# Overwrite doesn't happen when message empty

**URL:** <https://discuss.elastic.co/t/overwrite-doesnt-happen-when-message-empty/123095>\
**Category:** Logstash\
**Created:** [March 8, 2018, 2:27pm UTC](https://discuss.elastic.co/t/overwrite-doesnt-happen-when-message-empty/123095 "2018-03-08T14:27:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![huyouiqq](https://avatars.discourse-cdn.com/v4/letter/h/6a8cbe/32.png) [@huyouiqq](https://discuss.elastic.co/u/huyouiqq)\
**Post date:** [March 8, 2018, 2:27pm UTC](https://discuss.elastic.co/t/overwrite-doesnt-happen-when-message-empty/123095/1 "2018-03-08T14:27:22Z")

</div>

logstash 5.3.0

filter {  
grok {  
patterns\_dir =\> ["/etc/logstash/patterns"]  
match =\> [  
"message", "%{NGINXACCESS} %{GREEDYDATA:message}",  
"message", "%{NGINXACCESSAUTH}%{GREEDYDATA:message}",  
"message", "%{NGINXERROR}",  
"message", "%{PHPLOG}%{GREEDYDATA:message}",  
"message", "%{FPMERROR}%{GREEDYDATA:message}",  
"message", "%{SYSLOG5424PRI}%{SYSLOGBASE2} %{GREEDYDATA:message}"  
]  
overwrite =\> ["message"]  
}

I am having an issue here where I have a complete parse here for NGINXACCESSAUTH which leaves me with empty result for %{GREEDYDATA:message} and this not rewriting message field to empty, leaving me with messy outcome of message field being the full rsyslog source message as well as all the tags parsed.

program:nginx  
logsource:ppdlweb005  
nginx\_client:10.175.37.27  
nginx\_auth:-  
nginx\_time:08/Mar/2018:14:16:24 +0000  
nginx\_ident:-  
nginx\_response:200  
message:\<141\>Mar 8 14:16:33 ppdlweb005 nginx 10.175.37.27 - - - [08/Mar/2018:14:16:24 +0000] "HEAD /?\_=havemercy11 HTTP/1.1" 200 0 "-" "AppleWebkit/534.1 (KHTML) HbbTV/1.4.1 (+DRM;SureSoft-Browser-3.0;T3;0010;1.0;Manhattan-FVPlay;) FVC/2.0(SureSoft-Browser-3.0;Manhattan-FVPlay;)" SUCCESS 0.001

nginx\_bytes:0  
http\_user\_agent:AppleWebkit/534.1 (KHTML) HbbTV/1.4.1 (+DRM;SureSoft-Browser-3.0;T3;0010;1.0;Manhattan-FVPlay;) FVC/2.0(SureSoft-Browser-3.0;Manhattan-FVPlay;) nginx\_httpversion:1.1  
@timestamp:March 8th 2018, 14:16:33.000  
nginx\_verb:HEAD  
nginx\_processing\_time:0.001  
fvc\_role:auth  
http\_referer:-  
fvc\_env:staging  
syslog5424\_pri:141  
@version:1  
host:ppdlweb005  
nginx\_ssl\_verify:SUCCESS  
nginx\_request:/?\_=havemercy11  
timestamp:Mar 8 14:16:33  
\_id:AWIF-Hov00VaJHdB36R2  
\_type:logs \_index:logstash-2018.03.08  
\_score: -

Any idea how to go about this apart from removing part of the pattern so there is something for GREEDYDATA to parse?

---

<div class="post-metadata">

**Author:** ![huyouiqq](https://avatars.discourse-cdn.com/v4/letter/h/6a8cbe/32.png) [@huyouiqq](https://discuss.elastic.co/u/huyouiqq)\
**Post date:** [March 9, 2018, 4:15pm UTC](https://discuss.elastic.co/t/overwrite-doesnt-happen-when-message-empty/123095/2 "2018-03-09T16:15:56Z")

</div>

solved by keep\_empty\_captures =\> true

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 6, 2018, 4:16pm UTC](https://discuss.elastic.co/t/overwrite-doesnt-happen-when-message-empty/123095/3 "2018-04-06T16:16:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
