# Another mysterious work logstash with errors \_grokparsefailure

**URL:** <https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327>\
**Category:** Logstash\
**Created:** [June 30, 2023, 2:54pm UTC](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327 "2023-06-30T14:54:42Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![San9](https://avatars.discourse-cdn.com/v4/letter/s/a9adbd/32.png) [@San9](https://discuss.elastic.co/u/San9)\
**Post date:** [June 30, 2023, 2:54pm UTC](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327/1 "2023-06-30T14:54:42Z")

</div>

again I encounter a problem in the work of logstash, and specifically with grock. Everything is fine in the debugger, the messages are parsed, but as soon as I apply this configuration to the production, then these messages are received with errors, although the second part is successfully parsed. This is not the first time such a problem has occurred. Usually the problem in such cases was solved by restarting logstash, but now it does not work. Is it not stable for you there?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 30, 2023, 4:16pm UTC](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327/2 "2023-06-30T16:16:15Z")

</div>

grok debuggers are not grok and there are patterns that work differently in each of them. Show us your grok filter and an example of an event that gets a parse failure.

---

<div class="post-metadata">

**Author:** ![San9](https://avatars.discourse-cdn.com/v4/letter/s/a9adbd/32.png) [@San9](https://discuss.elastic.co/u/San9)\
**Post date:** [July 3, 2023, 8:55am UTC](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327/3 "2023-07-03T08:55:26Z")

</div>

Thanks for your reply.  
Example of a message to be parsed:

```auto
10.1.1.2.1688371819767.414890.G_B2C_BETA,07/03/2023 11:10:26.059,sf_sap_error.log,custom,err info,Type: Java Exception / Code:com.audium.server.AudiumException / Message: Incorrect syntax near 'янівка'.

```

Here is an example of my grock:

```auto
%{IP:ip}.%{IDCUST:id}.%{TEXCUST:app},%{TIMECUST:time},%{TEXCUST2:3rd_integration},%{TEXCUST:element},%{GREEDYDATA:fl},%{GREEDYDATA:msg}

```

Custom Patterns:

```auto
IDCUST \d+[^.].\d+[^.]
TIMECUST \d{2}/\d{2}/\d{4} %{TIME}
IP (?<![0-9])(?:(?:25[0-5]|2[0-4][0-9]|[0-1]?[0-9]{1,2})[.](?:25[0-5]|2[0-4][0-9]|[0-1]?[0-9]{1,2})[.](?:25[0-5]|2[0-4][0-9]|[0-1]?[0-9]{1,2})[.](?:25[0-5]|2[0-4][0-9]|[0-1]?[0-9]{1,2}))(?![0-9])
TEXCUST [a-zA-Z0-9-_]+
TEXCUST2 [a-zA-Z0-9-_ .]+|

```

My grok debugger and parsing messages:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/5/25ecca96a9016753621d1c3ee2015fa3aa50275c.png)

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [July 3, 2023, 9:28am UTC](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327/4 "2023-07-03T09:28:30Z")

</div>

> [@San9](#):
>
> `3rd_integration`

Have you tried without a number at begging? I.e. `%{TEXCUST2:integration}`

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 3, 2023, 12:36pm UTC](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327/5 "2023-07-03T12:36:30Z")

</div>

What does your Logstash configuration looks like?

Just tested your grok with the message shared and got no issue:

```auto
{
                "app" => "G_B2C_BETA",
         "@timestamp" => 2023-07-03T12:37:50.643684857Z,
               "time" => "07/03/2023 11:10:26.059",
    "3rd_integration" => "sf_sap_error.log",
                 "ip" => "10.1.1.2",
           "@version" => "1",
            "message" => "10.1.1.2.1688371819767.414890.G_B2C_BETA,07/03/2023 11:10:26.059,sf_sap_error.log,custom,err info,Type: Java Exception / Code:com.audium.server.AudiumException / Message: Incorrect syntax near 'янівка'.",
               "host" => "lab",
                 "id" => "1688371819767.414890",
                "msg" => "Type: Java Exception / Code:com.audium.server.AudiumException / Message: Incorrect syntax near 'янівка'.",
                 "fl" => "err info",
            "element" => "custom"
}

```

You need to share your Logstash configuration and some sample of messages that are not being parsed.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [July 3, 2023, 1:01pm UTC](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327/6 "2023-07-03T13:01:13Z")

</div>

I have tested [here](https://grokconstructor.appspot.com/do/match) and only error is in the 3rd\_integration field.

Might be related to LS version. @San9 which version LS do you have?

---

<div class="post-metadata">

**Author:** ![San9](https://avatars.discourse-cdn.com/v4/letter/s/a9adbd/32.png) [@San9](https://discuss.elastic.co/u/San9)\
**Post date:** [July 3, 2023, 1:16pm UTC](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327/7 "2023-07-03T13:16:42Z")

</div>

Config logstash

```auto
filter {
  if "cc-activity" in [tags] {
        if ([message] =~ "apm_g_999_release,data,floor_2,rep_BR=Передача показів: Покази прийнято") {
    grok {
           patterns_dir => ["/etc/logstash/conf.d/patterns"]
           match => {"message" => "%{IP:ip}.%{IDCUST:id}.%{TEXCUST:app},%{TIMECUST:time},%{TEXCUST2:3rd_integration},%{TEXCUST:element},%{GREEDYDATA:fl},%{GREEDYDATA:msg1}"}
             }
                kv {
                source => "msg1"
                field_split => ";"
                value_split => "="
                }
        }
        else if ([message] =~ "call_oem_put,data,RESP Fer") or ([message] =~ "sf_sap_error.call_db_parse_error,data,sap_Error,COUNT: 1 - 005") {
                    grok {
                        patterns_dir => ["/etc/logstash/conf.d/patterns"]
                        match => {"message" => "%{IP:ip}.%{IDCUST:id}.%{TEXCUST:app},%{TIMECUST:time},%{TEXCUST2:3rd_integration},%{TEXCUST:element},%{GREEDYDATA:fl},%{GREEDYDATA:msg}"}
             }
        }
        else if [message] =~ "sf_sap_error.call_db_parse_error,data,sap_Error,COUNT: 1 - 005" or [message] =~ "sf_sap_error.call_db_parse_error,data,sap_Error,COUNT: 1 - 002" or [message] =~ "sf_sap_error.call_db_parse_error,data,sap_Error,COUNT: 1 - 001" or [message] =~ "sf_sap_error.call_db_parse_error,data,sap_Error,COUNT: 2 - 533" or [message] =~ "sf_sap_error.log,custom,err info,Type:" {
                    grok {
                        patterns_dir => ["/etc/logstash/conf.d/patterns"]
                        match => {"message" => "%{IP:ip}.%{IDCUST:id}.%{TEXCUST:app},%{TIMECUST:time},%{TEXCUST2:3rd_integration},%{TEXCUST:element},%{GREEDYDATA:fl},%{GREEDYDATA:msg}"}
             }
        mutate {
                        add_tag => ["count"]
                }
        }
	}
 }

```

error message

```auto
10.1.1.2.1688388330123.466601.G_B2C_BETA,07/03/2023 15:45:31.348,sf_sap_error.log,custom,err info,Type: Java Exception / Code: com.audium.server.AudiumException / Message: XML parsing: line 0 character 0 unrecognized input signature

```

norm message

```auto
10.1.1.2.1688389540084.743428.G_B2C_BETA,07/03/2023 16:08:39.502,apm_g_999_release,data,floor_2,rep_BR=OK;v_App_Type=2C;v_OSR=OM;v_RAID=N;mok_Alive=Y;

```

and

```auto
10.1.1.2.1688389564428.743516.G_B2C_BETA,07/03/2023 16:08:20.141,call_oem_put,data,RESP Fer,Message OK.

```

---

<div class="post-metadata">

**Author:** ![San9](https://avatars.discourse-cdn.com/v4/letter/s/a9adbd/32.png) [@San9](https://discuss.elastic.co/u/San9)\
**Post date:** [July 3, 2023, 1:29pm UTC](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327/8 "2023-07-03T13:29:16Z")

</div>

Hi, My version - 8.3.3-1.  
My Grok Debugger parses messages without problems, but in the config itself there are problems with some of the messages that I wrote above.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 3, 2023, 1:46pm UTC](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327/9 "2023-07-03T13:46:28Z")

</div>

Can't replicate, the _error message_ works fine for me using that pipeline:

```auto
{
                 "fl" => "err info",
                "app" => "G_B2C_BETA",
         "@timestamp" => 2023-07-03T13:45:32.117177908Z,
               "time" => "07/03/2023 15:45:31.348",
           "@version" => "1",
               "host" => "lab",
            "message" => "10.1.1.2.1688388330123.466601.G_B2C_BETA,07/03/2023 15:45:31.348,sf_sap_error.log,custom,err info,Type: Java Exception / Code: com.audium.server.AudiumException / Message: XML parsing: line 0 character 0 unrecognized input signature",
                 "id" => "1688388330123.466601",
               "tags" => [
        [0] "count"
    ],
    "3rd_integration" => "sf_sap_error.log",
                "msg" => "Type: Java Exception / Code: com.audium.server.AudiumException / Message: XML parsing: line 0 character 0 unrecognized input signature",
                 "ip" => "10.1.1.2",
            "element" => "custom"
}

```

---

<div class="post-metadata">

**Author:** ![San9](https://avatars.discourse-cdn.com/v4/letter/s/a9adbd/32.png) [@San9](https://discuss.elastic.co/u/San9)\
**Post date:** [July 3, 2023, 3:00pm UTC](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327/10 "2023-07-03T15:00:35Z")

</div>

I also can’t find a pattern when in the same config some conditions work, and these are some gaps that cannot be reproduced in the test environment

---

<div class="post-metadata">

**Author:** ![San9](https://avatars.discourse-cdn.com/v4/letter/s/a9adbd/32.png) [@San9](https://discuss.elastic.co/u/San9)\
**Post date:** [July 5, 2023, 1:35pm UTC](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327/11 "2023-07-05T13:35:21Z")

</div>

Anyone else have any ideas why this isn't working as it should?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 5, 2023, 1:48pm UTC](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327/12 "2023-07-05T13:48:38Z")

</div>

Without more information is pretty hard to suggest anything, the message you share was parsed without any issue on my test.

Can you shared how it looks like in Kibana, in the Json tab on discover for a document that should've been parsed, but wasn't?

---

<div class="post-metadata">

**Author:** ![San9](https://avatars.discourse-cdn.com/v4/letter/s/a9adbd/32.png) [@San9](https://discuss.elastic.co/u/San9)\
**Post date:** [July 11, 2023, 12:29pm UTC](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327/13 "2023-07-11T12:29:06Z")

</div>

hi, this is what it looks like in kibana:

```auto
{
  "_index": "cvp-gcc-activity-2023.07",
  "_id": "1PTpRIkB8lGSjmELmGUp",
  "_version": 1,
  "_score": 0,
  "_source": {
    "event": {},
    "@timestamp": "2023-07-11T12:25:05.807Z",
    "message": "10.1.1.2.1689078291751.433472.G_B2C,07/11/2023 15:25:04.083,sf_sap_error.log,custom,err info,Type: Java Exception / Code: com.audium.server.AudiumException / Message: Incorrect syntax near '�'.",
    "input": {},
    "host": {
      "os": {}
    },
    "ecs": {},
    "log": {
      "file": {
        "path": "C:\\Cisco\\CVP\\VXMLServer\\applications\\G_B2C\\logs\\ActivityLog\\activity_log2023-07-11-14-32-52.txt"
      }
    },
    "@version": "1",
    "agent": {},
    "tags": [
      "gcc-activity",
      "beats_input_codec_plain_applied",
      "_grokparsefailure",
      "count",
      "lst02"
    ]
  },
  "fields": {
    "@timestamp": [
      "2023-07-11T12:25:05.807Z"
    ],
    "message.keyword": [
      "10.1.1.2.1689078291751.433472.G_B2C,07/11/2023 15:25:04.083,sf_sap_error.log,custom,err info,Type: Java Exception / Code: com.audium.server.AudiumException / Message: Incorrect syntax near '�'."
    ],
    "log.file.path": [
      "C:\\Cisco\\CVP\\VXMLServer\\applications\\G_B2C\\logs\\ActivityLog\\activity_log2023-07-11-14-32-52.txt"
    ],
    "@version": [
      "1"
    ],
    "tags.keyword": [
      "gcc-activity",
      "beats_input_codec_plain_applied",
      "_grokparsefailure",
      "count",
      "lst02"
    ],
    "@version.keyword": [
      "1"
    ],
    "message": [
      "10.1.1.2.1689078291751.433472.G_B2C,07/11/2023 15:25:04.083,sf_sap_error.log,custom,err info,Type: Java Exception / Code: com.audium.server.AudiumException / Message: Incorrect syntax near '�'."
    ],
    "log.file.path.keyword": [
      "C:\\Cisco\\CVP\\VXMLServer\\applications\\G_B2C\\logs\\ActivityLog\\activity_log2023-07-11-14-32-52.txt"
    ],
    "tags": [
      "gcc-activity",
      "beats_input_codec_plain_applied",
      "_grokparsefailure",
      "count",
      "lst02"
    ]
  }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 11, 2023, 4:42pm UTC](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327/14 "2023-07-11T16:42:35Z")

</div>

The grok patterns that you share will successfully parse the two messages that you say get \_grokparsefailure tags. That suggests that you are not actually running the configuration that you think you are running.

I suggest triple-checking whether the grok filters and custom patterns are correct in the production environment.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 11, 2023, 4:56pm UTC](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327/15 "2023-07-11T16:56:08Z")

</div>

Again I could not replicate your error.

I used the same filter you shared:

```auto
filter {
    if "cc-activity" in [tags] {
        if ([message] =~ "apm_g_999_release,data,floor_2,rep_BR=Передача показів: Покази прийнято") {
            grok {
                patterns_dir => ["/opt/logstash/patterns"]
                match => {"message" => "%{IP:ip}.%{IDCUST:id}.%{TEXCUST:app},%{TIMECUST:time},%{TEXCUST2:3rd_integration},%{TEXCUST:element},%{GREEDYDATA:fl},%{GREEDYDATA:msg1}"}
                add_tag => ["first-grok"]
            }
            kv {
                source => "msg1"
                field_split => ";"
                value_split => "="
            }
        } else if ([message] =~ "call_oem_put,data,RESP Fer") or ([message] =~ "sf_sap_error.call_db_parse_error,data,sap_Error,COUNT: 1 - 005") {
            grok {
                patterns_dir => ["/opt/logstash/patterns"]
                match => {"message" => "%{IP:ip}.%{IDCUST:id}.%{TEXCUST:app},%{TIMECUST:time},%{TEXCUST2:3rd_integration},%{TEXCUST:element},%{GREEDYDATA:fl},%{GREEDYDATA:msg}"}
                add_tag => ["second-grok"]
            }
        } else if [message] =~ "sf_sap_error.call_db_parse_error,data,sap_Error,COUNT: 1 - 005" or [message] =~ "sf_sap_error.call_db_parse_error,data,sap_Error,COUNT: 1 - 002" or [message] =~ "sf_sap_error.call_db_parse_error,data,sap_Error,COUNT: 1 - 001" or [message] =~ "sf_sap_error.call_db_parse_error,data,sap_Error,COUNT: 2 - 533" or [message] =~ "sf_sap_error.log,custom,err info,Type:" {
            grok {
                patterns_dir => ["/opt/logstash/patterns"]
                match => {"message" => "%{IP:ip}.%{IDCUST:id}.%{TEXCUST:app},%{TIMECUST:time},%{TEXCUST2:3rd_integration},%{TEXCUST:element},%{GREEDYDATA:fl},%{GREEDYDATA:msg}"}
                add_tag => ["third-grok"]
            }
            mutate {
                add_tag => ["count"]
            }
        }
    }
}

```

The only chage I made was to add a tag for each grok to see which one would parse it.

Then I created this sample file:

```auto
{ "tags": "gcc-activity", "message": "10.1.1.2.1689078291751.433472.G_B2C,07/11/2023 15:25:04.083,sf_sap_error.log,custom,err info,Type: Java Exception / Code: com.audium.server.AudiumException / Message: Incorrect syntax near '�'."}

```

And got this result:

```auto
{
                "app" => "G_B2C",
         "@timestamp" => 2023-07-11T15:36:25.538603884Z,
               "time" => "07/11/2023 15:25:04.083",
                 "fl" => "err info",
               "host" => "lab",
            "message" => "10.1.1.2.1689078291751.433472.G_B2C,07/11/2023 15:25:04.083,sf_sap_error.log,custom,err info,Type: Java Exception / Code: com.audium.server.AudiumException / Message: Incorrect syntax near '�'.",
                 "id" => "1689078291751.433472",
               "tags" => [
        [0] "gcc-activity",
        [1] "third-grok",
        [2] "count"
    ],
           "@version" => "1",
    "3rd_integration" => "sf_sap_error.log",
                "msg" => "Type: Java Exception / Code: com.audium.server.AudiumException / Message: Incorrect syntax near '�'.",
                 "ip" => "10.1.1.2",
            "element" => "custom"
}

```

I would suggest the same as @Badger, check if you are realy running the configuration you shared.

Also, add a different `tag_on_failure` for each grok to help troubleshoot which one is not working.

---

<div class="post-metadata">

**Author:** ![San9](https://avatars.discourse-cdn.com/v4/letter/s/a9adbd/32.png) [@San9](https://discuss.elastic.co/u/San9)\
**Post date:** [July 12, 2023, 1:37pm UTC](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327/16 "2023-07-12T13:37:24Z")

</div>

I sent the configuration from the working pipeline, which I currently have running. if I noticed in my two conditions, if else they use the same grock, if I choose another grock, then the situation repeats itself, it feels so good that in the messages I didn’t take into account the special symbol or something else. Since other messages are successfully parsed. I add tag outcc.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/5/8/58dc2edb64fc3cc6c4224aa86a094b8c18acae54.png)

---

<div class="post-metadata">

**Author:** ![San9](https://avatars.discourse-cdn.com/v4/letter/s/a9adbd/32.png) [@San9](https://discuss.elastic.co/u/San9)\
**Post date:** [July 12, 2023, 2:06pm UTC](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327/17 "2023-07-12T14:06:43Z")

</div>

I also noticed - when I added the tag "count-grok" you suggested to the configuration, I didn’t see it only that old one --"count"  
example:

```auto
        else if [message] =~ "sf_sap_error.call_db_parse_error,data,sap_Error,COUNT: 1 - 005" or [message] =~ "sf_sap_error.call_db_parse_error,data,sap_Error,COUNT: 1 - 002" or [message] =~ "sf_sap_error.call_db_parse_error,data,sap_Error,COUNT: 1 - 001" or [message] =~ "sf_sap_error.call_db_parse_error,data,sap_Error,COUNT: 2 - 533" or [message] =~ "sf_sap_error.log,custom,err info,Type:" {
                    grok {
                        patterns_dir => ["/etc/logstash/conf.d/patterns"]
                        match => {"message" => "%{IP:ip}.%{IDCUST:id}.%{TEXCUST:app},%{TIMECUST:time},%{TEXCUST2:3rd_integration},%{TEXCUST:element},%{GREEDYDATA:fl},%{GREEDYDATA:msg}"}
                        add_tag => ["count-grok"]
             }
        mutate {
                        add_tag => ["count"]
                }
        }

```

in kibana

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/8/08911ce5ee73c42180a0db9a20f6d4e0d787d8f3.png)

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 12, 2023, 2:09pm UTC](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327/18 "2023-07-12T14:09:20Z")

</div>

> [@San9](#):
>
> I also noticed - when I added the tag "count-grok" you suggested to the configuration, I didn’t see it only that old one --"count"

In this case, the tag _count-grok_ will only be added if that specific `grok` is successful.

Since you have many groks, first thing you should do is use a different [failure tag](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html#plugins-filters-grok-tag_on_failure) for each one so you can know exactly where it is failing.

---

<div class="post-metadata">

**Author:** ![San9](https://avatars.discourse-cdn.com/v4/letter/s/a9adbd/32.png) [@San9](https://discuss.elastic.co/u/San9)\
**Post date:** [July 12, 2023, 2:51pm UTC](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327/19 "2023-07-12T14:51:43Z")

</div>

> [@leandrojmp](#):
>
> Since you have many groks, first thing you should do is use a different [failure tag](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html#plugins-filters-grok-tag_on_failure) for each one so you can know exactly where it is failing.

I'm trying to do this, for each grock a separate tag.  
for that problematic message, I simplified and shortened the parsing of messages and everything went well ...  
now I will add one value to the parsing and look at what errors there will be.

```auto
match => {"message" => "%{IP:ip}.%{IDCUST:id}.%{TEXCUST:app},%{TIMECUST:time},%{GREEDYDATA:msg4}"}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 9, 2023, 2:52pm UTC](https://discuss.elastic.co/t/another-mysterious-work-logstash-with-errors-grokparsefailure/337327/20 "2023-08-09T14:52:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
