# Seeing Grok regexp exception "incompatible encoding regexp match (UTF-8 regexp with ASCII-8BIT string)"

**URL:** <https://discuss.elastic.co/t/seeing-grok-regexp-exception-incompatible-encoding-regexp-match-utf-8-regexp-with-ascii-8bit-string/120084>\
**Category:** Logstash\
**Created:** [February 15, 2018, 10:22pm UTC](https://discuss.elastic.co/t/seeing-grok-regexp-exception-incompatible-encoding-regexp-match-utf-8-regexp-with-ascii-8bit-string/120084 "2018-02-15T22:22:20Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![cb2015](https://avatars.discourse-cdn.com/v4/letter/c/7993a0/32.png) [@cb2015](https://discuss.elastic.co/u/cb2015)\
**Post date:** [February 15, 2018, 10:22pm UTC](https://discuss.elastic.co/t/seeing-grok-regexp-exception-incompatible-encoding-regexp-match-utf-8-regexp-with-ascii-8bit-string/120084/1 "2018-02-15T22:22:21Z")

</div>

Hi everyone,

I am seeing this error in my logstash logs

```
[2018-02-15T10:00:48,009][WARN][logstash.filters.grok] Grok regexp threw exception {:exception=>"incompatible encoding regexp match (UTF-8 regexp with ASCII-8BIT string)", :backtrace=>["org/jruby/RubyRegexp.java:1107:in `match'"
"/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/jls-grok-0.11.4/lib/grok-pure.rb:182:in `execute'"
"/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.2/lib/logstash/filters/grok/timeout_enforcer.rb:20:in `grok_till_timeout'"
"/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.2/lib/logstash/filters/grok.rb:342:in `block in match_against_groks'"
"org/jruby/RubyArray.java:1734:in `each'"
"/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.2/lib/logstash/filters/grok.rb:339:in `match_against_groks'"
"/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.2/lib/logstash/filters/grok.rb:328:in `match'"
"/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.2/lib/logstash/filters/grok.rb:296:in `block in filter'"
"org/jruby/RubyHash.java:1343:in `each'"
"/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.2/lib/logstash/filters/grok.rb:295:in `filter'"
"/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:145:in `do_filter'"
"/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:164:in `block in multi_filter'"
"org/jruby/RubyArray.java:1734:in `each'"
"/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:161:in `multi_filter'"
"/usr/share/logstash/logstash-core/lib/logstash/filter_delegator.rb:47:in `multi_filter'"
"(eval):18987:in `block in initialize'"
"org/jruby/RubyArray.java:1734:in `each'"
"(eval):18984:in `block in initialize'"
"(eval):3140:in `block in filter_func'"
"/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:447:in `filter_batch'"
"/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:426:in `worker_loop'"
"/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:385:in `block in start_workers'"], :class=>"Encoding::CompatibilityError

```

The interesting part of the error seems to be  
`incompatible encoding regexp match (UTF-8 regexp with ASCII-8BIT string)`

I believe (though have not completely proven) it is being thrown because of this character : ®

Is there a way to configure grok to deal with this character?  
Logstash is not dropping the offending log lines, it is just not parsing them.

If a grok-configuration fix is not possible work around suggestions are welcome, though I can't stop that character from appearing in my app logs, as it is put there by a user's input.

---

<div class="post-metadata">

**Author:** ![r.weires](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/r.weires/32/27914_2.png) [@r.weires](https://discuss.elastic.co/u/r.weires)\
**Post date:** [February 20, 2018, 10:08am UTC](https://discuss.elastic.co/t/seeing-grok-regexp-exception-incompatible-encoding-regexp-match-utf-8-regexp-with-ascii-8bit-string/120084/2 "2018-02-20T10:08:36Z")

</div>

Same problem here, we've got a "μ" in a grok regex causing this, resulting in a stacktrace very similar to above.

The issue only appeared for us only after upgrading logstash. The problem was not present in 6.0.1, but at least appears for us with 6.1.1 (same on 6.2.1), installed via [https://artifacts.elastic.co/packages/6.x/apt](https://artifacts.elastic.co/packages/6.x/apt) on Ubuntu.

Stacktrace for us:

> [2018-02-20T09:26:45,504][WARN][logstash.filters.grok] Grok regexp threw exception {:exception=\>"incompatible encoding regexp match (UTF-8 regexp with ASCII-8BIT string)", :backtrace=\>["org/jruby/RubyRegexp.java:1107:in `match'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/jls-grok-0.11.4/lib/grok-pure.rb:182:in `execute'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.1/lib/logstash/filters/grok/timeout\_enforcer.rb:20:in `grok_till_timeout'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.1/lib/logstash/filters/grok.rb:347:in `block in match\_against\_groks'", "org/jruby/RubyArray.java:1734:in `each'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.1/lib/logstash/filters/grok.rb:344:in `match\_against\_groks'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.1/lib/logstash/filters/grok.rb:333:in `match'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.1/lib/logstash/filters/grok.rb:301:in `block in filter'", "org/jruby/RubyHash.java:1343:in `each'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/logstash-filter-grok-4.0.1/lib/logstash/filters/grok.rb:300:in `filter'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:145:in `do_filter'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:164:in `block in multi\_filter'", "org/jruby/RubyArray.java:1734:in `each'", "/usr/share/logstash/logstash-core/lib/logstash/filters/base.rb:161:in `multi\_filter'", "/usr/share/logstash/logstash-core/lib/logstash/filter\_delegator.rb:48:in `multi_filter'", "(eval):823:in `block in initialize'", "org/jruby/RubyArray.java:1734:in `each'", "(eval):808:in `block in initialize'", "(eval):524:in `block in filter_func'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:455:in `filter\_batch'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:434:in `worker_loop'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:393:in `block in start\_workers'"], :class=\>"Encoding::CompatibilityError"}

---

<div class="post-metadata">

**Author:** ![cb2015](https://avatars.discourse-cdn.com/v4/letter/c/7993a0/32.png) [@cb2015](https://discuss.elastic.co/u/cb2015)\
**Post date:** [February 20, 2018, 6:02pm UTC](https://discuss.elastic.co/t/seeing-grok-regexp-exception-incompatible-encoding-regexp-match-utf-8-regexp-with-ascii-8bit-string/120084/3 "2018-02-20T18:02:44Z")

</div>

I believe that we only started seeing this happen in 6.2, but we don't have logs going back before we upgraded, so I can't confirm.

---

<div class="post-metadata">

**Author:** ![neu5ron](https://avatars.discourse-cdn.com/v4/letter/n/0ea827/32.png) [@neu5ron](https://discuss.elastic.co/u/neu5ron)\
**Post date:** [February 21, 2018, 3:00pm UTC](https://discuss.elastic.co/t/seeing-grok-regexp-exception-incompatible-encoding-regexp-match-utf-8-regexp-with-ascii-8bit-string/120084/4 "2018-02-21T15:00:54Z")

</div>

I as well am receiving this error on 6.2 and no errors previously on 5 or 6.0 or 6.1

---

<div class="post-metadata">

**Author:** ![winpat](https://avatars.discourse-cdn.com/v4/letter/w/51bf81/32.png) [@winpat](https://discuss.elastic.co/u/winpat)\
**Post date:** [March 7, 2018, 12:55pm UTC](https://discuss.elastic.co/t/seeing-grok-regexp-exception-incompatible-encoding-regexp-match-utf-8-regexp-with-ascii-8bit-string/120084/6 "2018-03-07T12:55:09Z")

</div>

Same here. Never had a problem with encoding until 6.2.x.

---

<div class="post-metadata">

**Author:** ![cb2015](https://avatars.discourse-cdn.com/v4/letter/c/7993a0/32.png) [@cb2015](https://discuss.elastic.co/u/cb2015)\
**Post date:** [March 9, 2018, 6:30pm UTC](https://discuss.elastic.co/t/seeing-grok-regexp-exception-incompatible-encoding-regexp-match-utf-8-regexp-with-ascii-8bit-string/120084/7 "2018-03-09T18:30:43Z")

</div>

For everyone who hasnt posted what character appears to be breaking their parsing, could you?

---

<div class="post-metadata">

**Author:** ![brendan](https://avatars.discourse-cdn.com/v4/letter/b/50afbb/32.png) [@brendan](https://discuss.elastic.co/u/brendan)\
**Post date:** [March 13, 2018, 12:42pm UTC](https://discuss.elastic.co/t/seeing-grok-regexp-exception-incompatible-encoding-regexp-match-utf-8-regexp-with-ascii-8bit-string/120084/8 "2018-03-13T12:42:19Z")

</div>

I am having the same problem with log entries with the micro second symbol µ.

I was originally using 6.1.3. I upgraded to 6.2.2 but the problem remains. Same errors in the logs.

Anyone come up with a work around?

---

<div class="post-metadata">

**Author:** ![smbullet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/smbullet/32/27833_2.png) [@smbullet](https://discuss.elastic.co/u/smbullet)\
**Post date:** [April 4, 2018, 7:08pm UTC](https://discuss.elastic.co/t/seeing-grok-regexp-exception-incompatible-encoding-regexp-match-utf-8-regexp-with-ascii-8bit-string/120084/9 "2018-04-04T19:08:05Z")

</div>

Did anyone figure out what the issue is?

---

<div class="post-metadata">

**Author:** ![cb2015](https://avatars.discourse-cdn.com/v4/letter/c/7993a0/32.png) [@cb2015](https://discuss.elastic.co/u/cb2015)\
**Post date:** [April 5, 2018, 3:52pm UTC](https://discuss.elastic.co/t/seeing-grok-regexp-exception-incompatible-encoding-regexp-match-utf-8-regexp-with-ascii-8bit-string/120084/10 "2018-04-05T15:52:32Z")

</div>

I have not found a solution.

We are just eating the errors for now.

---

<div class="post-metadata">

**Author:** ![joshiegy](https://avatars.discourse-cdn.com/v4/letter/j/848f3c/32.png) [@joshiegy](https://discuss.elastic.co/u/joshiegy)\
**Post date:** [April 5, 2018, 6:14pm UTC](https://discuss.elastic.co/t/seeing-grok-regexp-exception-incompatible-encoding-regexp-match-utf-8-regexp-with-ascii-8bit-string/120084/11 "2018-04-05T18:14:01Z")

</div>

I to am getting this error. I have Swedish characters in some logs (Å Ä Ö).

---

<div class="post-metadata">

**Author:** ![Armin\_Braun](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/armin_braun/32/20092_2.png) [@Armin\_Braun](https://discuss.elastic.co/u/Armin_Braun)\
**Post date:** [April 17, 2018, 9:07am UTC](https://discuss.elastic.co/t/seeing-grok-regexp-exception-incompatible-encoding-regexp-match-utf-8-regexp-with-ascii-8bit-string/120084/12 "2018-04-17T09:07:11Z")

</div>

We are aware of this issue and it has been fixed already in [https://github.com/elastic/logstash/pull/9307](https://github.com/elastic/logstash/pull/9307).  
The fix will be included in the upcoming release (version 6.2.4).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 15, 2018, 9:07am UTC](https://discuss.elastic.co/t/seeing-grok-regexp-exception-incompatible-encoding-regexp-match-utf-8-regexp-with-ascii-8bit-string/120084/13 "2018-05-15T09:07:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
