# Provided Grok patterns do not match data in the input

**URL:** <https://discuss.elastic.co/t/provided-grok-patterns-do-not-match-data-in-the-input/270265>\
**Category:** Logstash\
**Created:** [April 15, 2021, 3:20pm UTC](https://discuss.elastic.co/t/provided-grok-patterns-do-not-match-data-in-the-input/270265 "2021-04-15T15:20:44Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cris\_R](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cris_r/32/87133_2.png) [@Cris\_R](https://discuss.elastic.co/u/Cris_R)\
**Post date:** [April 15, 2021, 3:20pm UTC](https://discuss.elastic.co/t/provided-grok-patterns-do-not-match-data-in-the-input/270265/1 "2021-04-15T15:20:44Z")

</div>

Hi,  
Trying to create my own grok patterns, I'm using the following with the Grok Debugger :  
Sample data :  
`[4812 6032][15 Feb 18:23:15][LdManInit] Loading Library in Load mode`  
Grok Pattern :  
`%{IDLOG:whom} %{TIMEST:when} %{LOGCAT:what}`  
Custom patterns :  
`IDLOG ^\[.([0-9]{4,6}.[0-9]{4,6})\] TIMEST \[([0-9]{1,2}.[a-zA-Z]{3}.*[0-9])\] LOGCAT \]\[(.[a-zA-Z]*.)\]|\]\[\]`

Which returns the error above.  
But if I'm using only one pattern (IDLOG, TIMEST, LOGCAT) at onces, they work perfectly...

Any idea that could help me to debug this ?  
Many thanks in advance,  
Chris

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 15, 2021, 4:26pm UTC](https://discuss.elastic.co/t/provided-grok-patterns-do-not-match-data-in-the-input/270265/2 "2021-04-15T16:26:35Z")

</div>

You pattern has spaces between the three items, your message does not. Also, TIMEST has consumed the ] after the timestamp, so LOGCAT does not have anything to match the "\]" that it starts with. This works...

```
input { generator { count => 1 lines => ['[ 4812 6032][15 Feb 18:23:15][LdManInit] Loading Library in Load mode' ] } }
filter {
    grok {
        pattern_definitions => {
            IDLOG => "^\[.([0-9]{4,6}.[0-9]{4,6})\]"
            TIMEST => "\[([0-9]{1,2}.[a-zA-Z]{3}.*[0-9])\]"
            LOGCAT => "\[(.[a-zA-Z]*.)\]|\]\[\]"
        }
        match => { "message" => "%{IDLOG:whom}%{TIMEST:when}%{LOGCAT:what}" }
    }
}
```

---

<div class="post-metadata">

**Author:** ![Cris\_R](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cris_r/32/87133_2.png) [@Cris\_R](https://discuss.elastic.co/u/Cris_R)\
**Post date:** [April 15, 2021, 5:05pm UTC](https://discuss.elastic.co/t/provided-grok-patterns-do-not-match-data-in-the-input/270265/3 "2021-04-15T17:05:10Z")

</div>

> [@Badger](#):
>
> pattern has spaces betw

Hi, thanks a lot indeed for this rapid answer.

You are right, I started so (without spaces) but still without spaces, the debug screen does not work.

I will try now using directly logstash, does it means that the debugger works differently from the routine ?

Chris

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 15, 2021, 5:18pm UTC](https://discuss.elastic.co/t/provided-grok-patterns-do-not-match-data-in-the-input/270265/4 "2021-04-15T17:18:03Z")

</div>

> [@Cris\_R](#):
>
> does it means that the debugger works differently from the routine ?

I have certainly seen cases where kibana and the Heroku debugger parse things differently to logstash (kibana does multiline matching of GREEDYDATA differently, for example). I do not use them, instead I debug grok patterns using grok as detailed [here](https://discuss.elastic.co/t/help-needed-in-grok/213827/2).

---

<div class="post-metadata">

**Author:** ![Cris\_R](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cris_r/32/87133_2.png) [@Cris\_R](https://discuss.elastic.co/u/Cris_R)\
**Post date:** [April 16, 2021, 6:57am UTC](https://discuss.elastic.co/t/provided-grok-patterns-do-not-match-data-in-the-input/270265/5 "2021-04-16T06:57:17Z")

</div>

Thanks a lot, it worked perfectly... no more use of Grok Debugger 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 14, 2021, 6:57am UTC](https://discuss.elastic.co/t/provided-grok-patterns-do-not-match-data-in-the-input/270265/6 "2021-05-14T06:57:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
