# Timeout executing grok 5.4.3

**URL:** <https://discuss.elastic.co/t/timeout-executing-grok-5-4-3/92222>\
**Category:** Logstash\
**Created:** [July 7, 2017, 7:49am UTC](https://discuss.elastic.co/t/timeout-executing-grok-5-4-3/92222 "2017-07-07T07:49:45Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![steveng](https://avatars.discourse-cdn.com/v4/letter/s/6de8d8/32.png) [@steveng](https://discuss.elastic.co/u/steveng)\
**Post date:** [July 7, 2017, 7:49am UTC](https://discuss.elastic.co/t/timeout-executing-grok-5-4-3/92222/1 "2017-07-07T07:49:45Z")

</div>

Hi,

I send with Filebeat the file  
/usr/local/tomcat/current/logs/filieredistribution\_vodpublish.log  
in Logstash.

I want to extract the filename without extension like this :

```
  grok {
          match => { "source" => ["%{PATH}/%{GREEDYDATA:logfile}\."] }
  }

```

When I try on [https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/), it's ok :

```
{
  "UNIXPATH": [
    [
      "/usr/local/tomcat/current/logs"
    ]
  ],
  "logfile": [
    [
      "filieredistribution_vodpublish"
    ]
  ]
}

```

but in Logstash, I have this error :

```
[2017-07-07T09:22:22,333][WARN][logstash.filters.grok] Timeout executing grok '%{UNIXPATH}/%{GREEDYDATA:logfile}\.' against field 'source' with value '/usr/local/tomcat/current/logs/filieredistribution_vodpublish.log'!
[2017-07-07T09:22:22,333][WARN][logstash.filters.grok] Timeout executing grok '%{UNIXPATH}/%{GREEDYDATA:logfile}\.' against field 'source' with value '/usr/local/tomcat/current/logs/filieredistribution_vodpublish.log'!

```

I use Logstash and FileBeat in version 5.4.3.

I don't understand, can you help me ?

Thanks

---

<div class="post-metadata">

**Author:** ![steveng](https://avatars.discourse-cdn.com/v4/letter/s/6de8d8/32.png) [@steveng](https://discuss.elastic.co/u/steveng)\
**Post date:** [July 7, 2017, 10:16am UTC](https://discuss.elastic.co/t/timeout-executing-grok-5-4-3/92222/2 "2017-07-07T10:16:46Z")

</div>

If I rename the file **filieredistribution\_vodpublish.log** in **filier\_publish.log** , I don't have error.  
And I can see the field logfile :

```
"_source": {
             ...
              "offset": 16179,
              "level": "INFO",
              "logfile": "filier_publish",
              "input_type": "log",
              "source": "/usr/local/tomcat/current/logs/filier_publish.log",
              ...
}

```

Somebody can explain me where is the problem ?

---

<div class="post-metadata">

**Author:** ![steveng](https://avatars.discourse-cdn.com/v4/letter/s/6de8d8/32.png) [@steveng](https://discuss.elastic.co/u/steveng)\
**Post date:** [July 13, 2017, 9:47am UTC](https://discuss.elastic.co/t/timeout-executing-grok-5-4-3/92222/3 "2017-07-13T09:47:58Z")

</div>

I changed the way to find the filename of my logs :

```
grok {
       match => { "source" => ["%{PATH}/%{GREEDYDATA:logfile}\."] }
}

```

in

```
ruby {
      code => "
            filename = event.get('[source]').split('/').last
            event.set('logfile',filename.split('.').first)
       "
}

```

It's much faster !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2017, 9:48am UTC](https://discuss.elastic.co/t/timeout-executing-grok-5-4-3/92222/4 "2017-08-10T09:48:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
