New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Grok Function Always Returns {} in Pipeline #3610
Comments
As grok pattern are working and I assume that the space after the : is also in your rule you should fix that and then this should work. We are using GitHub issues for tracking bugs in Graylog itself, but this doesn't look like one. Please post this issue to our discussion forum or join the #graylog channel on freenode IRC. Thank you! |
I have removed space. Result: no effect, same behavior.
Added fields:
|
@lystor How are you importing the messages for which the Grok extraction fails? Which character set are these messages using? |
Hello, joschi I have created minimal testcase. Requirements:
Steps:
Simulation results:
Please reopen the bug and fix it. Thank you |
@lystor Is the used Grok pattern |
Sure. I use OFFICIAL docker image without any configuration options. The bug is reproducible in 100% cases using provided testcase. Additional info:
Details:
Result: grok in pipeline doesn't work
Result: grok in pipeline works perfectly. |
I could reproduce the problem. Reopening the issue. |
The BundleImporter logic for creating Grok patterns from a content pack wasn't publishing a GrokPatternsChangedEvent which caused the GrokService to invalidate and reload its internal cache. Fixes #3610
The BundleImporter logic for creating Grok patterns from a content pack wasn't publishing a GrokPatternsChangedEvent which caused the GrokService to invalidate and reload its internal cache. Fixes #3610
Hello
It seems grok function doesn't work in Graylog 2.2.2.
Clean installation with default'All messages' stream, single pipeline, default stage, single rule:
Simulate:
Simulation results:
As you can see - 'x' field is absent, 'grok_matches' field is {}.
Please fix the bug.
Thank you
The text was updated successfully, but these errors were encountered: