# \_grokparsefailure also after Grok Constructor

**URL:** <https://discuss.elastic.co/t/-grokparsefailure-also-after-grok-constructor/56178>\
**Category:** Logstash\
**Created:** [July 22, 2016, 12:18pm UTC](https://discuss.elastic.co/t/-grokparsefailure-also-after-grok-constructor/56178 "2016-07-22T12:18:36Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hans](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Hans](https://discuss.elastic.co/u/Hans)\
**Post date:** [July 22, 2016, 12:18pm UTC](https://discuss.elastic.co/t/-grokparsefailure-also-after-grok-constructor/56178/1 "2016-07-22T12:18:36Z")

</div>

HI, I have a challenge that I have been trying to resolve now for some time however not making positive progress. I have logs that I would like to filter and did Incremental Grok Construct and all is matching, however when running this into Elaticsearch I get the \_grokparsefailure error.

Here is a sample log:  
Jul 22 03:30:10 192.29.58.44 400 \<11\>1 2016-07-22T03:17:29+01:00 10.31.12.12 1 - - - 2016-07-22T03:29:14.649+01:00 ABC-0000-WWWW03 RT\_IDS - RT\_SCREEN\_TCP\_LS [junos@1111.1.1.1.1.88 logical-system-name="TEST-INTERNET" attack-name="TCP sweep!" source-address="58.18.186.131" source-port="45633" destination-address="106.225.87.224" destination-port="22" source-zone-name="INTERNET-TEST" interface-name="xe-1/0/13.9" action="drop"]

The filter I am using is:  
grok {  
match =\> ["messages", "%{SYSLOGTIMESTAMP:Date1} %{SYSLOGHOST} %{WORD:Nr} %{SYSLOGPROG} %{TIMESTAMP\_ISO8601:Date2} %{IP} %{WORD} - - - %{TIMESTAMP\_ISO8601:Date} %{HOSTNAME} RT\_IDS - RT\_SCREEN\_TCP\_LS %{SYSLOG5424PRINTASCII} %{SYSLOG5424PRINTASCII} %{GREEDYDATA}"]  
tag\_on\_failure =\> []  
add\_tag =\> "RT\_IDS"  
}

Any assistance will be truly appreciated with this challenge.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 24, 2016, 1:24am UTC](https://discuss.elastic.co/t/-grokparsefailure-also-after-grok-constructor/56178/2 "2016-07-24T01:24:52Z")

</div>

I just tried that on [http://grokdebug.herokuapp.com/](http://grokdebug.herokuapp.com/) and it doesn't work.  
I'd start by hitting up that site and then back tracking till you find the problem.

---

<div class="post-metadata">

**Author:** ![Hans](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Hans](https://discuss.elastic.co/u/Hans)\
**Post date:** [July 27, 2016, 3:35pm UTC](https://discuss.elastic.co/t/-grokparsefailure-also-after-grok-constructor/56178/3 "2016-07-27T15:35:41Z")

</div>

Thank you for the response, it is quite interesting as I was using [http://grokconstructor.appspot.com/do/construction](http://grokconstructor.appspot.com/do/construction) and all was matching here, however in [http://grokdebug.herokuapp.com/](http://grokdebug.herokuapp.com/) this was not the case. I have updated the filter and now it is matching in both tools, however the challenge is still current, here is the latest filer:  
`%{CISCOTIMESTAMP} %{IP} %{WORD:Nr} %{SYSLOG5424PRI}1 %{TIMESTAMP_ISO8601} %{IP} %{WORD} - - - %{TIMESTAMP_ISO8601:Date} %{CISCOTAG} RT_IDS - RT_SCREEN_TCP_LS %{SYSLOG5424SD}`

---

<div class="post-metadata">

**Author:** ![Hans](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Hans](https://discuss.elastic.co/u/Hans)\
**Post date:** [July 30, 2016, 8:33pm UTC](https://discuss.elastic.co/t/-grokparsefailure-also-after-grok-constructor/56178/4 "2016-07-30T20:33:02Z")

</div>

It looks like the date is the challenge in the filter, could someone assist in validating if the following is correct:

Date Example:  
2016-07-28T03:51:34.068+01:00

Filter Applied:  
"yyyy-MM-dd'T'HH:mm:ss.SSSz"

Thank you

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 30, 2016, 11:00pm UTC](https://discuss.elastic.co/t/-grokparsefailure-also-after-grok-constructor/56178/5 "2016-07-30T23:00:00Z")

</div>

Just use the `TIMESTAMP_ISO8601` pattern 🙂

---

<div class="post-metadata">

**Author:** ![Hans](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Hans](https://discuss.elastic.co/u/Hans)\
**Post date:** [July 31, 2016, 6:36am UTC](https://discuss.elastic.co/t/-grokparsefailure-also-after-grok-constructor/56178/6 "2016-07-31T06:36:05Z")

</div>

Thank you for that, however let me provide you with the configuration sections I am struggling with:  
if "RT\_IDS" in [tags] {  
grok {  
match =\> ["messages", "%{CISCOTIMESTAMP} %{IP} %{WORD:Nr} %{SYSLOG5424PRI}1 %{TIMESTAMP\_ISO8601} %{IP} %{WORD} - - - %{TIMESTAMP\_ISO8601:Date} %{CISCOTAG} RT\_IDS - RT\_SCREEN\_TCP\_LS %{SYSLOG5424SD}"]  
add\_tag =\> "RT\_IDS"  
}  
date {  
locale =\> "en"  
match =\> ["Date",  
"yyyy-mm-dd'T'HH:mm:ss.SSSZ",  
"ISO8601"]  
timezone =\> "Africa/Windhoek"  
target =\> "@timestamp"  
add\_field =\> { "debug" =\> "timestampMatched"}  
}

---

<div class="post-metadata">

**Author:** ![Hans](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Hans](https://discuss.elastic.co/u/Hans)\
**Post date:** [July 31, 2016, 6:37am UTC](https://discuss.elastic.co/t/-grokparsefailure-also-after-grok-constructor/56178/7 "2016-07-31T06:37:30Z")

</div>

> [@Hans](#):
>
> Jul 22 03:30:10 192.29.58.44 400 \<11\>1 2016-07-22T03:17:29+01:00 10.31.12.12 1 - - - 2016-07-22T03:29:14.649+01:00 ABC-0000-WWWW03 RT\_IDS - RT\_SCREEN\_TCP\_LS [junos@1111.1.1.1.1.88 logical-system-name="TEST-INTERNET" attack-name="TCP sweep!" source-address="58.18.186.131" source-port="45633" destination-address="106.225.87.224" destination-port="22" source-zone-name="INTERNET-TEST" interface-name="xe-1/0/13.9" action="drop"]

Log:  
Jul 22 03:30:10 192.29.58.44 400 \<11\>1 2016-07-22T03:17:29+01:00 10.31.12.12 1 - - - 2016-07-22T03:29:14.649+01:00 ABC-0000-WWWW03 RT\_IDS - RT\_SCREEN\_TCP\_LS [junos@1111.1.1.1.1.88 logical-system-name="TEST-INTERNET" attack-name="TCP sweep!" source-address="58.18.186.131" source-port="45633" destination-address="106.225.87.224" destination-port="22" source-zone-name="INTERNET-TEST" interface-name="xe-1/0/13.9" action="drop"]

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:45am UTC](https://discuss.elastic.co/t/-grokparsefailure-also-after-grok-constructor/56178/8 "2017-07-06T04:45:41Z")

</div>


