# \_grokparsefailure with date, but not without it

**URL:** <https://discuss.elastic.co/t/-grokparsefailure-with-date-but-not-without-it/80755>\
**Category:** Logstash\
**Created:** [March 30, 2017, 9:38pm UTC](https://discuss.elastic.co/t/-grokparsefailure-with-date-but-not-without-it/80755 "2017-03-30T21:38:45Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![yacovm](https://avatars.discourse-cdn.com/v4/letter/y/f17d59/32.png) [@yacovm](https://discuss.elastic.co/u/yacovm)\
**Post date:** [March 30, 2017, 9:38pm UTC](https://discuss.elastic.co/t/-grokparsefailure-with-date-but-not-without-it/80755/1 "2017-03-30T21:38:45Z")

</div>

Hi all.

I have an ELK container and I send logs to it using filebeats.  
root@20e13712ecb2:/# cat /etc/logstash/conf.d/02-beats-input.conf

> input {  
> beats {  
> port =\> 5044  
> ssl =\> false  
> ssl\_certificate =\> "/etc/pki/tls/certs/logstash-beats.crt"  
> ssl\_key =\> "/etc/pki/tls/private/logstash-beats.key"  
> }  
> }

> filter {  
> grok {  
> match =\> { 'message' =\> '(.\*)%{TIMESTAMP\_ISO8601:ttime} %{TZ} [%{DATA:module}] %{WORD:function} -\> %{WORD:loglevel}(.\*?) %{GREEDYDATA:message}' }  
> }

> date {  
> "match" =\> [  
> "ttime",  
> "yyyy-MM-dd HH:mm:ss.SSS",  
> "ISO8601"  
> ]  
> }  
> }

> output {  
> elasticsearch {  
> hosts =\> ["localhost:9200"]  
> }  
> if "\_grokparsefailure" in [tags] {  
> file { path =\> "/var/log/logstash/grokparsefailure.log" }  
> }  
> }

When I have the beats input config above, I get:

> beats\_input\_codec\_plain\_applied, \_grokparsefailure

In the tags field, on all log entries (the logs sent to the ELK container are formatted in the same way)  
I want, of course- to use the timestamp of the log entries to be the @timestamp in kibana.

When I delete the date {} block, the grok succeeds and the ttime field is evaluated successfully to values like '17-03-30 17:35:21.319', and the rest of the fields are also caught except that the message field is from some reason, the entire log entry.

Any advice would be appreciated.

Thanks and regards.

---

<div class="post-metadata">

**Author:** ![jordansissel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jordansissel/32/44957_2.png) [@jordansissel](https://discuss.elastic.co/u/jordansissel)\
**Post date:** [March 30, 2017, 9:41pm UTC](https://discuss.elastic.co/t/-grokparsefailure-with-date-but-not-without-it/80755/2 "2017-03-30T21:41:51Z")

</div>

Can you provide a sample log that results in \_grokparsefailure?

---

<div class="post-metadata">

**Author:** ![yacovm](https://avatars.discourse-cdn.com/v4/letter/y/f17d59/32.png) [@yacovm](https://discuss.elastic.co/u/yacovm)\
**Post date:** [March 30, 2017, 9:57pm UTC](https://discuss.elastic.co/t/-grokparsefailure-with-date-but-not-without-it/80755/3 "2017-03-30T21:57:45Z")

</div>

ESC[36m2017-03-30 17:44:51.331 EDT [cauthdsl] func1 -\> DEBU 2ccc5bESC[0m Gate evaluation succeeds: (&{N:1 policies:\<signed\_by:0 \> })  
as I said- all logs result in parse failures.  
[http://grokdebug.herokuapp.com/](http://grokdebug.herokuapp.com/) parses the above input and the pattern (.\*)%{TIMESTAMP\_ISO8601:ttime} %{TZ} [%{DATA:module}] %{WORD:function} -\> %{WORD:loglevel}(.\*?) %{GREEDYDATA:message}

---

<div class="post-metadata">

**Author:** ![yacovm](https://avatars.discourse-cdn.com/v4/letter/y/f17d59/32.png) [@yacovm](https://discuss.elastic.co/u/yacovm)\
**Post date:** [March 31, 2017, 4:28pm UTC](https://discuss.elastic.co/t/-grokparsefailure-with-date-but-not-without-it/80755/5 "2017-03-31T16:28:52Z")

</div>

Provided above

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 28, 2017, 4:29pm UTC](https://discuss.elastic.co/t/-grokparsefailure-with-date-but-not-without-it/80755/6 "2017-04-28T16:29:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
