# \_grokparsefailure tag not removed

**URL:** <https://discuss.elastic.co/t/-grokparsefailure-tag-not-removed/87292>\
**Category:** Logstash\
**Created:** [May 26, 2017, 7:30pm UTC](https://discuss.elastic.co/t/-grokparsefailure-tag-not-removed/87292 "2017-05-26T19:30:55Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mikygee](https://avatars.discourse-cdn.com/v4/letter/m/57b2e6/32.png) [@mikygee](https://discuss.elastic.co/u/mikygee)\
**Post date:** [May 26, 2017, 7:30pm UTC](https://discuss.elastic.co/t/-grokparsefailure-tag-not-removed/87292/1 "2017-05-26T19:30:55Z")

</div>

Hello,

I'm strugling to get rid of these \_grokparsefailure tags

Case 1:  
Message  
1.1.1.1 - - [26/May/2017:21:24:04 +0200] "GET /plugins/jqueryui/themes/classic/jquery-ui-1.10.4.custom.css?s=1450862292 HTTP/1.1" 200 6284 "[https://server.domain.org/?\_task=mail&\_mbox=INBOX](https://server.domain.org/?_task=mail&_mbox=INBOX)" "Opera/9.80 (Windows NT 6.1; Win64; x64) Presto/2.12.388 Version/12.18"

Config

```auto
filter {
  if [program] == "nginx" {
    grok {
        break_on_match => true
        patterns_dir => "/etc/logstash/conf.d/patterns"
       match => ["message", "%{IPORHOST:remote_addr} - - \[%{HTTPDATE:time_local}\] %{QS:request} %{INT:status} %{INT:body_bytes_sent} %{QS:http_referer} %{QS:http_user_agent}" ]
        add_tag => ["_grok_nginx_access_success"]
        add_tag => ["Web"]
        add_tag => ["nginx_access"]
        remove_tag => ["_grokparsefailure"]
    }
  }
}

```

Result: The tags are added, the informations are extracted but \_grokparsefailure is not removed

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 29, 2017, 5:21am UTC](https://discuss.elastic.co/t/-grokparsefailure-tag-not-removed/87292/2 "2017-05-29T05:21:17Z")

</div>

That's odd. Do you have another grok filter somewhere in your configuration? Keep in mind that Logstash reads _all_ files in /etc/logstash/conf.d.

If you don't want a grok filter to add a `_grokparsefailure` tag the typical way of avoiding it is setting `tag_on_failure` to an empty list. That doesn't appear to be the problem in your case since you're saying it's adding the tags, which indicates that the grok filter is successful.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 26, 2017, 5:21am UTC](https://discuss.elastic.co/t/-grokparsefailure-tag-not-removed/87292/3 "2017-06-26T05:21:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
