# Timeout executing grok

**URL:** <https://discuss.elastic.co/t/timeout-executing-grok/76261>\
**Category:** Logstash\
**Created:** [February 23, 2017, 4:02pm UTC](https://discuss.elastic.co/t/timeout-executing-grok/76261 "2017-02-23T16:02:13Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![kmroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmroz/32/62741_2.png) [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Post date:** [February 23, 2017, 4:02pm UTC](https://discuss.elastic.co/t/timeout-executing-grok/76261/1 "2017-02-23T16:02:13Z")

</div>

Hello I am getting a timeout issue when running a grok filter. My logstash config looks like so.

filter {  
if [type] == "cast" {  
grok {  
break\_on\_match =\> false

```
             match => { 'message'=> '\[%{DATA:timestamp}\] \[%{DATA:pool}\] %{WORD:ignore} %{NUMBER:pid}'}

             match => { 'message' => '%{DATESTAMP:timestamp} \[%{WORD:status}\] %{DATA:ignore}\: \*%{NUMBER:ignore} %{GREEDYDATA:error-message}'}

             match => { 'message' => '%{IPORHOST:ip} \- \- \[%{HTTPDATE:timestamp}\] "%{WORD:ignore} %{PATH:a-info}%{DATA:ignore}&%{WORD:ignore}=%{NUMBER:font}%{DATA:ignore}" %{INT:http_response} %{INT:wall} "-" %{DATA:ignore}\(%{WORD:OS}; %{DATA:ignore}\) %{WORD:browser}%{GREEDYDATA:ignore}'}

             match => { 'message' => '%{IPORHOST:ip} \- \- \[%{HTTPDATE:timestamp}\] "%{WORD:ignore} %{PATH:a-info}%{DATA:ignore}&%{WORD:ignore}=%{NUMBER:font}%{DATA:ignore}" %{INT:http_response} %{INT:wall} "%{URI:URL}" %{DATA:ignore}\(%{WORD:OS}%{DATA:ignore},%{DATA:ignore}\) %{WORD:browser}%{GREEDYDATA:ignore}'}

```

}

I checked the message it is time outing on and it matches on of the filters above. I dont get why it would timeout. Any help would be greatly appreciated.

---

<div class="post-metadata">

**Author:** ![kmroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmroz/32/62741_2.png) [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Post date:** [February 23, 2017, 6:21pm UTC](https://discuss.elastic.co/t/timeout-executing-grok/76261/2 "2017-02-23T18:21:17Z")

</div>

just updated stack to latest and greatest, still the same issue.

---

<div class="post-metadata">

**Author:** ![kmroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmroz/32/62741_2.png) [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Post date:** [February 23, 2017, 7:05pm UTC](https://discuss.elastic.co/t/timeout-executing-grok/76261/3 "2017-02-23T19:05:48Z")

</div>

ive tried adding tag\_n\_timeout and then grab that time out and jsut grok match it to %{GREEDYDATA:timeout} and it doesn't work.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 24, 2017, 1:52am UTC](https://discuss.elastic.co/t/timeout-executing-grok/76261/4 "2017-02-24T01:52:06Z")

</div>

What is the exact error, please post the log.

---

<div class="post-metadata">

**Author:** ![kmroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmroz/32/62741_2.png) [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Post date:** [February 24, 2017, 4:07pm UTC](https://discuss.elastic.co/t/timeout-executing-grok/76261/5 "2017-02-24T16:07:21Z")

</div>

Timeout executing grok '%{IPORHOST:ip} - - [%{HTTPDATE:timestamp}] "%{WORD:ignore} %{PATH:a-info}%{DATA:ignore}&%{WORD:ignore}=%{NUMBER:font}%{DATA:ignore}" %{INT:http\_response} %{INT:wall} "-" %{DATA:ignore}(%{WORD:OS}; %{DATA:ignore}) %{WORD:browser}%{GREEDYDATA:ignore}' against field 'message' with value 'Value too large to output (431 bytes)! First 255 chars are:

---

<div class="post-metadata">

**Author:** ![kmroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmroz/32/62741_2.png) [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Post date:** [March 2, 2017, 7:41pm UTC](https://discuss.elastic.co/t/timeout-executing-grok/76261/6 "2017-03-02T19:41:25Z")

</div>

anyone have an idea of what can be causing this?

---

<div class="post-metadata">

**Author:** ![kmroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmroz/32/62741_2.png) [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Post date:** [March 2, 2017, 8:58pm UTC](https://discuss.elastic.co/t/timeout-executing-grok/76261/7 "2017-03-02T20:58:52Z")

</div>

added x-pack to logstash and see that CPU is at 95-97% is this because of the bad filter or could this be causing it?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 3, 2017, 2:25am UTC](https://discuss.elastic.co/t/timeout-executing-grok/76261/8 "2017-03-03T02:25:53Z")

</div>

Does monitoring show you where it's spending most of its time?

---

<div class="post-metadata">

**Author:** ![kmroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmroz/32/62741_2.png) [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Post date:** [March 6, 2017, 2:49pm UTC](https://discuss.elastic.co/t/timeout-executing-grok/76261/9 "2017-03-06T14:49:42Z")

</div>

it does not, unless i am looking in the wrong place?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 6, 2017, 2:56pm UTC](https://discuss.elastic.co/t/timeout-executing-grok/76261/10 "2017-03-06T14:56:03Z")

</div>

You have a few occurrences of `DATA` and `GREEDYDATA` that tend to match a lot and can be expensive/slow to compute. Try to be more specific. It also looks like you have a few fields named `ignore`. If you do not want to capture the data, I believe you can simply just not name it.

---

<div class="post-metadata">

**Author:** ![kmroz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kmroz/32/62741_2.png) [@kmroz](https://discuss.elastic.co/u/kmroz)\
**Post date:** [March 6, 2017, 2:58pm UTC](https://discuss.elastic.co/t/timeout-executing-grok/76261/11 "2017-03-06T14:58:00Z")

</div>

using greedydata is just to grab the rest of the log? Is there a better work around than grabbing each piece of data?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 6, 2017, 3:00pm UTC](https://discuss.elastic.co/t/timeout-executing-grok/76261/12 "2017-03-06T15:00:05Z")

</div>

The last `GREEDYDATA` is fine, but you may want to be more specific and replace the `DATA` patterns earlier in the pattern. If you show what a log line looks like we may be able to provide better guidance.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 3, 2017, 3:00pm UTC](https://discuss.elastic.co/t/timeout-executing-grok/76261/13 "2017-04-03T15:00:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
