# Timeout executing grok error on LS docker container

**URL:** <https://discuss.elastic.co/t/timeout-executing-grok-error-on-ls-docker-container/169630>\
**Category:** Logstash\
**Created:** [February 22, 2019, 8:15pm UTC](https://discuss.elastic.co/t/timeout-executing-grok-error-on-ls-docker-container/169630 "2019-02-22T20:15:48Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jwalls](https://avatars.discourse-cdn.com/v4/letter/j/0ea827/32.png) [@jwalls](https://discuss.elastic.co/u/jwalls)\
**Post date:** [February 22, 2019, 8:15pm UTC](https://discuss.elastic.co/t/timeout-executing-grok-error-on-ls-docker-container/169630/1 "2019-02-22T20:15:48Z")

</div>

I'm running a docker container using LS 6.5.4, but in the docker logs I am getting these errors

```
Timeout executing grok '%{USERNAME:level}: ?%{PATH:file} %{NUMBER:line_num} %{GREEDYDATA:kvpairs}' against field 'message' with value 'INFO: --> GET https://URL_REMOVED_FOR_SECURITY/news-en/query?version=2018-08-01&query=publication_date%3E%3Dnow-18hours,publication_date%3Cnow-16hours&count=50&offset=4650 http/1.1'!
Timeout executing grok '%{USERNAME:level}: ?%{PATH:file} %{NUMBER:line_num} %{GREEDYDATA:kvpairs}' against field 'message' with value 'INFO: <-- 200 OK https://URL_REMOVED_FOR_SECURITY/news-en/query?version=2018-08-01&query=publication_date%3E%3Dnow-18hours,publication_date%3Cnow-16hours&count=50&offset=4700 (1236ms, unknown-length body)'!

```

One solution I believe would be possibly increasing the heap in the jvm options, but is there a way to do that witohut using `docker-compose?` I need to use ansible to set the container up.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 22, 2019, 9:37pm UTC](https://discuss.elastic.co/t/timeout-executing-grok-error-on-ls-docker-container/169630/2 "2019-02-22T21:37:05Z")

</div>

I do not believe increasing the heap would help. PATH is an defined as '(?:%{UNIXPATH}|%{WINPATH})', UNIXPATH is know to have severe [performance issues](https://github.com/logstash-plugins/logstash-patterns-core/issues/159). You will need to write a more efficient regexp. What are the lines you are trying to match?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2019, 9:37pm UTC](https://discuss.elastic.co/t/timeout-executing-grok-error-on-ls-docker-container/169630/3 "2019-03-22T21:37:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
