# Problem with Grok debugger

**URL:** <https://discuss.elastic.co/t/problem-with-grok-debugger/121333>\
**Category:** Logstash\
**Created:** [February 24, 2018, 9:55am UTC](https://discuss.elastic.co/t/problem-with-grok-debugger/121333 "2018-02-24T09:55:37Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [February 24, 2018, 9:55am UTC](https://discuss.elastic.co/t/problem-with-grok-debugger/121333/1 "2018-02-24T09:55:38Z")

</div>

Hello  
I have the problem with the Grok debugger.

I'm reading your post [https://www.elastic.co/blog/grokking-the-linux-authorization-logs](https://www.elastic.co/blog/grokking-the-linux-authorization-logs) and I try to parse this sample line

Feb 21 21:56:12 localhost sshd[3430]: Invalid user test from 10.0.2.2

with this pattern

%{SYSLOGTIMESTAMP:system.auth.timestamp} %{SYSLOGHOST:system.auth.hostname} sshd(?:\[%{POSINT:system.auth.pid}\])?: %{DATA:system.auth.ssh.event} user %{DATA:system.auth.user} from %{IPORHOST:system.auth.ip}

but I have the message **No match** from [http://grokdebug.herokuapp.com/](http://grokdebug.herokuapp.com/)

I'm trying with the Kibana debugger (I have the 6.2.1 version), but I have the same problem.

If I break the string in two, the first string before the ":" and the second string after the ":" it works, why?

Thank you for attention  
Franco

---

<div class="post-metadata">

**Author:** ![Makra](https://avatars.discourse-cdn.com/v4/letter/m/8491ac/32.png) [@Makra](https://discuss.elastic.co/u/Makra)\
**Post date:** [February 24, 2018, 2:43pm UTC](https://discuss.elastic.co/t/problem-with-grok-debugger/121333/2 "2018-02-24T14:43:49Z")

</div>

Hi  
@franco.federico

The pattern is working in [http://grokdebug.herokuapp.com/](http://grokdebug.herokuapp.com/)  
Probably you have a new line character at the end of pattern.

---

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [February 24, 2018, 3:26pm UTC](https://discuss.elastic.co/t/problem-with-grok-debugger/121333/3 "2018-02-24T15:26:47Z")

</div>

> [@franco.federico](#):
>
> %{SYSLOGTIMESTAMP:system.auth.timestamp} %{SYSLOGHOST:system.auth.hostname} sshd(?:[%{POSINT:system.auth.pid}])?: %{DATA:system.auth.ssh.event} user %{DATA:system.auth.user} from %{IPORHOST:system.auth.ip}

Thank you Makra! It's incredible, now I'm copying and pasting the string in the grokdebugger and it goes on.

I try the same string in the grok debug on kibana and now it goes on.

Thank you for quickly response.

I'm continuing with the sample showed in the post that I link.  
Bye  
Franco

---

<div class="post-metadata">

**Author:** ![franco.federico](https://avatars.discourse-cdn.com/v4/letter/f/67e7ee/32.png) [@franco.federico](https://discuss.elastic.co/u/franco.federico)\
**Post date:** [February 24, 2018, 3:52pm UTC](https://discuss.elastic.co/t/problem-with-grok-debugger/121333/4 "2018-02-24T15:52:42Z")

</div>

I found the error

This one goes on

%{SYSLOGTIMESTAMP:system.auth.timestamp} %{SYSLOGHOST:system.auth.hostname} sshd(?:[%{POSINT:system.auth.pid}])?: %{DATA:system.auth.ssh.event} user %{DATA:system.auth.user} from %{IPORHOST:system.auth.ip}

Instead of this that is wrong for grokdebugger

%{SYSLOGTIMESTAMP:system.auth.timestamp} %{SYSLOGHOST:system.auth.hostname} sshd(?:\[%{POSINT:system.auth.pid}\])?: %{DATA:system.auth.ssh.event} user %{DATA:system.auth.user} from %{IPORHOST:system.auth.ip}

If you look there are "\" instead of "". Why?

Thank you again  
Franco

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 24, 2018, 3:52pm UTC](https://discuss.elastic.co/t/problem-with-grok-debugger/121333/5 "2018-03-24T15:52:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
