# Problem grok pattern

**URL:** <https://discuss.elastic.co/t/problem-grok-pattern/82200>\
**Category:** Logstash\
**Created:** [April 12, 2017, 4:39pm UTC](https://discuss.elastic.co/t/problem-grok-pattern/82200 "2017-04-12T16:39:07Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vittorio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vittorio/32/18171_2.png) [@Vittorio](https://discuss.elastic.co/u/Vittorio)\
**Post date:** [April 12, 2017, 4:39pm UTC](https://discuss.elastic.co/t/problem-grok-pattern/82200/1 "2017-04-12T16:39:07Z")

</div>

Hi all,

I'm issuing a problem while using filter grok. For instance, i'm trying to parse nginx logs using this pattern:

```
NGUSERNAME [a-zA-Z\.\@\-\+_%]+
NGUSER %{NGUSERNAME}
NGINXACCESS %{IPORHOST:clientip} %{NGUSER:ident} %{NGUSER:auth} \[%{HTTPDATE:timestamp}\] "%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}" %{NUMBER:response} (?:%{NUMBER:bytes}|-) (?:"(?:%{URI:referrer}|-)"|%{Q S:referrer}) %{QS:agent} %{QS:xforwardedfor} %{IPORHOST:host} %{BASE10NUM:request_duration}       

```

I'm pretty sure other people use this pattern for nginx log, it's pretty standard.

Because grok doesn't ship with this pattern by default, i'm using this configuration:

```
   filter{
           if [type] == "proxy_nginx" {
                   grok {
                           patterns_dir => "/etc/logstash/patterns"
                           match => { "message" => "%{NGINXACCESS}"}
                           add_field => {"index_name" => "nginx"}
                           add_tag => ["output_elastic"]
             }
           }
  }

```

I'm using the patterns\_dir to tell logstash where to look for the pattern... it's not working and I have \_grokparsefailure...

Here is an example log:

`10.55.6.104 - - [2017-04-12T16:31:07+00:00] \"GET /check HTTP/1.1\" 200 0 \"-\" \"ELB-HealthChecker/2.0\"`

---

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [April 13, 2017, 12:25am UTC](https://discuss.elastic.co/t/problem-grok-pattern/82200/2 "2017-04-13T00:25:36Z")

</div>

I would test your custom pattern with [https://grokdebug.herokuapp.com](https://grokdebug.herokuapp.com)

see if it works there, though it is odd to see " in the log lines normally it is just a " and I presume that will not match

---

<div class="post-metadata">

**Author:** ![Vittorio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vittorio/32/18171_2.png) [@Vittorio](https://discuss.elastic.co/u/Vittorio)\
**Post date:** [April 13, 2017, 7:43am UTC](https://discuss.elastic.co/t/problem-grok-pattern/82200/3 "2017-04-13T07:43:02Z")

</div>

sorry, this is the log, that one was the one already parsed by elasticsearch.

`10.55.10.68 - - [2017-04-13T07:42:09+00:00] "GET /check HTTP/1.1" 200 0 "-" "ELB-HealthChecker/2.0"`

---

<div class="post-metadata">

**Author:** ![Vittorio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vittorio/32/18171_2.png) [@Vittorio](https://discuss.elastic.co/u/Vittorio)\
**Post date:** [April 13, 2017, 9:22am UTC](https://discuss.elastic.co/t/problem-grok-pattern/82200/4 "2017-04-13T09:22:37Z")

</div>

I made it work, the error was in the pattern. Thanks @eperry for the suggestion.

but now my doubt is why in elasticsearch i have the field like this?

`"agent": "\"ELB-HealthChecker/2.0\""`

Why elastic is putting a `\"` before and after the agent name? thanks

---

<div class="post-metadata">

**Author:** ![Vittorio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vittorio/32/18171_2.png) [@Vittorio](https://discuss.elastic.co/u/Vittorio)\
**Post date:** [April 14, 2017, 9:03am UTC](https://discuss.elastic.co/t/problem-grok-pattern/82200/5 "2017-04-14T09:03:36Z")

</div>

nobody know why i have this output in elasticsearch?

---

<div class="post-metadata">

**Author:** ![Vittorio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vittorio/32/18171_2.png) [@Vittorio](https://discuss.elastic.co/u/Vittorio)\
**Post date:** [April 14, 2017, 9:29am UTC](https://discuss.elastic.co/t/problem-grok-pattern/82200/6 "2017-04-14T09:29:28Z")

</div>

I found the problem, is elasticsearch that automatically maps strings. So it is using \ for escaping the " and consider the agent a string.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 12, 2017, 9:35am UTC](https://discuss.elastic.co/t/problem-grok-pattern/82200/7 "2017-05-12T09:35:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
