# Eliminating \_grokparsefailure

**URL:** <https://discuss.elastic.co/t/eliminating--grokparsefailure/40033>\
**Category:** Logstash\
**Created:** [January 25, 2016, 2:51pm UTC](https://discuss.elastic.co/t/eliminating--grokparsefailure/40033 "2016-01-25T14:51:05Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Diggy](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@Diggy](https://discuss.elastic.co/u/Diggy)\
**Post date:** [January 25, 2016, 2:51pm UTC](https://discuss.elastic.co/t/eliminating--grokparsefailure/40033/1 "2016-01-25T14:51:06Z")

</div>

Hello, all.

I've been working on setting up my ELK stack for about the past two weeks. I must admit that I've cobbled together my instance based on various posts, how-to's, etc. Because of that, my configuration is probably a mess. That notwithstanding, my instance does work; I'm getting log data in Kibana from Windows, Linux, and ESXi (more on ESXi in another post here) servers.

However, for every single log event I'm capturing, I see \_grokparsefailure in tags. I've read about, and tried, everything I can, but no joy. I can't get rid of \_grokparsefailure.

I know this is a very lot to ask of you all, but I've posted all of my config files, including from logstash-forwarder and nxlog, here: [http://pastebin.com/4hDae6bT](http://pastebin.com/4hDae6bT). I would be most grateful if someone would take a look, and see where I've possibly created a condition that creates the \_grokparsefailures. Or, to suggest another means by which I can get rid of them.

With thanks,

Diggy

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 25, 2016, 9:21pm UTC](https://discuss.elastic.co/t/eliminating--grokparsefailure/40033/2 "2016-01-25T21:21:09Z")

</div>

At least one cause of the `_grokparsefailure` tags everywhere is the fact that the grok filter with COMBINEDAPACHELOG is applied to all messages even though it'll obviously only apply to HTTP logs. Secondly you should probably match against the `message` field instead of `line`. This should work better:

```auto
if [type] == "apache-access" {
  grok {
    match => { "message" => "%{COMBINEDAPACHELOG}" }
  }
 
  date {
    match => ["timestamp", "dd/MMM/yyyy:HH:mm:ss Z"]
    locale => "en"
  }
}

```

You might have other filters that should be wrapped in conditionals. These two were the most obvious ones.

---

<div class="post-metadata">

**Author:** ![Diggy](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@Diggy](https://discuss.elastic.co/u/Diggy)\
**Post date:** [January 26, 2016, 8:35pm UTC](https://discuss.elastic.co/t/eliminating--grokparsefailure/40033/3 "2016-01-26T20:35:33Z")

</div>

Magnus,

Once again, you've helped solve the problem. Thank you so much.

Interestingly, syslog-generated logs from my Linux hosts don't contain the field "message" but, rather, "line". Thus, "match against the message field instead of line" wouldn't work. I don't know why that is. Any idea?

Diggy

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 27, 2016, 7:16am UTC](https://discuss.elastic.co/t/eliminating--grokparsefailure/40033/4 "2016-01-27T07:16:33Z")

</div>

logstash-forwarder sends the payload from a log file in the `line` field but Logstash itself has standardized on `message`.

You should drop logstash-forwarder in favor of Filebeat since the former is deprecated and not maintained.

---

<div class="post-metadata">

**Author:** ![Diggy](https://avatars.discourse-cdn.com/v4/letter/d/e99b99/32.png) [@Diggy](https://discuss.elastic.co/u/Diggy)\
**Post date:** [January 27, 2016, 4:13pm UTC](https://discuss.elastic.co/t/eliminating--grokparsefailure/40033/5 "2016-01-27T16:13:34Z")

</div>

Hi, Magnus.

Just an update that I've installed, and am successfully using, Filebeat in my Linux servers. Of course, I'm now seeing the "message" field, and have made the requisite changes in my logstash conf files.

Diggy

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:14am UTC](https://discuss.elastic.co/t/eliminating--grokparsefailure/40033/6 "2017-07-06T05:14:05Z")

</div>


