# \_grokparsefailure with collectd

**URL:** <https://discuss.elastic.co/t/-grokparsefailure-with-collectd/48762>\
**Category:** Logstash\
**Created:** [April 29, 2016, 4:18am UTC](https://discuss.elastic.co/t/-grokparsefailure-with-collectd/48762 "2016-04-29T04:18:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![vchav73](https://avatars.discourse-cdn.com/v4/letter/v/f475e1/32.png) [@vchav73](https://discuss.elastic.co/u/vchav73)\
**Post date:** [April 29, 2016, 4:18am UTC](https://discuss.elastic.co/t/-grokparsefailure-with-collectd/48762/1 "2016-04-29T04:18:56Z")

</div>

I have a simple config file:

```
input {
  udp {
	  port => 25826
    buffer_size => 1452
    codec => collectd { }
    type => "collectd"
  }
}
output {
	if [type] == "collectd" {
	  elasticsearch {
		  index => "collectd-%{+YYYY.MM.dd}"
	    hosts => ["127.0.0.1"]
	  }
  }
}

```

When I pull up the collectd index in Kibana I see that all the documents have a \_grokparsefailure tag. The logstash log file shows nothing.

I don't understand why I am seeing this, since this config doesn't use the grok plug in. There is another config file I'm using, which does use grok, but it uses a different index and the documents for it don't have the \_grokparsefailure tag.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 29, 2016, 5:38am UTC](https://discuss.elastic.co/t/-grokparsefailure-with-collectd/48762/2 "2016-04-29T05:38:54Z")

</div>

Is your other configuration file used in the same Logstash instance? If so you need to add conditionals to select which filters should apply to which events. Otherwise all outputs and all filters will apply to all events.

---

<div class="post-metadata">

**Author:** ![MrLee](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mrlee/32/9429_2.png) [@MrLee](https://discuss.elastic.co/u/MrLee)\
**Post date:** [April 29, 2016, 6:41am UTC](https://discuss.elastic.co/t/-grokparsefailure-with-collectd/48762/3 "2016-04-29T06:41:42Z")

</div>

As @magnusbaeck said, if you start logstash like `sudo /etc/init.d/logstash start`,you should pay attention to the argument `-f` if you have multiple config files.

```ruby
Usage:
    /bin/logstash agent [OPTIONS]

Options:
    -f, --config CONFIG_PATH Load the logstash config from a specific file
                                  or directory. If a directory is given, all
                                  files in that directory will be concatenated
                                  in lexicographical order and then parsed as a
                                  single config file. You can also specify
                                  wildcards (globs) and any matched files will
                                  be loaded in the order described above.

```

---

<div class="post-metadata">

**Author:** ![vchav73](https://avatars.discourse-cdn.com/v4/letter/v/f475e1/32.png) [@vchav73](https://discuss.elastic.co/u/vchav73)\
**Post date:** [April 29, 2016, 2:28pm UTC](https://discuss.elastic.co/t/-grokparsefailure-with-collectd/48762/4 "2016-04-29T14:28:27Z")

</div>

@magnusbaeck was right. I added an if around the grok in my other config and that's taken care of the problem.

I'm on a yum installation running CentOS 6, so I use "service logstash start". It's set up to use whatever's in /etc/logstash/conf.d/. for configs.

Thanks for the suggestions.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:59am UTC](https://discuss.elastic.co/t/-grokparsefailure-with-collectd/48762/5 "2017-07-06T04:59:58Z")

</div>


