# Timestamp does not match data

**URL:** <https://discuss.elastic.co/t/timestamp-does-not-match-data/298344>\
**Category:** Logstash\
**Created:** [February 26, 2022, 9:39pm UTC](https://discuss.elastic.co/t/timestamp-does-not-match-data/298344 "2022-02-26T21:39:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![tjunge](https://avatars.discourse-cdn.com/v4/letter/t/ad7895/32.png) [@tjunge](https://discuss.elastic.co/u/tjunge)\
**Post date:** [February 26, 2022, 9:39pm UTC](https://discuss.elastic.co/t/timestamp-does-not-match-data/298344/1 "2022-02-26T21:39:43Z")

</div>

Hi,

I am new to Elastic Stack and trying to filter my fail2ban log.

In Grok Debugger I tried to simulate my Grok pattern on my data but have problems with the timestamp. I always get the simulate error: Provided Grok patterns do not match data in the input.

Input:

```auto
Feb 25 09:29:09 fail2ban-server[35630]: fail2ban.actions [35630]: NOTICE [postfix-gateways-soft] Ban 2001:41d0:8:ca94::/

```

Grok pattern:

```auto
%{SYSLOGTIMESTAMP} %{WORD:src_action} *\[%{INT:fail2ban_digit}\]: %{LOGLEVEL:loglevel} *\[%{NOTSPACE:service}\] %{WORD:ban_status} %{IP:clientip}

```

![2022-02-26 22_09_22-Window](https://us1.discourse-cdn.com/elastic/original/3X/0/d/0df55f3fd1ef8ae344092f1b633103b28a4422d3.png)

If I use the input without date and time I got an output as expected

```auto
fail2ban-server[35630]: fail2ban.actions [35630]: NOTICE [postfix-gateways-soft] Ban 2001:41d0:8:ca94::

%{WORD:src_action} *\[%{INT:fail2ban_digit}\]: %{LOGLEVEL:loglevel} *\[%{NOTSPACE:service}\] %{WORD:ban_status} %{IP:clientip}

```

```auto
{
  "service": "postfix-gateways-soft",
  "loglevel": "NOTICE",
  "clientip": "2001:41d0:8:ca94::",
  "ban_status": "Ban",
  "src_action": "actions",
  "fail2ban_digit": "35630"
}

```

How can I get it working with the timestamp at the beginning of the input?

Thanks for your help in advance.

Tom

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 26, 2022, 9:48pm UTC](https://discuss.elastic.co/t/timestamp-does-not-match-data/298344/2 "2022-02-26T21:48:25Z")

</div>

> [@tjunge](#):
>
> ```auto
> Feb 25 09:29:09 fail2ban-server[35630]: fail2ban.actions [35630]: NOTICE [postfix-gateways-soft] Ban 2001:41d0:8:ca94::/
> 
> ```
> 
> Grok pattern:
> 
> ```auto
> %{SYSLOGTIMESTAMP} %{WORD:src_action} *\[%{INT:fail2ban_digit}\]: %{LOGLEVEL:loglevel} *\[%{NOTSPACE:service}\] %{WORD:ban_status} %{IP:clientip}
> 
> ```

SYSLOGTIMESTAMP will consume 'Feb 25 09:29:09'. WORD:src\_action will match the following 'fail2ban'. Then there nothing in your pattern to match '-server[35630]: fail2ban.actions'. You need to add to your grok pattern to match that.

---

<div class="post-metadata">

**Author:** ![tjunge](https://avatars.discourse-cdn.com/v4/letter/t/ad7895/32.png) [@tjunge](https://discuss.elastic.co/u/tjunge)\
**Post date:** [February 27, 2022, 2:21pm UTC](https://discuss.elastic.co/t/timestamp-does-not-match-data/298344/3 "2022-02-27T14:21:44Z")

</div>

Badger

thanks a lot for this hint.  
That helped me to solve the problem 🙂

```auto
%{SYSLOGTIMESTAMP:timestamp} %{WORD:log_service_1}-%{WORD:log_service_2}\[%{INT:fail2ban_digit}\]: %{WORD:log_src}.%{WORD:src_action} *\[%{INT:fail2ban_digit}\]: %{LOGLEVEL:loglevel} *\[%{NOTSPACE:service}\] %{WORD:ban_status} %{IP:clientip}

```

Output:

```auto
{
  "ban_status": "Ban",
  "log_src": "fail2ban",
  "log_2": "server",
  "log_1": "fail2ban",
  "service": "postfix-gateways-soft",
  "loglevel": "NOTICE",
  "clientip": "2001:41d0:8:ca94::",
  "src_action": "actions",
  "fail2ban_digit": "35640",
  "timestamp": "Feb 25 09:29:09"
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 27, 2022, 2:21pm UTC](https://discuss.elastic.co/t/timestamp-does-not-match-data/298344/4 "2022-03-27T14:21:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
