# Provided Grok patterns do not match data in the input

**URL:** <https://discuss.elastic.co/t/provided-grok-patterns-do-not-match-data-in-the-input/213601>\
**Category:** Logstash\
**Created:** [January 2, 2020, 5:02pm UTC](https://discuss.elastic.co/t/provided-grok-patterns-do-not-match-data-in-the-input/213601 "2020-01-02T17:02:41Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yasso](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yasso/32/60173_2.png) [@Yasso](https://discuss.elastic.co/u/Yasso)\
**Post date:** [January 2, 2020, 5:02pm UTC](https://discuss.elastic.co/t/provided-grok-patterns-do-not-match-data-in-the-input/213601/1 "2020-01-02T17:02:41Z")

</div>

hello guys  
i want to parse that log :  
55.3.244.1 GET /index.html 10024 0.043 [2012-01-31 07:19:54]  
when i'm using this patters :  
%{IP:client} %{WORD:method} %{URIPATHPARAM:request} %{NUMBER:bytes} %{NUMBER:duration}  
i get that result :  
{  
"duration": "0.043",  
"request": "/index.html",  
"method": "GET",  
"bytes": "10024",  
"client": "55.3.244.1"  
}  
-but my probleme is when i want to get the timestampe of that log by this patterns :  
%{TIMESTAMP\_ISO8601:timestamp} %{IP:client} %{WORD:method} %{URIPATHPARAM:request} %{NUMBER:bytes} %{NUMBER:duration}  
-it says Provided Grok patterns do not match data in the input  
please a need a help ..thanks in advance

---

<div class="post-metadata">

**Author:** ![E04](https://avatars.discourse-cdn.com/v4/letter/e/7ea924/32.png) [@E04](https://discuss.elastic.co/u/E04)\
**Post date:** [January 2, 2020, 9:44pm UTC](https://discuss.elastic.co/t/provided-grok-patterns-do-not-match-data-in-the-input/213601/2 "2020-01-02T21:44:52Z")

</div>

Since your timestamp is at the end of your message you will need to add the timestamp at the end of your GROK statement rather than at the beginning. Also ensuring that you escape the brackets encapsulating your timestamp:

> %{IP:client} %{WORD:method} %{URIPATHPARAM:request} %{NUMBER:bytes} %{NUMBER:duration} \[%{TIMESTAMP\_ISO8601:timestamp}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 2, 2020, 9:45pm UTC](https://discuss.elastic.co/t/provided-grok-patterns-do-not-match-data-in-the-input/213601/3 "2020-01-02T21:45:14Z")

</div>

You show the timestamp at the end of the record but have added a pattern for it at the beginning. That is not going to work.

---

<div class="post-metadata">

**Author:** ![Yasso](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yasso/32/60173_2.png) [@Yasso](https://discuss.elastic.co/u/Yasso)\
**Post date:** [January 3, 2020, 4:20pm UTC](https://discuss.elastic.co/t/provided-grok-patterns-do-not-match-data-in-the-input/213601/4 "2020-01-03T16:20:45Z")

</div>

thank you for replying.  
i have put it at the end .. but it still says : Provided Grok patterns do not match data in the input  
thanks in advance

---

<div class="post-metadata">

**Author:** ![Rob\_wylde](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rob_wylde/32/58231_2.png) [@Rob\_wylde](https://discuss.elastic.co/u/Rob_wylde)\
**Post date:** [January 5, 2020, 4:27am UTC](https://discuss.elastic.co/t/provided-grok-patterns-do-not-match-data-in-the-input/213601/5 "2020-01-05T04:27:38Z")

</div>

`%{IP:client} %{WORD:method} %{URIPATHPARAM:request} %{NUMBER:bytes} %{NUMBER:duration} \[%{TIMESTAMP_ISO8601:timestamp} \]`

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/e/8ebdc65d1ee156782c7a33332bf0da9e7365c5ee.png)

The issue here is the need to escape the square brackets.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 2, 2020, 4:27am UTC](https://discuss.elastic.co/t/provided-grok-patterns-do-not-match-data-in-the-input/213601/6 "2020-02-02T04:27:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
