# \_grokparse failure, but it's working

**URL:** <https://discuss.elastic.co/t/-grokparse-failure-but-its-working/27533>\
**Category:** Logstash\
**Created:** [August 17, 2015, 7:04pm UTC](https://discuss.elastic.co/t/-grokparse-failure-but-its-working/27533 "2015-08-17T19:04:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jack\_Judge](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jack_judge/32/85499_2.png) [@Jack\_Judge](https://discuss.elastic.co/u/Jack_Judge)\
**Post date:** [August 17, 2015, 7:04pm UTC](https://discuss.elastic.co/t/-grokparse-failure-but-its-working/27533/1 "2015-08-17T19:04:37Z")

</div>

I'm getting a weird grokparse failure everything seems to be working, it's a bit of a puzzler. I'm running logstash 1.5.0-1

This is a sample log message;

```
<B 2015Jul30 10:29:26.859> Workbook references the 'today' function but 'today' calendar position is not in the Workbook. Hence, calculations which use 'today' may contain wrong results.

```

And this is a snippet from the logstash conf,

```
grok {
                        match => { "message" => "\<%{USERNAME:loglevel} %{GREEDYDATA:logdate}\> %{GREEDYDATA:log_msg}" }
                }
                date {
                        timezone => "PST8PDT"
                        match => ["logdate", "YYYYMMMdd HH:mm:ss.SSS"]
                }

```

And this is the output, the grok and date filters are working so I'm puzzled why I'm getting tagged with a grokparsefailure.  
{  
"\_index": "logstash-2015.08.17",  
"\_type": "rpas",  
"\_id": "AU89BH2s8IpA7GMMxcYe",  
"\_score": null,  
"\_source": {  
"message": "\<D 2015Aug17 11:55:47.297\> TcpStream::closeSocket(SSL 2 Server70, 8);",  
"@version": "1",  
"@timestamp": "2015-08-17T18:55:47.297Z",  
"type": "rpas",  
"host": "qa-ip-rpas-02",  
"path": "/u01/app/oracle/mfp/logs/daemon\_D201508170000b00.log",  
"tags": [  
"\_grokparsefailure"  
],  
"loglevel": "D",  
"logdate": "2015Aug17 11:55:47.297",  
"log\_msg": "TcpStream::closeSocket(SSL 2 Server70, 8);"  
},  
"fields": {  
"@timestamp": [  
1439837747297  
]  
},  
"sort": [  
1439837747297  
]  
}

I'm outputting to an elasticsearch machine using the node protocol, this is our preferred choice by a country mile. I'm not specifying any codecs but I'm not getting this when I output to STDOUT using the rubydebug codec.  
I guess it's something to do with the elasticsearch output.  
I have experimented with a couple of output codecs (json and json\_lines) but there was no discernible difference.  
Does anyone have any ideas ? Thanks.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 18, 2015, 5:45am UTC](https://discuss.elastic.co/t/-grokparse-failure-but-its-working/27533/2 "2015-08-18T05:45:05Z")

</div>

And this is your only grok filter? No stray files in /etc/logstash/conf.d that you've forgotten about?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:31am UTC](https://discuss.elastic.co/t/-grokparse-failure-but-its-working/27533/3 "2017-07-06T05:31:41Z")

</div>


