# Solved: Problem with pipeline rule and grok pattern

**URL:** <https://community.graylog.org/t/solved-problem-with-pipeline-rule-and-grok-pattern/11542>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules\
**Created:** [August 10, 2019, 11:20pm UTC](https://community.graylog.org/t/solved-problem-with-pipeline-rule-and-grok-pattern/11542 "2019-08-10T23:20:10Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![diba](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@diba](https://community.graylog.org/u/diba)\
**Post date:** [August 10, 2019, 11:20pm UTC](https://community.graylog.org/t/solved-problem-with-pipeline-rule-and-grok-pattern/11542/1 "2019-08-10T23:20:10Z")

</div>

Hello everybody,

i am Dirk from Germany. I am a newbie with graylog. The most of my problems i solved with good inet documentation and youtube :-). But now i have a problem with the pipelines rules and a grok pattern.

The following grok pattern works fine within the extracttor.

`action=%{QUOTEDSTRING:action}\s*.*\s*srcip=\"%{IPV4:SourceIP}\"\s*dstip=\"%{IPV4:DestinationIP}\"\s*.*\s*srcport=\"%{POSINT:SourcePORT}\"\s*dstport=\"%{POSINT:DestinationPORT}\"`

But the follwoing code for the pipeline rule doesn’t work.

```
rule "SOPHOS UTM SYSLOG RULE"
when
    has_field("message")
then
    let message_field = to_string($message.message);
    
    let fw = grok(pattern: "action=%{QUOTEDSTRING:action}\s*.*\s*srcip=\"%{IPV4:SourceIP}\"\s*dstip=\"%{IPV4:DestinationIP}\"\s*.*\s*srcport=\"%{POSINT:SourcePORT}\"\s*dstport=\"%{POSINT:DestinationPORT}\"", value: message_field, only_named_captures: true);
    
    
    set_fields(fw);
end

```

I can’t safe the rule. I see no red x on the left site if i write the code by hand. If i make a cut and paste from my notepad into the rule editor i get an red x on line 7 on the left site.

At the moment i work with Graylog Version : Graylog v3.0.2+1686930 and Elasticsearch-oss 6.8.2

I hope somebody of you can help me and can say what mistake i have done.

**Solution: I have to escape the backslash and the double quotes. Both are special characters.**

Thanks a lot.

Best regards

Dirk

---

<div class="post-metadata">

**Author:** ![Ponet](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/ponet/32/2131_2.png) [@Ponet](https://community.graylog.org/u/Ponet)\
**Post date:** [August 10, 2019, 11:44pm UTC](https://community.graylog.org/t/solved-problem-with-pipeline-rule-and-grok-pattern/11542/2 "2019-08-10T23:44:03Z")

</div>

What is the issue you’re actually encountering?

---

<div class="post-metadata">

**Author:** ![diba](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@diba](https://community.graylog.org/u/diba)\
**Post date:** [August 10, 2019, 11:57pm UTC](https://community.graylog.org/t/solved-problem-with-pipeline-rule-and-grok-pattern/11542/3 "2019-08-10T23:57:27Z")

</div>

Hi Ponet,

thanks for your reply. I can’t safe the rule. I see no red x on the left site if i write the code by hand. If i make a cut and paste from my notepad into the rule editor i get an red x on line 7 on the left site.

At the moment i work with Graylog Version : Graylog v3.0.2+1686930 and Elasticsearch-oss 6.8.2.

Best regards.

Dirk

---

<div class="post-metadata">

**Author:** ![Ponet](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/ponet/32/2131_2.png) [@Ponet](https://community.graylog.org/u/Ponet)\
**Post date:** [August 11, 2019, 12:18am UTC](https://community.graylog.org/t/solved-problem-with-pipeline-rule-and-grok-pattern/11542/4 "2019-08-11T00:18:45Z")

</div>

Hi @diba

Try escaping the backslash characters in your grok pattern…

`grok(pattern: "action=%{QUOTEDSTRING:action}\\s*.*\\s*srcip=\\"%{IPV4:SourceIP}\\"\\s*dstip=\\"%{IPV4:DestinationIP}\\"\\s*.*\\s*srcport=\\"%{POSINT:SourcePORT}\\"\\s*dstport=\\"%{POSINT:DestinationPORT}\\"", value: message_field, only_named_captures: true);`

---

<div class="post-metadata">

**Author:** ![diba](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@diba](https://community.graylog.org/u/diba)\
**Post date:** [August 11, 2019, 9:12am UTC](https://community.graylog.org/t/solved-problem-with-pipeline-rule-and-grok-pattern/11542/5 "2019-08-11T09:12:20Z")

</div>

HI @Ponet,

i tested the code from your answer but unfortunately it doesn’t work.

This time i got two red x in line 7 and 10.

Do you have any other idea ?

Best regards

Dirk

---

<div class="post-metadata">

**Author:** ![diba](https://avatars.discourse-cdn.com/v4/letter/d/977dab/32.png) [@diba](https://community.graylog.org/u/diba)\
**Post date:** [August 11, 2019, 9:43am UTC](https://community.graylog.org/t/solved-problem-with-pipeline-rule-and-grok-pattern/11542/6 "2019-08-11T09:43:45Z")

</div>

Hi @Ponet

i found the solution. i have to escape the double quotes too.

Thanks for your help.

Best regards.

Dirk

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [August 25, 2019, 9:43am UTC](https://community.graylog.org/t/solved-problem-with-pipeline-rule-and-grok-pattern/11542/7 "2019-08-25T09:43:52Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
