# Why am I getting GrokTimeout for a my simple log?

**URL:** <https://discuss.elastic.co/t/why-am-i-getting-groktimeout-for-a-my-simple-log/65847>\
**Category:** Logstash\
**Created:** [November 11, 2016, 8:56pm UTC](https://discuss.elastic.co/t/why-am-i-getting-groktimeout-for-a-my-simple-log/65847 "2016-11-11T20:56:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![seanziee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seanziee/32/45151_2.png) [@seanziee](https://discuss.elastic.co/u/seanziee)\
**Post date:** [November 11, 2016, 8:56pm UTC](https://discuss.elastic.co/t/why-am-i-getting-groktimeout-for-a-my-simple-log/65847/1 "2016-11-11T20:56:11Z")

</div>

Hi,

My grok keeps timing out while trying to filter a not so complicated/long log file. I have been trying for days now to no avail. I have tested all the patterns in the grok constructor with no issue so the main problem seems to be how the pattern is reading the log to cause a timeout, and not the integrity of the patterns. However, it is possible that my patterns aren't optimal because I am new at this.

The sample log file I am trying to filter is:

> Error Code: E-00000  
> Severity: WORDS  
> Category: CATEGORYTYPE.CATEGORY  
> Timestamp: 2016-09-08 06:08:12.621  
> Message: MESSAGE ERROR  
> Exception: TextTextTextTextTextTextTextText TextTextTextTextTextTextTextTextTextTextTextText  
> TextTextTextTextText  
> at TxtTextTextTextTextTextTextTextTextTextTextTextTextTextTextTextTextTextTe  
> at xtTextTextTextTextTextTextTextTextTextTextTextTextTextTextTextTextTextTex  
> at TextTextTextTextTextTextTextTextTextTextTextTextTextTextTextTextTextTextTe

> Machine: XX00XXXX000X  
> Application Domain: Application.exe  
> Process Id: 0000  
> Process Name: C:\file\file\filehere\file.exe  
> App Type for Log: NAME  
> Win32 Thread Id: 0000  
> Thread Name:  
> Extended Properties:

Where my grok looks like this, and all the 3 letter patterns are just the names of each category and won't be displayed. The problem seems to be from the filter because when I take out the "Exception: " field from the log and filter, everything runs perfectly smoothly.:

```
filter{
        grok {
        timeout_millis => 60000
        patterns_dir => "/etc/logstash/patterns/patterns"
        match => { "message" => "%{ERC}%{CODE:ErrorCode456}%{SPACE}%{SEV}%{WORD:Severity}%{SPACE}%{CAT}%{GREEDYDATA:Category}%{SPACE}
        %{TIM}%{TIMESTAMP_ISO8601:Time}%{SPACE}%{MES}(?<Summary>%{SPACE}(?:(?!((Machine: )|(Exception: ))).)*)%{SPACE}%{EXC}(?<Exception>(.*\s*)*(?:(?!Machine: ).)*)
        %{SPACE}%{MACH}%{SERVER:Server}%{SPACE}%{APD}(?<ApplicationDomain>.*exe$)%{SPACE}%{PID}%{INT:PID}%{SPACE}%{PRN}(?<Process Name>.*exe$)%{SPACE}%{ATL}
        %{APPTYPE:App Type for Log}%{SPACE}%{WTI}%{NUMBER:ThreadID}%{SPACE}%{THN}%{SPACE}%{EXP}" }
        }
}

```

And my patterns are:

```
ERC Error Code:\s*
CODE \w-\d{5}
SEV Severity:\s*
CAT Category:\s*
TIM Timestamp:\s*
EXC Exception:\s*
MACH Machine:\s*
SERVER \w+{8,}
APD Application Domain:\s*
PID Process Id:\s*
PRN Process Name:\s*
ATL App Type for Log:\s*
APPTYPE \w*
WTI Win32 Thread Id:\s*
THN Thread Name:\s*
EXP Extended Properties:\s*

```

This is the error I get in case that it's of any help.

```
[2016-11-11T15:21:06,063][WARN][logstash.filters.grok] Timeout executing grok '%{ERC}%{CODE:ErrorCode456}%{SPACE}%{SEV}%{WORD:Severity}%{SPACE}%{CAT}%{GREEDYDATA:Category}%{SPACE}%{TIM}%{TIMESTAMP_ISO8601:Time}%{SPACE}%{MES}(?<Summary>%{SPACE}(?:(?!((Machine: )|(Exception: ))).)*)%{SPACE}%{EXC}(?<Exception>(.*\s*)*(?:(?!Machine: ).)*)%{SPACE}%{MACH}%{SERVER:Server}%{SPACE}%{APD}(?<ApplicationDomain>.*exe$)%{SPACE}%{PID}%{INT:PID}%{SPACE}%{PRN}(?<Process Name>.*exe$)%{SPACE}%{ATL}%{APPTYPE:App Type for Log}%{SPACE}%{WTI}%{NUMBER:ThreadID}%{SPACE}%{THN}%{SPACE}%{EXP}' against field 'message' with value 'Value too large to output (791 bytes)! First 255 chars are:

```

---

<div class="post-metadata">

**Author:** ![seanziee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seanziee/32/45151_2.png) [@seanziee](https://discuss.elastic.co/u/seanziee)\
**Post date:** [November 14, 2016, 4:51pm UTC](https://discuss.elastic.co/t/why-am-i-getting-groktimeout-for-a-my-simple-log/65847/3 "2016-11-14T16:51:48Z")

</div>

Anyone?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 14, 2016, 4:58pm UTC](https://discuss.elastic.co/t/why-am-i-getting-groktimeout-for-a-my-simple-log/65847/4 "2016-11-14T16:58:38Z")

</div>

You do have a GREEDYDATA pattern quite early on, which I believe can be quite inefficient. Is it possible to try replacing this with something more specific?

---

<div class="post-metadata">

**Author:** ![seanziee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seanziee/32/45151_2.png) [@seanziee](https://discuss.elastic.co/u/seanziee)\
**Post date:** [November 15, 2016, 9:20pm UTC](https://discuss.elastic.co/t/why-am-i-getting-groktimeout-for-a-my-simple-log/65847/5 "2016-11-15T21:20:26Z")

</div>

Thanks for the protip!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 13, 2016, 9:20pm UTC](https://discuss.elastic.co/t/why-am-i-getting-groktimeout-for-a-my-simple-log/65847/6 "2016-12-13T21:20:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
