# Gork extractor not matching any message

**URL:** <https://community.graylog.org/t/gork-extractor-not-matching-any-message/20227>\
**Category:** Graylog Tech Challenges\
**Tags:** pipeline-rules\
**Created:** [June 19, 2021, 9:28pm UTC](https://community.graylog.org/t/gork-extractor-not-matching-any-message/20227 "2021-06-19T21:28:51Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![braiam](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/braiam/32/8889_2.png) [@braiam](https://community.graylog.org/u/braiam)\
**Post date:** [June 19, 2021, 9:28pm UTC](https://community.graylog.org/t/gork-extractor-not-matching-any-message/20227/1 "2021-06-19T21:28:51Z")

</div>

I created the following extractor:

```auto
{
  "extractors": [
    {
      "title": "Bind query extractor with view",
      "extractor_type": "grok",
      "converters": [],
      "order": 0,
      "cursor_strategy": "copy",
      "source_field": "message",
      "target_field": "",
      "extractor_config": {
        "grok_pattern": "client %{DATA:client_cookie} %{IPORHOST:client_ip}#%{POSINT:client_port} (%{DATA}): %{BindViewName} query: %{GREEDYDATA:query}",
        "named_captures_only": false
      },
      "condition_type": "none",
      "condition_value": ""
    }
  ],
  "version": "4.0.8"
}

```

Metric details say that it haven’t matched anything, but there are messages like this one:

```auto
<30>1 2021-06-19T17:10:55.646107-04:00 bind01 named 38409 - - client @0x7f9dcc4d5b50 172.16.10.39#43918 (www.amazon.com): view normal: query: www.amazon.com IN AAAA + (172.16.15.48)

```

```auto
client @0x7f9dcc4d5b50 172.16.10.39#43918 (www.amazon.com): view normal: query: www.amazon.com IN AAAA + (172.16.15.48)

```

I put everything on the message and apply my extractor to it.

Testing the extractor against these messages do extract them, but otherwise it’s like the extractor didn’t exist in the input.

---

<div class="post-metadata">

**Author:** ![dscryber](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/dscryber/32/14178_2.png) [@dscryber](https://community.graylog.org/u/dscryber)\
**Post date:** [June 21, 2021, 3:25pm UTC](https://community.graylog.org/t/gork-extractor-not-matching-any-message/20227/2 "2021-06-21T15:25:08Z")

</div>

> [@braiam](#):
>
> Testing the extractor against these messages do extract them, but otherwise it’s like the extractor didn’t exist in the input.

Hello, braiam,

```
I've noticed your post hasn't been responded to. Moving it to Daily Challenges for perhaps a helpful response. In the meantime, here's a previous article on your topic. Let me know if it helps.

```

> [@JSON extractor not working?](https://community.graylog.org/t/json-extractor-not-working/6648):
>
> hello, we have an appliance that sends JSON formatted log data in message field, when i try to create JSON extractor on it i’m getting Nothing will be extracted in extractor preview, also it doesn’t extract data after saving in Example message field when creating an extractor there is what resembles perfect JSON, also i tested it with jq and it worked fine, here’s JSON sample: {“event\_type”:“Audit\_Event”,“ipv4”:“192.168.0.140”,“hostname”:“era.wupb.lokalna”,“source\_uuid”:“4a8c1c40-88a7-4a12-bb…

---

<div class="post-metadata">

**Author:** ![braiam](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/braiam/32/8889_2.png) [@braiam](https://community.graylog.org/u/braiam)\
**Post date:** [June 24, 2021, 9:58pm UTC](https://community.graylog.org/t/gork-extractor-not-matching-any-message/20227/3 "2021-06-24T21:58:19Z")

</div>

In that specific case, the preview doesn’t show any matched field. In my case, there are matched fields, but it isn’t hit by the input.

---

<div class="post-metadata">

**Author:** ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)\
**Post date:** [July 2, 2021, 8:02am UTC](https://community.graylog.org/t/gork-extractor-not-matching-any-message/20227/4 "2021-07-02T08:02:32Z")

</div>

Hi @braiam  
I’ve tested your grok and didn’t work for obvious reasons:

1. Your grok pattern `%{BindViewName}` is probably not defined, so graylog can’t process extractor at all
2. Another problem is that you didn’t enabled `Named captures only` in extractor definition. So `%{DATA}` in your grok is saved as generic field DATA, which is propably not desired.
3. If there is another problem with extractor, always check graylog server logs file. If graylog didn’t process extractor for any reason, there should be error or warning in logs file:  
`sudo tail -f /var/log/graylog-server/server.log`

---

<div class="post-metadata">

**Author:** ![braiam](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/braiam/32/8889_2.png) [@braiam](https://community.graylog.org/u/braiam)\
**Post date:** [July 2, 2021, 11:40am UTC](https://community.graylog.org/t/gork-extractor-not-matching-any-message/20227/5 "2021-07-02T11:40:28Z")

</div>

There’s some problems with that theories:

1. If it was not defined, Graylog would complain about it loudly on “Try against example” with “We were not able to run the grok extraction because of the following error: No definition for key ‘DdATA’ found, aborting” for example. I changed it to plain “DATA:view”, no dice.
2. While named\_captures\_only is disabled, it shouldn’t effect whenever it is matched or not, just that the field name would be something like “DATA”.
3. [The extractor metrics says “0 total invocations since boot, averages: 0, 0, 0.”,](https://community.graylog.org/uploads/short-url/lGNVdknmeYPjHh7gaanOmNj3UL5.png) which means that it doesn’t even fire when the input retrieves a new message. There’s no error about the pattern, since the pattern is never tried.

As I said, it should be firing since the condition is “Always try to extract” even if it doesn’t match anything, and the [“Try against example” correctly extracts the data](https://community.graylog.org/uploads/short-url/fX49kq0w8sEvv6NMRI6XGEeRujv.png).

---

<div class="post-metadata">

**Author:** ![braiam](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/braiam/32/8889_2.png) [@braiam](https://community.graylog.org/u/braiam)\
**Post date:** [July 2, 2021, 11:58am UTC](https://community.graylog.org/t/gork-extractor-not-matching-any-message/20227/6 "2021-07-02T11:58:09Z")

</div>

So, a development: I created a extractor that simply copies message to another field, same “Always try to extract”, still not firing. I think I’ve hit a bug.

---

<div class="post-metadata">

**Author:** ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)\
**Post date:** [July 2, 2021, 12:12pm UTC](https://community.graylog.org/t/gork-extractor-not-matching-any-message/20227/7 "2021-07-02T12:12:45Z")

</div>

I’ve tried your grok and worked fine for me in versions 4.0.7 and 4.1.

a. I don’t think that there is a bug in such essential feature as simple extractor.  
b. Check if you didn’t disabled `Message Filter Chain` by accident in `System - Configurations` in section `Message Processors Configuration`.  
c. What’s your `Message Processors Configuration` order? `Message Filter Chain` is after or before `Pipeline Processor`  
d. Do you use any pipeline rules, which should collide with extractor?  
e. What type of input do you use? Syslog TCP or UDP or another one?  
f. Do you have same problem with other extractors, or none of extractors works?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [July 16, 2021, 12:13pm UTC](https://community.graylog.org/t/gork-extractor-not-matching-any-message/20227/8 "2021-07-16T12:13:42Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
