# Trouble parsing this statement - help with grok expression

**URL:** <https://discuss.elastic.co/t/trouble-parsing-this-statement-help-with-grok-expression/42496>\
**Category:** Logstash\
**Created:** [February 23, 2016, 1:59pm UTC](https://discuss.elastic.co/t/trouble-parsing-this-statement-help-with-grok-expression/42496 "2016-02-23T13:59:06Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jjdepaul](https://avatars.discourse-cdn.com/v4/letter/j/e0b2c6/32.png) [@jjdepaul](https://discuss.elastic.co/u/jjdepaul)\
**Post date:** [February 23, 2016, 1:59pm UTC](https://discuss.elastic.co/t/trouble-parsing-this-statement-help-with-grok-expression/42496/1 "2016-02-23T13:59:06Z")

</div>

LogStash 2.0.0 on Window7 (and cygwin). I have the following grok expression:

`Customer Account Number=%{NOTSPACE:accountId} Contract Number=%{NOTSPACE:cftsContractNumber} Work Number=%{NOTSPACE:cftsWorkNumber} Status=%{GREEDYDATA:cftsStatus} (cftsFileName=%{GREEDYDATA:cftsFilename})? (emailRecipients=%{GREEDYDATA:emailRecipients})?`

Here is the input log line.... not sure why it's not working and not sure how to get rid of all of the GREEDYDATA patterns and still be able to parse it properly. Log data:

`Customer Account Number=352784 Contract Number=ES00104293 Work Number=P033629 Status=Success cftsFileName=/web/cftsftp_emea/cftscron/fromcfts/gbi_output_ALL_ALL_IC2ECFTS_001044.xml emailRecipients=email1,email2, email3, email4`

I've tried debugging it - it has trouble somewhere in the Work Number expression... no idea why.

---

<div class="post-metadata">

**Author:** ![Kryten](https://avatars.discourse-cdn.com/v4/letter/k/58956e/32.png) [@Kryten](https://discuss.elastic.co/u/Kryten)\
**Post date:** [February 23, 2016, 6:12pm UTC](https://discuss.elastic.co/t/trouble-parsing-this-statement-help-with-grok-expression/42496/2 "2016-02-23T18:12:51Z")

</div>

Hi,  
You could try replacing your grok expression with this:-

`Customer\sAccount\sNumber\=(?<customer_account_number>\d*)\sContract\sNumber\=(?<contract_number>\w*)\sWork\sNumber\=(?<work_number>\w*)\sStatus\=(?<status>\w*)\scftsFileName\=(?<cfts_filename>.*?(?=\s))\semailRecipients\=(?<email_recipients>.*)`

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 23, 2016, 6:30pm UTC](https://discuss.elastic.co/t/trouble-parsing-this-statement-help-with-grok-expression/42496/3 "2016-02-23T18:30:50Z")

</div>

Be systematic. Start with the simplest possible expression,

```
Customer Account Number=%{NOTSPACE:accountId}

```

and verify that it works. Add the next token,

```
Customer Account Number=%{NOTSPACE:accountId} Contract Number=%{NOTSPACE:cftsContractNumber}

```

and continue until it stops working.

I'd be very careful about those GREEDYDATA patterns, some of which are optional. It'll almost certainly not work as expected.

Also, the spaces surrounding the optional tokens are incorrect. Follow this pattern instead:

```
%{A:b}( %{C:d})?( %{E:f})?
```

---

<div class="post-metadata">

**Author:** ![jjdepaul](https://avatars.discourse-cdn.com/v4/letter/j/e0b2c6/32.png) [@jjdepaul](https://discuss.elastic.co/u/jjdepaul)\
**Post date:** [February 23, 2016, 6:52pm UTC](https://discuss.elastic.co/t/trouble-parsing-this-statement-help-with-grok-expression/42496/4 "2016-02-23T18:52:19Z")

</div>

Thank you to both. It worked, with a minor tweak.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:10am UTC](https://discuss.elastic.co/t/trouble-parsing-this-statement-help-with-grok-expression/42496/5 "2017-07-06T05:10:03Z")

</div>


