I've been working on setting up my ELK stack for about the past two weeks. I must admit that I've cobbled together my instance based on various posts, how-to's, etc. Because of that, my configuration is probably a mess. That notwithstanding, my instance does work; I'm getting log data in Kibana from Windows, Linux, and ESXi (more on ESXi in another post here) servers.
However, for every single log event I'm capturing, I see _grokparsefailure in tags. I've read about, and tried, everything I can, but no joy. I can't get rid of _grokparsefailure.
I know this is a very lot to ask of you all, but I've posted all of my config files, including from logstash-forwarder and nxlog, here: http://pastebin.com/4hDae6bT. I would be most grateful if someone would take a look, and see where I've possibly created a condition that creates the _grokparsefailures. Or, to suggest another means by which I can get rid of them.