# Can't see \_grokparsefailure

**URL:** <https://discuss.elastic.co/t/cant-see-grokparsefailure/118645>\
**Category:** Logstash\
**Created:** [February 6, 2018, 12:37pm UTC](https://discuss.elastic.co/t/cant-see-grokparsefailure/118645 "2018-02-06T12:37:08Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![samiujan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/samiujan/32/23605_2.png) [@samiujan](https://discuss.elastic.co/u/samiujan)\
**Post date:** [February 6, 2018, 12:37pm UTC](https://discuss.elastic.co/t/cant-see-grokparsefailure/118645/1 "2018-02-06T12:37:08Z")

</div>

I am running Logstash 6.1.3, Elasticsearch 6.1.3 and Filebeat 6.1.2

I have a grok pattern that looks like this (notice the fail text in the middle)

```
 grok {
            match => { "message" => ["^%{IPORHOST:clientip} **fail** (?:%{USER:ident}|-) (?:%{USER:auth}|-) \[%{HTTPDATE:timestamp}\] \"(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawr
equest})\" %{NUMBER:response} (?:%{NUMBER:bytes}|-)" ] }
        }

```

When I read filebeat nginx data and output to stdout, it shows there is an error

```
"tags" => [
        [0] "beats_input_codec_plain_applied",
        [1] " **_grokparsefailure**",
        [2] "_geoip_lookup_failure"
    ],

```

But when I send the same output to elasticsearch, \_grokparsefailure is missing in the elasticsearch output

 ![11](https://us1.discourse-cdn.com/elastic/original/3X/7/2/72fa6668ed26cbbc1ce88f139403860206067d72.png)

Any idea why this is happening?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 6, 2018, 12:37pm UTC](https://discuss.elastic.co/t/cant-see-grokparsefailure/118645/2 "2018-03-06T12:37:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
