# The grok error

**URL:** <https://discuss.elastic.co/t/the-grok-error/130430>\
**Category:** Logstash\
**Created:** [May 3, 2018, 10:43am UTC](https://discuss.elastic.co/t/the-grok-error/130430 "2018-05-03T10:43:14Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Pinno\_Lin](https://avatars.discourse-cdn.com/v4/letter/p/aca169/32.png) [@Pinno\_Lin](https://discuss.elastic.co/u/Pinno_Lin)\
**Post date:** [May 3, 2018, 10:43am UTC](https://discuss.elastic.co/t/the-grok-error/130430/1 "2018-05-03T10:43:15Z")

</div>

Hi,

I have a mail log data in [mail][suser] attribute in below, i want to get user account (ABC03245) to new attribute.

jamescc\_chen@abc.com.tw;ABC03245|Jamescc Chen(James);abc:🔤:User::FIN::PD;abc:🔤:User::FIN;abc:🔤:User;abc::Abc;abc

the Grok configure in below  
grok {  
match =\> { "[mail][suser]" =\> ";%{GREEDYDATA:LoginID}\"}  
}

if add this grok condition in my config. Logstash always show error

Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, {, } at line 228

I check config many times. it not miss anything. so, i don't know what's problems??

thanks.

---

<div class="post-metadata">

**Author:** ![JohanRask](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/johanrask/32/22713_2.png) [@JohanRask](https://discuss.elastic.co/u/JohanRask)\
**Post date:** [May 3, 2018, 11:37am UTC](https://discuss.elastic.co/t/the-grok-error/130430/2 "2018-05-03T11:37:48Z")

</div>

> [@Pinno\_Lin](#):
>
> ";%{GREEDYDATA:LoginID}"

I would recommend to use [https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/) to try out your grok expressions.  
Your example gives an error due to the last backslash.

---

<div class="post-metadata">

**Author:** ![Pinno\_Lin](https://avatars.discourse-cdn.com/v4/letter/p/aca169/32.png) [@Pinno\_Lin](https://discuss.elastic.co/u/Pinno_Lin)\
**Post date:** [May 4, 2018, 1:50am UTC](https://discuss.elastic.co/t/the-grok-error/130430/3 "2018-05-04T01:50:12Z")

</div>

Hi JohanRask,

Thanks for your reply. Maybe i provide information not enough. sorry.  
I had use grokdebug website to get grok pattern. it's correct.

jamescc\_chen@abc.com.tw;ABC03245\|Jamescc Chen(James);abc:🔤:User::FIN::PD;abc:🔤:User::FIN;abc:🔤:User;abc::Abc;abc

;%{GREEDYDATA:LoginID}\\

I make a simple config below, Logstash always show the error if use the grok. i don't know where has problems??

Thank a lot.

[2018-05-04T09:34:27,665][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, {, } at line 269, column 6 (byte 6653) after filter {\n\tif "LAB" in [tags] {\n\t\tgrok {\n match =\> { "[mail][suser]" =\> ";%{GREEDYDATA:LoginID}\\"}\n }\n }\t\n}\n\noutput {\n\tif "", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:42:in `compile_imperative'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:50:in`compile\_graph'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:12:in `block in compile_sources'", "org/jruby/RubyArray.java:2486:in`map'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:11:in `compile_sources'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:51:in`initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:169:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:40:in`execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:315:in `block in converge_state'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:141:in`with\_pipelines'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:312:in `block in converge_state'", "org/jruby/RubyArray.java:1734:in`each'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:299:in `converge_state'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:166:in`block in converge\_state\_and\_update'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:141:in `with_pipelines'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:164:in`converge\_state\_and\_update'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:90:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:348:in`block in execute'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/task.rb:24:in `block in initialize'"]}

-----------------------------------------------------

 ![simple](https://us1.discourse-cdn.com/elastic/original/3X/1/e/1e0a7d0c1bf07691c40c31dd547c78edc3dda709.jpg)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 4, 2018, 1:06pm UTC](https://discuss.elastic.co/t/the-grok-error/130430/4 "2018-05-04T13:06:44Z")

</div>

I think that the problem is that

```
  "%GREEDYDATA:LoginID\\"

```

escapes the double quote, not the backslash. I am unable to find a way to escape the backslash. Not single \, not double \, not triple \.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 4, 2018, 2:40pm UTC](https://discuss.elastic.co/t/the-grok-error/130430/5 "2018-05-04T14:40:53Z")

</div>

So we have to get the backslashes away from the quotes. This works in grok

```
";%{GREEDYDATA:LoginID}\\."

```

although this would be a lot cheaper

```
dissect { mapping => "[mail][suser] => "%{};%{LoginID}\%{}" } }
```

---

<div class="post-metadata">

**Author:** ![Pinno\_Lin](https://avatars.discourse-cdn.com/v4/letter/p/aca169/32.png) [@Pinno\_Lin](https://discuss.elastic.co/u/Pinno_Lin)\
**Post date:** [May 8, 2018, 12:41am UTC](https://discuss.elastic.co/t/the-grok-error/130430/6 "2018-05-08T00:41:02Z")

</div>

Hi Badger,

```
  Thanks for you reply and suggestion. it resolve my problems.
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 5, 2018, 12:41am UTC](https://discuss.elastic.co/t/the-grok-error/130430/7 "2018-06-05T00:41:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
