# \_grokparsefailure even though the right patterns are there

**URL:** <https://discuss.elastic.co/t/-grokparsefailure-even-though-the-right-patterns-are-there/92153>\
**Category:** Logstash\
**Created:** [July 6, 2017, 6:09pm UTC](https://discuss.elastic.co/t/-grokparsefailure-even-though-the-right-patterns-are-there/92153 "2017-07-06T18:09:07Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![DanMa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danma/32/18970_2.png) [@DanMa](https://discuss.elastic.co/u/DanMa)\
**Post date:** [July 6, 2017, 6:09pm UTC](https://discuss.elastic.co/t/-grokparsefailure-even-though-the-right-patterns-are-there/92153/1 "2017-07-06T18:09:08Z")

</div>

Hey,

iam trying to build a syslog solution for my firewall.

I had built this two patterns:

`CISCOFW710006 %{WORD:protocol} (?:request|access) %{CISCO_ACTION:action} from %{IP:src_ip} to %{DATA:dst_interface}:%{IP:dst_ip}`

`CISCOFW710005 %{WORD:protocol} (?:request|access) %{CISCO_ACTION:action} from %{IP:src_ip}/%{INT:src_port} to %{DATA:dst_interface}:%{IP:dst_ip}/%{INT:dst_port}`

In the grok debugger is the first pattern matching with this cisco\_message:  
`VRRP request discarded from 190.12.13.14 to OUTSIDE:224.0.0.18`

The second pattern matches with this cisco\_message:  
`UDP request discarded from 192.168.1.1/64523 to DMZ703:255.255.255.255/69`

But if i try to use both pattern as a match like here:  
`grok { patterns_dir => ["/etc/logstash/conf.d/custom_patterns"] break_on_match => false match => ["cisco_message", "%{CISCOFW710005}", "cisco_message", "%{CISCOFW710006}", "cisco_message", "%{CISCOFW106016}", "cisco_message", "%{CISCOFW106017}", "cisco_message", "%{CISCOFW725001}"]`

then i get a \_grokparsefailure.

If i use only one of the patterns then it works.

It seems like the CISCOFW710005 pattern is also matching the other message but not completly but it tries and uses the false insted of the right pattern.

Has anybody a idea?

Best Regards

Daniel

---

<div class="post-metadata">

**Author:** ![DanMa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danma/32/18970_2.png) [@DanMa](https://discuss.elastic.co/u/DanMa)\
**Post date:** [July 11, 2017, 11:21am UTC](https://discuss.elastic.co/t/-grokparsefailure-even-though-the-right-patterns-are-there/92153/3 "2017-07-11T11:21:05Z")

</div>

Nobody a Idea?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 11, 2017, 11:25am UTC](https://discuss.elastic.co/t/-grokparsefailure-even-though-the-right-patterns-are-there/92153/4 "2017-07-11T11:25:30Z")

</div>

> [@DanMa](#):
>
> break\_on\_match =\> false

This means that all patterns listed will be attempted, and processing will not stop when there is a match. Can a message match multiple patterns? If not, you should change this to `true`.

---

<div class="post-metadata">

**Author:** ![Leandro\_Sampaio](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandro_sampaio/32/18409_2.png) [@Leandro\_Sampaio](https://discuss.elastic.co/u/Leandro_Sampaio)\
**Post date:** [July 11, 2017, 11:38am UTC](https://discuss.elastic.co/t/-grokparsefailure-even-though-the-right-patterns-are-there/92153/5 "2017-07-11T11:38:06Z")

</div>

Post a example .

---

<div class="post-metadata">

**Author:** ![DanMa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danma/32/18970_2.png) [@DanMa](https://discuss.elastic.co/u/DanMa)\
**Post date:** [July 20, 2017, 10:15am UTC](https://discuss.elastic.co/t/-grokparsefailure-even-though-the-right-patterns-are-there/92153/6 "2017-07-20T10:15:24Z")

</div>

These value `break_on_match => false`  
was only a test value. It is also not functioning without.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 17, 2017, 10:15am UTC](https://discuss.elastic.co/t/-grokparsefailure-even-though-the-right-patterns-are-there/92153/7 "2017-08-17T10:15:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
