# Oniguruma patern will not work in grok debuger

**URL:** <https://discuss.elastic.co/t/oniguruma-patern-will-not-work-in-grok-debuger/213190>\
**Category:** Logstash\
**Created:** [December 27, 2019, 12:59pm UTC](https://discuss.elastic.co/t/oniguruma-patern-will-not-work-in-grok-debuger/213190 "2019-12-27T12:59:14Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marta\_Zagrajek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marta_zagrajek/32/47442_2.png) [@Marta\_Zagrajek](https://discuss.elastic.co/u/Marta_Zagrajek)\
**Post date:** [December 27, 2019, 12:59pm UTC](https://discuss.elastic.co/t/oniguruma-patern-will-not-work-in-grok-debuger/213190/1 "2019-12-27T12:59:14Z")

</div>

I have a filters like that:

> ```
> filter {
> grok {
> match => { "message" => '%{TIME:timestamp} (\[)?(%{DATA:logger})?(\])? \{%{DATA:thread}\} %{LOGLEVEL:level} : (?<problem>(.|\r|\n)*)' }
> remove_field => ["message"]
> }
> grok {
> match => { "problem" => ''(?<exception>java(.*)Exception).*\z" }
> }
> }
> 
> ```

And in regex101 it is working and group exception is what I wanted to achieve.

Sample of problem field:

> Problem with cache (get from DB):\njava.lang.NullPointerException: null\n09:56:49.712 pl.com.agora.api.client.rest.invocation.FutureCallbacksSupport {HttpClient@2052321524-scheduler} ERROR : Uri invocation failure callback failed. Invocation : AbstractUriInvocation [successful=false

and so on.  
Why it is still telling that exception is the same as problem instead of only: **java.lang.NullPointerException**

---

<div class="post-metadata">

**Author:** ![andres-perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andres-perez/32/136461_2.png) [@andres-perez](https://discuss.elastic.co/u/andres-perez)\
**Post date:** [December 27, 2019, 3:12pm UTC](https://discuss.elastic.co/t/oniguruma-patern-will-not-work-in-grok-debuger/213190/2 "2019-12-27T15:12:53Z")

</div>

Hi  
This pattern `(?<exception>java(.*)Exception).*\z` works as you expected on [https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/) with your `problem` field contents so I presume it may be due to syntax.

Is your grok filter a verbatim copy of the actual configuration?  
Then, the repeated single quotes `''` instead of double quotes `"` are wrong and it may be cause of this issue.

> [@Marta\_Zagrajek](#):
>
> `"problem" => ''(...`

---

<div class="post-metadata">

**Author:** ![Marta\_Zagrajek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marta_zagrajek/32/47442_2.png) [@Marta\_Zagrajek](https://discuss.elastic.co/u/Marta_Zagrajek)\
**Post date:** [December 30, 2019, 6:29am UTC](https://discuss.elastic.co/t/oniguruma-patern-will-not-work-in-grok-debuger/213190/3 "2019-12-30T06:29:34Z")

</div>

> [@andres-perez](#):
>
> `(?<exception>java(.*)Exception).*\z` w

Thank you, but I'm still getting no match even at herokuapp ☹

---

<div class="post-metadata">

**Author:** ![Marta\_Zagrajek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marta_zagrajek/32/47442_2.png) [@Marta\_Zagrajek](https://discuss.elastic.co/u/Marta_Zagrajek)\
**Post date:** [December 30, 2019, 11:29am UTC](https://discuss.elastic.co/t/oniguruma-patern-will-not-work-in-grok-debuger/213190/4 "2019-12-30T11:29:00Z")

</div>

I have checked again in grok debugger and it's working! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 27, 2020, 11:29am UTC](https://discuss.elastic.co/t/oniguruma-patern-will-not-work-in-grok-debuger/213190/5 "2020-01-27T11:29:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
