# Pattern Assistance

**URL:** <https://discuss.elastic.co/t/pattern-assistance/79283>\
**Category:** Logstash\
**Created:** [March 20, 2017, 3:54pm UTC](https://discuss.elastic.co/t/pattern-assistance/79283 "2017-03-20T15:54:13Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![rach](https://avatars.discourse-cdn.com/v4/letter/r/ecb155/32.png) [@rach](https://discuss.elastic.co/u/rach)\
**Post date:** [March 20, 2017, 3:54pm UTC](https://discuss.elastic.co/t/pattern-assistance/79283/1 "2017-03-20T15:54:13Z")

</div>

Hi 🙂  
can you please help me understand the issue?  
this is my log:

DEBUG 2017-02-21 17:49:13,431 "local Ip":172.33.82.82 "Algo":Extraction "Status":"Constructor" "Current":0 "Pending":0 "Done":0 "All":0 "TaskId":425

I tried the following:

input {  
beats {  
port =\> "5043"  
}  
}

filter {  
grok {  
match =\> [  
"message",  
"%{WORD} (?%{TIMESTAMP\_ISO8601}+\d\d:\d\d) %{IP} %{GREEDYDATA:kvdata}"  
]  
}  
kv {  
field\_split =\> " "  
value\_split =\> ":"  
source =\> "kvdata"  
remove\_field =\> "kvdata"  
}  
}

output {  
elasticsearch {  
hosts =\> "localhost:9200"  
}  
stdout {}  
}

not working...

can you please help?  
thank you!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 20, 2017, 9:02pm UTC](https://discuss.elastic.co/t/pattern-assistance/79283/2 "2017-03-20T21:02:28Z")

</div>

The string you're trying to match prefixes the IP address with `"local Ip:"` but you're not including that literal string in your expression. If you're using the kv filter for the rest of the string why not deal with the "local Ip" field in the same way?

---

<div class="post-metadata">

**Author:** ![rach](https://avatars.discourse-cdn.com/v4/letter/r/ecb155/32.png) [@rach](https://discuss.elastic.co/u/rach)\
**Post date:** [March 21, 2017, 8:22am UTC](https://discuss.elastic.co/t/pattern-assistance/79283/3 "2017-03-21T08:22:00Z")

</div>

ok I'll try, thanks!

---

<div class="post-metadata">

**Author:** ![rach](https://avatars.discourse-cdn.com/v4/letter/r/ecb155/32.png) [@rach](https://discuss.elastic.co/u/rach)\
**Post date:** [March 22, 2017, 9:58am UTC](https://discuss.elastic.co/t/pattern-assistance/79283/4 "2017-03-22T09:58:48Z")

</div>

hi!  
I did the following and it's still not working:

input {  
beats {  
port =\> "5043"  
}  
}

filter {  
grok {  
match =\> [  
"message",  
"%{WORD} (?%{TIMESTAMP\_ISO8601}+\d\d:\d\d) %{IP} %{GREEDYDATA:kvdata}"  
]  
}  
kv {  
field\_split =\> " "  
value\_split =\> ":"  
source =\> "kvdata"  
remove\_field =\> "kvdata"  
}  
}

output {  
elasticsearch {  
hosts =\> "localhost:9200"  
}  
stdout {}  
}

i'm getting the tag :

```
beats_input_codec_plain_applied, _grokparsefailure

```

in the Kibana.

can you please assist?  
maybe it has something to do with the filebeat.template.json file?  
what am i missing?...  
thank you!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 22, 2017, 11:19am UTC](https://discuss.elastic.co/t/pattern-assistance/79283/5 "2017-03-22T11:19:42Z")

</div>

I don't get it. Your grok expression is the same as last time so unless you input is different you'll get the same unwanted output.

---

<div class="post-metadata">

**Author:** ![rach](https://avatars.discourse-cdn.com/v4/letter/r/ecb155/32.png) [@rach](https://discuss.elastic.co/u/rach)\
**Post date:** [March 22, 2017, 12:03pm UTC](https://discuss.elastic.co/t/pattern-assistance/79283/6 "2017-03-22T12:03:03Z")

</div>

I've copied by mistake the old pattern. the new one is the same without the IP:

input {  
beats {  
port =\> "5043"  
}  
}  
filter {  
grok {  
match =\> [  
"message",  
"%{WORD} (?%{TIMESTAMP\_ISO8601}+\d\d:\d\d) %{GREEDYDATA:kvdata}"  
]  
}  
kv {  
field\_split =\> " "  
value\_split =\> ":"  
source =\> "kvdata"  
remove\_field =\> "kvdata"  
}  
}  
output {  
elasticsearch {  
hosts =\> "localhost:9200"  
}  
stdout {}  
}

still getting the same issue..

---

<div class="post-metadata">

**Author:** ![asatsi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asatsi/32/28417_2.png) [@asatsi](https://discuss.elastic.co/u/asatsi)\
**Post date:** [March 22, 2017, 12:09pm UTC](https://discuss.elastic.co/t/pattern-assistance/79283/7 "2017-03-22T12:09:40Z")

</div>

Why can't you use this pattern:  
%{WORD} %{TIMESTAMP\_ISO8601} %{GREEDYDATA:kvdata}

---

<div class="post-metadata">

**Author:** ![rach](https://avatars.discourse-cdn.com/v4/letter/r/ecb155/32.png) [@rach](https://discuss.elastic.co/u/rach)\
**Post date:** [March 22, 2017, 12:40pm UTC](https://discuss.elastic.co/t/pattern-assistance/79283/8 "2017-03-22T12:40:09Z")

</div>

tried... didn't work..

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 22, 2017, 12:48pm UTC](https://discuss.elastic.co/t/pattern-assistance/79283/9 "2017-03-22T12:48:44Z")

</div>

Be systematic. Try the shortest possible pattern, `^%{WORD}`. Does that work? Yes? Then add the next token, i.e. `%{WORD} %{TIMESTAMP_ISO8601}` Does that work? Use the grok constructor web site to gradually build your expressions until you're comfortable doing it on your own.

---

<div class="post-metadata">

**Author:** ![asatsi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/asatsi/32/28417_2.png) [@asatsi](https://discuss.elastic.co/u/asatsi)\
**Post date:** [March 22, 2017, 12:58pm UTC](https://discuss.elastic.co/t/pattern-assistance/79283/10 "2017-03-22T12:58:22Z")

</div>

Are you sure? I tried the exact pattern and your log line in online grok debugger [https://grokdebug.herokuapp.com](https://grokdebug.herokuapp.com)[https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/) and it works.

---

<div class="post-metadata">

**Author:** ![rach](https://avatars.discourse-cdn.com/v4/letter/r/ecb155/32.png) [@rach](https://discuss.elastic.co/u/rach)\
**Post date:** [March 22, 2017, 1:12pm UTC](https://discuss.elastic.co/t/pattern-assistance/79283/11 "2017-03-22T13:12:47Z")

</div>

i'm sure... it's not working... tried also only with %{WORD}.  
in the Logstash logs there's now : "string index out of range" and also in the Kibana \_grokparsefailure.  
i'm working with Docker if that changes anything...

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 22, 2017, 1:16pm UTC](https://discuss.elastic.co/t/pattern-assistance/79283/12 "2017-03-22T13:16:39Z")

</div>

Perhaps you have another filter that's giving you the `_grokparsefailure` tag. Check all files in /etc/logstash/conf.d (if that's where you store your configuration files).

---

<div class="post-metadata">

**Author:** ![rach](https://avatars.discourse-cdn.com/v4/letter/r/ecb155/32.png) [@rach](https://discuss.elastic.co/u/rach)\
**Post date:** [March 22, 2017, 1:34pm UTC](https://discuss.elastic.co/t/pattern-assistance/79283/13 "2017-03-22T13:34:25Z")

</div>

that's the only file in /etc/logstash/conf.d..

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2017, 1:34pm UTC](https://discuss.elastic.co/t/pattern-assistance/79283/14 "2017-04-19T13:34:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
