# Can't parse my data logs- -getting \_grokparsefailure

**URL:** <https://discuss.elastic.co/t/cant-parse-my-data-logs-getting-grokparsefailure/127056>\
**Category:** Logstash\
**Created:** [April 6, 2018, 8:50am UTC](https://discuss.elastic.co/t/cant-parse-my-data-logs-getting-grokparsefailure/127056 "2018-04-06T08:50:38Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sara\_Hemmi](https://avatars.discourse-cdn.com/v4/letter/s/b77776/32.png) [@Sara\_Hemmi](https://discuss.elastic.co/u/Sara_Hemmi)\
**Post date:** [April 6, 2018, 8:50am UTC](https://discuss.elastic.co/t/cant-parse-my-data-logs-getting-grokparsefailure/127056/1 "2018-04-06T08:50:38Z")

</div>

Hello , any body can help me please to parse this log file (https\_access files from apache tomcat) , i've try with many patterns but i always get ["\_grokparsefailure"]

Those are two lines from my data logs :

172.23.10.200 46802 172.23.12.8 8084 172.23.10.200 POST - /PitneyBowse/Kering\_Validate/MailingAddressPro 2208 2.208 2208 http-nio-8084-exec-36 - [05/Apr/2018:08:04:39 +0200] 200 704 - Apache-HttpClient/4.2.1 (java 1.5)

172.23.10.200 46732 172.23.12.8 8084 172.23.10.200 GET - ?q=organization.brand:"BV"+AND+name.last.local:(Koushik+OR+Koushik\*)&&fl=client\_id,name.last.local,num,phone.home.num,activity.registr\_store /IODSTranscodes/diods1/customerv2 35 0.035 35 http-nio-8084-exec-36 - [05/Apr/2018:08:26:31 +0200] 200 11761 - Java/1.7.0\_85

this is pattern that i use in grok :

grok {  
match =\> { "message" =\>"%{IP:address\_ip\_source} %{INT:port1} %{IP:address\_ip\_dest} %{INT:port2} %{IP:address\_ip\_source\_dbl} %{WORD:request\_method} - %{GREEDYDATA:message\_or-request} %{INT:port3} %{NUMBER:duration} %{INT:port4} %{GREEDYDATA:http-nio} - %{TIMESTAMP\_ISO8601:timestamp} %{INT:response\_http\_status\_code} %{INT:nbr} %{GREEDYDATA:extra\_msg} %{GREEDYDATA:extra\_msg}"  
}  
}

thank you.

---

<div class="post-metadata">

**Author:** ![Evesy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evesy/32/29520_2.png) [@Evesy](https://discuss.elastic.co/u/Evesy)\
**Post date:** [April 6, 2018, 3:54pm UTC](https://discuss.elastic.co/t/cant-parse-my-data-logs-getting-grokparsefailure/127056/2 "2018-04-06T15:54:17Z")

</div>

Hey Sara,

It looks like the timestamp you're trying to grok for is not a valid ISO 8601 format so it won't match the grok filter you're using:

`TIMESTAMP_ISO8601 %{YEAR}-%{MONTHNUM}-%{MONTHDAY}[T]%{HOUR}:?%{MINUTE}(?::?%{SECOND})?%{ISO8601_TIMEZONE}?`

Perhaps try using `\[%{HTTPDATE:timestamp}\]` instead of `{TIMESTAMP_ISO8601:timestamp}`. It looks like it should parse correctly:

Data:  
`[05/Apr/2018:08:04:39 +0200]`

Pattern:  
`\[%{HTTPDATE:timestamp}\]`

Output:

```
{
  "timestamp": "05/Apr/2018:08:04:39 +0200"
}

```

I've tested on both your example data sets and it's parsing correctly, let me know if that works for you.

Cheers,  
Mike

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 4, 2018, 3:54pm UTC](https://discuss.elastic.co/t/cant-parse-my-data-logs-getting-grokparsefailure/127056/3 "2018-05-04T15:54:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
