Grok processor extracts only the first value if there are multiple matches #92092
Labels
>bug
:Data Management/Ingest Node
Execution or management of Ingest Pipelines including GeoIP
Team:Data Management
Meta label for data/management team
Elasticsearch Version
7.17.6, 8.x
Installed Plugins
No response
Java Version
bundled
OS Version
Doesn't depend on the OS Version
Problem Description
The Grok processor in the elasticsearch ingest pipelines does not extract multiple value that match a group but only the first one.
For example the following Grok expression:
when given the following input:
It should match both values and not only the first one.
Steps to Reproduce
The
source.addresses
in the response is:While the expected value of
source.address
is:The text was updated successfully, but these errors were encountered: