# Squid pipeline returns 'RegexpError: unmatched close parenthesis'

**URL:** <https://discuss.elastic.co/t/squid-pipeline-returns-regexperror-unmatched-close-parenthesis/181612>\
**Category:** Logstash\
**Created:** [May 17, 2019, 2:21pm UTC](https://discuss.elastic.co/t/squid-pipeline-returns-regexperror-unmatched-close-parenthesis/181612 "2019-05-17T14:21:27Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![netoeuler](https://avatars.discourse-cdn.com/v4/letter/n/c2a13f/32.png) [@netoeuler](https://discuss.elastic.co/u/netoeuler)\
**Post date:** [May 17, 2019, 2:21pm UTC](https://discuss.elastic.co/t/squid-pipeline-returns-regexperror-unmatched-close-parenthesis/181612/1 "2019-05-17T14:21:27Z")

</div>

Hi!

I'm trying to use the ELK 7.0 to monitor squid traffic. The connection is ok but I'm sending the traffic directly to Elasticsearch because I'm having problem to create a grok filter to it.

The pipeline looks like this:

> input {  
> beats {  
> port =\> 5044  
> }  
> }
> 
> filter {  
> grok {  
> match =\> { "message" =\> "%{POSINT:timestamp}.%{POSINT:timestamp\_ms}\s+%{NUMBER:response\_time} %{IP:src\_ip} %{WORD:squid\_request\_status}/%{NUMBER:http\_status\_code} %{NUMBER:reply\_size\_include\_header} %{WORD:http\_method} %{WORD:request\_url} %{NOTSPACE:user} %{WORD:squid}/%{IP:server\_ip}) %{NOTSPACE:content\_type}" }  
> }  
> }
> 
> output {  
> elasticsearch {  
> hosts =\> ["10.26.1.46:9200"]  
> }  
> }

But when I restart the logstash service, the log shows me the error:

> [ERROR][logstash.javapipeline] Pipeline aborted due to error {:pipeline\_id=\>"main", :exception=\>#\<RegexpError: unmatched close parenthesis: /(?POSINT:timestamp\b(?:[1-9][0-9]_)\b).(?POSINT:timestamp\_ms\b(?:[1-9][0-9]_)\b)\s+(?NUMBER:response\_time(?:(?:(?\<![0-9.+-])(?\>[+-]?(?:(?:[0-9]+(?:.[0-9]+)?)|(?:.[0-9]+)))))) (?IP:src\_ip(?:(?:((([0-9A-Fa-f]{1,4}:){7}([0-9A-Fa-f]{1,4}|:))|(([0-9A-Fa-f]{1,4}:){6}(:[0-9A-Fa-f]{1,4}|((25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)(.(25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)){3})|:))|(([0-9A-Fa-f]{1,4}:){5}(((:[0-9A-Fa-f]{1,4}){1,2})|:((25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)(.(25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)){3})|:))|(([0-9A-Fa-f]{1,4}:){4}(((:[0-9A-Fa-f]{1,4}){1,3})|((:[0-9A-Fa-f]{1,4})?:((25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)(.(25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)){3}))|:))|(([0-9A-Fa-f]{1,4}:){3}(((:[0-9A-Fa-f]{1,4}){1,4})|((:[0-9A-Fa-f]{1,4}){0,2}:((25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)(.(25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)){3}))|:))|(([0-9A-Fa-f]{1,4}:){2}(((:[0-9A-Fa-f]{1,4}){1,5})|((:[0-9A-Fa-f]{1,4}){0,3}:((25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)(.(25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)){3}))|:))|(([0-9A-Fa-f]{1,4}:){1}(((:[0-9A-Fa-f]{1,4}){1,6})|((:[0-9A-Fa-f]{1,4}){0,4}:((25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)(.(25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)){3}))|:))|(:(((:[0-9A-Fa-f]{1,4}){1,7})|((:[0-9A-Fa-f]{1,4}){0,5}:((25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)(.(25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)){3}))|:)))(%.+)?)|(?:(?\<![0-9])(?:(?:[0-1]?[0-9]{1,2}|2[0-4][0-9]|25[0-5])...)(?![0-9])))) (?WORD:squid\_request\_status\b\w+\b)/(?NUMBER:http\_status\_code(?:(?:(?\<![0-9.+-])(?\>[+-]?(?:(?:[0-9]+(?:.[0-9]+)?)|(?:.[0-9]+)))))) (?NUMBER:reply\_size\_include\_header(?:(?:(?\<![0-9.+-])(?\>[+-]?(?:(?:[0-9]+(?:.[0-9]+)?)|(?:.[0-9]+)))))) (?WORD:http\_method\b\w+\b) (?WORD:request\_url\b\w+\b) (?NOTSPACE:user\S+) (?WORD:squid\b\w+\b)/(?IP:server\_ip(?:(?:((([0-9A-Fa-f]{1,4}:){7}([0-9A-Fa-f]{1,4}|:))|(([0-9A-Fa-f]{1,4}:){6}(:[0-9A-Fa-f]{1,4}|((25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)(.(25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)){3})|:))|(([0-9A-Fa-f]{1,4}:){5}(((:[0-9A-Fa-f]{1,4}){1,2})|:((25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)(.(25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)){3})|:))|(([0-9A-Fa-f]{1,4}:){4}(((:[0-9A-Fa-f]{1,4}){1,3})|((:[0-9A-Fa-f]{1,4})?:((25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)(.(25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)){3}))|:))|(([0-9A-Fa-f]{1,4}:){3}(((:[0-9A-Fa-f]{1,4}){1,4})|((:[0-9A-Fa-f]{1,4}){0,2}:((25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)(.(25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)){3}))|:))|(([0-9A-Fa-f]{1,4}:){2}(((:[0-9A-Fa-f]{1,4}){1,5})|((:[0-9A-Fa-f]{1,4}){0,3}:((25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)(.(25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)){3}))|:))|(([0-9A-Fa-f]{1,4}:){1}(((:[0-9A-Fa-f]{1,4}){1,6})|((:[0-9A-Fa-f]{1,4}){0,4}:((25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)(.(25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)){3}))|:))|(:(((:[0-9A-Fa-f]{1,4}){1,7})|((:[0-9A-Fa-f]{1,4}){0,5}:((25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)(.(25[0-5]|2[0-4]\d|1\d\d|[1-9]?\d)){3}))|:)))(%.+)?)|(?:(?\<![0-9])(?:(?:[0-1]?[0-9]{1,2}|2[0-4][0-9]|25[0-5])...)(?![0-9]))))) (?NOTSPACE:content\_type\S+)/m\>, :backtrace=\>["org/jruby/RubyRegexp.java:940:in `initialize'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/jls-grok-0.11.5/lib/grok-pure.rb:127:in `compile'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-grok-4.0.4/lib/logstash/filters/grok.rb:281:in `block in register'", "org/jruby/RubyArray.java:1792:in `each'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-grok-4.0.4/lib/logstash/filters/grok.rb:275:in `block in register'", "org/jruby/RubyHash.java:1419:in `each'", "/usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-filter-grok-4.0.4/lib/logstash/filters/grok.rb:270:in `register'", "org/logstash/config/ir/compiler/AbstractFilterDelegatorExt.java:56:in `register'", "/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:191:in `block in register_plugins'", "org/jruby/RubyArray.java:1792:in `each'", "/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:190:in `register_plugins'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:446:in `maybe\_setup\_out\_plugins'", "/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:203:in `start_workers'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:145:in `run'", "/usr/share/logstash/logstash-core/lib/logstash/java\_pipeline.rb:104:in `block in start'"], :thread=\>"#\<Thread:0x4f31db7b run\>"}

I have already tested the filter in the Grok Debugger and it works. So, I'm trying to find the reason of the error but I'm stuck.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2019, 2:21pm UTC](https://discuss.elastic.co/t/squid-pipeline-returns-regexperror-unmatched-close-parenthesis/181612/2 "2019-06-14T14:21:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
