# \_grokparsefailure and missing events when using Logstash Forwarder

**URL:** <https://discuss.elastic.co/t/-grokparsefailure-and-missing-events-when-using-logstash-forwarder/33523>\
**Category:** Logstash\
**Created:** [November 2, 2015, 2:30pm UTC](https://discuss.elastic.co/t/-grokparsefailure-and-missing-events-when-using-logstash-forwarder/33523 "2015-11-02T14:30:20Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![incogniro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incogniro/32/5875_2.png) [@incogniro](https://discuss.elastic.co/u/incogniro)\
**Post date:** [November 2, 2015, 2:30pm UTC](https://discuss.elastic.co/t/-grokparsefailure-and-missing-events-when-using-logstash-forwarder/33523/1 "2015-11-02T14:30:20Z")

</div>

I have a strange issue in which all events sent to Logstash via Logstash Forwarder using the Lumberjack input plugin are not indexed at all (completely missing, no indexes created in ElasticSearch) and a subset of the events result in \_grokparsefailure. However when the files are processed on the Logstash server locally using the File input plugin there is no issues and the indexes are created in ElasticSearch.

Input and output configurations are:  
`
input {
 # lumberjack {
 # port => 6782
 # ssl_certificate => '/etc/pki/tls/certs/logstash-forwarder.crt'
 # ssl_key => '/etc/pki/tls/private/logstash-forwarder.key'
 # }`

  file {  
    path =\> '/tmp/all-fuse-logs/\*'  
    start\_position =\> 'beginning'  
    type =\> 'karaf'  
    sincedb\_path =\> '/tmp/csms.sincedb'  
  }  
}  
elasticsearch { # Store event in datastore.  
    host =\> 'abc-log.def.ghi'  
    index =\> "logstash-%{+YYYY.MM.dd}-%{host}-%{type}"  
}

Has anyone any idea what is going on and how I may proceed?

Thanks,

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 2, 2015, 2:32pm UTC](https://discuss.elastic.co/t/-grokparsefailure-and-missing-events-when-using-logstash-forwarder/33523/2 "2015-11-02T14:32:18Z")

</div>

Comment out the ES output and use a straight `stdout { codec => rubydebug }` to understand more of what's happening.

---

<div class="post-metadata">

**Author:** ![incogniro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incogniro/32/5875_2.png) [@incogniro](https://discuss.elastic.co/u/incogniro)\
**Post date:** [November 2, 2015, 2:54pm UTC](https://discuss.elastic.co/t/-grokparsefailure-and-missing-events-when-using-logstash-forwarder/33523/3 "2015-11-02T14:54:40Z")

</div>

Hi Magnus, also note that when I alter the matching pattern to:  
`
match => ['message', "%{GREEDYDATA:text}"]
`  
I still receive \_grokparsefailure when using the Logstash Forwarder shipper.  
I will give your suggestion a try.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:24am UTC](https://discuss.elastic.co/t/-grokparsefailure-and-missing-events-when-using-logstash-forwarder/33523/4 "2017-07-06T05:24:29Z")

</div>


