# Not all Java classes can be parsed using GROK pattern %{JAVACLASS}

**URL:** <https://discuss.elastic.co/t/not-all-java-classes-can-be-parsed-using-grok-pattern-javaclass/157545>\
**Category:** Logstash\
**Created:** [November 20, 2018, 12:33pm UTC](https://discuss.elastic.co/t/not-all-java-classes-can-be-parsed-using-grok-pattern-javaclass/157545 "2018-11-20T12:33:03Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ovanekem](https://avatars.discourse-cdn.com/v4/letter/o/6a8cbe/32.png) [@ovanekem](https://discuss.elastic.co/u/ovanekem)\
**Post date:** [November 20, 2018, 12:33pm UTC](https://discuss.elastic.co/t/not-all-java-classes-can-be-parsed-using-grok-pattern-javaclass/157545/1 "2018-11-20T12:33:03Z")

</div>

I'm writing a Logstash filter (using Logstash 6.4.0) that will filter lots of different applications (some are Spring Boot, some are Wildfly, some uses generated classes from wsdl2java,...).  
An issue I face is that the %{JAVACLASS} grok pattern is not alway matching the java class that creates the log.  
For example:  
ab.cd.ef works  
ab\_cd does not work  
ab.cd\_ef works  
ab$cd does not work

So I'm going to write my own regex pattern that's not an issue but I was wondering where in code of Logstash I could check the current defined patterns and compare with the ones I am (going to) write?

I found out that at some point there was a number of pattern files in GitHub in directory logstash/patterns (then /java,...) but those have disappeared as of release 2.4 and I must say that I do not know where they are located today...

Olivier

---

<div class="post-metadata">

**Author:** ![Shaoranlaos](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@Shaoranlaos](https://discuss.elastic.co/u/Shaoranlaos)\
**Post date:** [November 20, 2018, 1:34pm UTC](https://discuss.elastic.co/t/not-all-java-classes-can-be-parsed-using-grok-pattern-javaclass/157545/2 "2018-11-20T13:34:14Z")

</div>

all patterns that are used in the logstash grok can be found in a separate plugin under

> **[logstash-plugins/logstash-patterns-core](https://github.com/logstash-plugins/logstash-patterns-core/tree/master/patterns)**
>
> Contribute to logstash-plugins/logstash-patterns-core development by creating an account on GitHub.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 18, 2018, 1:34pm UTC](https://discuss.elastic.co/t/not-all-java-classes-can-be-parsed-using-grok-pattern-javaclass/157545/3 "2018-12-18T13:34:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
