# Timeout executing grok

**URL:** <https://discuss.elastic.co/t/timeout-executing-grok/269184>\
**Category:** Logstash\
**Created:** [April 4, 2021, 1:37pm UTC](https://discuss.elastic.co/t/timeout-executing-grok/269184 "2021-04-04T13:37:12Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Andrey\_RF](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrey_rf/32/86484_2.png) [@Andrey\_RF](https://discuss.elastic.co/u/Andrey_RF)\
**Post date:** [April 4, 2021, 1:37pm UTC](https://discuss.elastic.co/t/timeout-executing-grok/269184/1 "2021-04-04T13:37:12Z")

</div>

I have a quite long regex to pars my log message. But it drops with `Timeout executing grok `. Does have any mechanisms to speed up regex work? Also I have a multiple regexs and if one is failed does it other works ?

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [April 4, 2021, 1:41pm UTC](https://discuss.elastic.co/t/timeout-executing-grok/269184/2 "2021-04-04T13:41:23Z")

</div>

Have you tried to adjust the [timeout](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html#plugins-filters-grok-timeout_millis) setting?

---

<div class="post-metadata">

**Author:** ![Andrey\_RF](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrey_rf/32/86484_2.png) [@Andrey\_RF](https://discuss.elastic.co/u/Andrey_RF)\
**Post date:** [April 4, 2021, 2:40pm UTC](https://discuss.elastic.co/t/timeout-executing-grok/269184/3 "2021-04-04T14:40:39Z")

</div>

I thought about that. But I have 1M logs and I guess it will be ending in my next life

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 4, 2021, 2:48pm UTC](https://discuss.elastic.co/t/timeout-executing-grok/269184/4 "2021-04-04T14:48:49Z")

</div>

Perhaps share a few log lines and the groks... Maybe we can help tune,

Or sometimes breaking down a line with dissect first then grok the rest can help.

Or grok a part of it with the rest in GREEDYDATA (or not see below) then use one of the fields from the first grok as an identifier for more specific groks...

I.e Break it down with iterations.

Just a thought.

I'm not a regex expert though.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 4, 2021, 3:45pm UTC](https://discuss.elastic.co/t/timeout-executing-grok/269184/5 "2021-04-04T15:45:41Z")

</div>

I suggest you read [this](https://www.elastic.co/blog/do-you-grok-grok) blog. Anchor your patterns. Avoid using GREEDYDATA (try DATA, in delimited fields use custom patterns such as `(?<someField>[^,]*),` if a field ends with a comma). If you can show an example event and your patterns we can probably be more specific.

---

<div class="post-metadata">

**Author:** ![Andrey\_RF](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrey_rf/32/86484_2.png) [@Andrey\_RF](https://discuss.elastic.co/u/Andrey_RF)\
**Post date:** [April 4, 2021, 5:35pm UTC](https://discuss.elastic.co/t/timeout-executing-grok/269184/6 "2021-04-04T17:35:57Z")

</div>

Yep. It's my `filter` block

```auto
filter {
  if 'django' in [tags] {
    grok {
      match => {
        "message" => '(?m)%{LOGLEVEL:log-level} %{TIMESTAMP_ISO8601:timestamp}.*User- (?<user>[^;]+).*id - (?<user-id>[^;]+).*email - (?<email>[^;]+).*Agent-(?<useragent>[^;]+).*Request: \"(?<request>[^\s^\"]+).*Method: \"(?<method>[\w]+).*Module: (?<module>[^;]+).*Function: (?<func>[^;]+)' # backend.info.log
      }
    }
  } else {
    grok {
        ### other simple regexs ###
    }
  }

  date {
      match => ["timestamp", "yyyy-MM-dd HH:mm:ss,SSS", "yyyy-MM-dd HH:mm:ss", "yyyy-MM-dd HH:mm:ss.SSS", "ISO8601"]
      timezone => "Europe/Moscow"
  }
} 

```

I have a lot of django logs. They have different types, legacy too. Legacy logs should not pass this regex but they call timeout error. And I don't know how long correct log passes this regex 🙂

It's legacy log:

```auto
INFO 2019-08-24 11:52:56,619 
	Message: 
		User - Бондаренко; id - 111111; email - test@mail.ru;
		Agent - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.102 Safari/537.36 Edge/18.18363;
		ip - 10.205.0.10;
		Request: "/responses/" Method: "POST"; 
	In module: /app/lib/utils/logging.py

```

It's correct log:

```auto
INFO 2021-04-04 20:31:04,621
        Message:
                User - abykov_pexu; Name: Быков; id - 11111; email - test@mail.ru;
                Agent - Mozilla/5.0 (Linux; Android 5.0.2; SAMSUNG SM-T531 Build/LRX22G) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/3.3 Chrome/38.0.2125.102 Safari/537.36;
                ip - 188.170.1.1;
                token: eyJ0....ZGhI
                Request: "/auth/logout/" Method: "POST" Параметры: {}
                Request body:
        Module: oracle.views; Function: logout;

```

I could make some typing error because I translated it but I check my original regex on [https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/) and it works.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 4, 2021, 7:03pm UTC](https://discuss.elastic.co/t/timeout-executing-grok/269184/7 "2021-04-04T19:03:48Z")

</div>

> [@Andrey\_RF](#):
>
> Legacy logs should not pass this regex but they call timeout error.

That is typically the case. If the pattern matches then it matches, but if it does not match then grok spends lots of time trying a match and then backtracking to try a different match. All those .\* expressions embedded in your pattern are expensive when the pattern does not match.

I would take a different approach, using multiple patterns

```
grok {
    break_on_match => false
    match => {
        "message" => [
            "\A%{LOGLEVEL:log-level} %{TIMESTAMP_ISO8601:timestamp}",
            "User- (?<user>[^;]+)",
            "id - (?<user-id>[^;]+)",
            "email - (?<email>[^;]+)",
            "Agent-(?<useragent>[^;]+)",
            "Request: \"(?<request>[^\s^\"]+)",
            "Method: \"(?<method>[\w]+)",
            "Module: (?<module>[^;]+)",
            "Function: (?<func>[^;]+)"
    ]
}

```

Not sure if you need (?m) on all those patterns, you will have to test that.

---

<div class="post-metadata">

**Author:** ![Andrey\_RF](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrey_rf/32/86484_2.png) [@Andrey\_RF](https://discuss.elastic.co/u/Andrey_RF)\
**Post date:** [April 5, 2021, 12:58pm UTC](https://discuss.elastic.co/t/timeout-executing-grok/269184/8 "2021-04-05T12:58:36Z")

</div>

I read the article that you sent. It has a lot good tips. But do you think it's a good idea to allow the `match` breaking and trying to find all regex in incoming message ?

It confused me a little.

Will they stop after first match or global match ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 5, 2021, 2:27pm UTC](https://discuss.elastic.co/t/timeout-executing-grok/269184/9 "2021-04-05T14:27:19Z")

</div>

If you set `break_on_match => false` then grok will try each of the patterns in turn, regardless of whether they match or not.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 3, 2021, 2:27pm UTC](https://discuss.elastic.co/t/timeout-executing-grok/269184/10 "2021-05-03T14:27:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
