your feedback and what can i use for that time stamp
> 
> ```
> \[%{HTTPDATE:timestamp}\]
> 
> ```

Why don't you try it out?

Regarding how to match "Balance Check", the most efficient would be to match two words with `(?<fieldname>\w+ \w+)`, but is it _always_ two words there? Or do you want to match everything up to the number at the end? In the latter case DATA or GREEDYDATA would be adequate choices.

Anyway, you should be more diligent with the use of `^` and `$` anchors. The loglevel should always match at the beginning of the string so your expression should begin with `^%{LOGLEVEL:Info}` (I think the `Info` field name is a misnomer, but that's another story) and it should end with `%{NUMBER:id}$` since the number must always be at the end of the string (right?).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 5, 2018, 7:22am UTC](https://discuss.elastic.co/t/no-matches-for-the-grok-filter/122820/7 "2018-04-05T07:22:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
