# \_grokparsefailure when not using grok

**URL:** <https://discuss.elastic.co/t/-grokparsefailure-when-not-using-grok/54883>\
**Category:** Logstash\
**Created:** [July 7, 2016, 1:06am UTC](https://discuss.elastic.co/t/-grokparsefailure-when-not-using-grok/54883 "2016-07-07T01:06:21Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![memelet](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@memelet](https://discuss.elastic.co/u/memelet)\
**Post date:** [July 7, 2016, 1:06am UTC](https://discuss.elastic.co/t/-grokparsefailure-when-not-using-grok/54883/1 "2016-07-07T01:06:21Z")

</div>

I'm using file to ingest consul-template logs

```
  input {
    file {
      type => "consul-template"
      path => ["/var/log/consul-template.log"]
      add_field => { "name" => "consul-template" }
    }
  }

```

For every log message \_grokparsefailure is tagged -- but I'm not using grok. What could be causing that?

The rest of the pipeline on the host with the logs:

```
output {
  rabbitmq {
    host => "rabbitmq.service.ops.consul"
    port => {{rabbitmq_port}}
    user => "{{elk_rabbitmq_logstash_user}}"
    password => "{{elk_rabbitmq_logstash_password}}"
    vhost => "logstash"
    exchange => "logs_json"
    exchange_type => "direct"
    durable => true
  }
}

```

The pipeline on the ingest node:

```
  input {
    rabbitmq {
      host => "localhost"
      port => {{rabbitmq_port}}
      user => "{{elk_rabbitmq_logstash_user}}"
      password => "{{elk_rabbitmq_logstash_password}}"
      vhost => "logstash"
      exchange => "logs_json"
      queue => "logs_json"
      threads => 3
      codec => json
    }
  }

  output {
      elasticsearch {
        hosts => "{{ elasticsearch_consul_service }}"
        workers => 6
        manage_template => true
        template => "{{logstash_es_templates_dir}}/es-logstash-mappings-template.json"
        template_name => "logstash-vimana"
        template_overwrite => true
      }
    }
  }

```

Could it be the code=\>json in the rabbitmq input?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 7, 2016, 5:41am UTC](https://discuss.elastic.co/t/-grokparsefailure-when-not-using-grok/54883/2 "2016-07-07T05:41:44Z")

</div>

Logstash will read _all_ configuration files in directories where it looks for configuration files. Do you have any files in /etc/logstash/conf.d that you've forgotten about? Perhaps a file with a grok filter?

---

<div class="post-metadata">

**Author:** ![memelet](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@memelet](https://discuss.elastic.co/u/memelet)\
**Post date:** [July 8, 2016, 4:52am UTC](https://discuss.elastic.co/t/-grokparsefailure-when-not-using-grok/54883/3 "2016-07-08T04:52:32Z")

</div>

Nothing that I can find. All our logstash filters are provisioned by ansible. And the play deletes any configs that are no longer in the play. I'll keep poking around though.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 8, 2016, 5:21am UTC](https://discuss.elastic.co/t/-grokparsefailure-when-not-using-grok/54883/4 "2016-07-08T05:21:59Z")

</div>

Hmm. Logstash dumps its configuration upon startup if you start it with `--debug`. Grep that output for "grok" might be useful.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:49am UTC](https://discuss.elastic.co/t/-grokparsefailure-when-not-using-grok/54883/5 "2017-07-06T04:49:00Z")

</div>


