# Example in the 0-60 video, cannot reproduce

**URL:** <https://discuss.elastic.co/t/example-in-the-0-60-video-cannot-reproduce/1306>\
**Category:** Logstash\
**Created:** [May 26, 2015, 11:22am UTC](https://discuss.elastic.co/t/example-in-the-0-60-video-cannot-reproduce/1306 "2015-05-26T11:22:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Paolo](https://avatars.discourse-cdn.com/v4/letter/p/6f9a4e/32.png) [@Paolo](https://discuss.elastic.co/u/Paolo)\
**Post date:** [May 26, 2015, 11:22am UTC](https://discuss.elastic.co/t/example-in-the-0-60-video-cannot-reproduce/1306/1 "2015-05-26T11:22:54Z")

</div>

Hello All,  
I am a newbie, my aim is to analyze some log  
files created with the "liferay" environment.  
As a test I was trying to reproduce the log analysis of the 0-60 video.  
I copied both the log and the config file from the video (but for the shield plugin),  
I have installed logstash 1.5 and elasticsearch 1.5.1,  
however logstash seems to be unable to recognize the log.  
Am I missing something obvious?

I attach here the log, and the result lt:

71.141.244.242 - kurt [18/May/2011:01:48:10 -0700] "GET /admin HTTP/1.1" 301 566 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3"  
{  
"message" =\> "71.141.244.242 - kurt [18/May/2011:01:48:10 -0700] "GET /admin HTTP/1.1" 301 566 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.3) Gecko/20100401 Firefox/3.6.3" ",  
"@version" =\> "1",  
"@timestamp" =\> "2015-05-26T09:31:42.224Z",  
"host" =\> "localhost.localdomain",  
"tags" =\> [  
[0] "\_grokparsefailure"  
],  
"useragent" =\> {  
"name" =\> "Other",  
"os" =\> "Other",  
"os\_name" =\> "Other",  
"device" =\> "Other"  
}  
}

here is the config file.

input {  
stdin{ }  
}  
filter {  
grok{  
match =\>{  
"message" =\> '%{IPORHOST:clientip} %{USER:ident} %{USER:auth} [%{HTTPDATE:timestamp}]  
"%{WORD:verb} %{DATA:request} HTTP/%{NUMBER:httpversion}" %{NUMBER:response:int} (?:-|%{NUMBER:bytes:int}) %{QS:referrer} %{QS:agen  
t}'  
}  
}  
date {  
match =\> ["timestamp", "dd/MM/YYYY:HH:mm:ss Z"]  
locale =\> en  
}  
geoip{  
source =\> "clientip"  
}  
useragent{  
source =\> "agent"  
target =\> "useragent"  
}  
}

output {  
stdout {codec =\> rubydebug}  
elasticsearch {  
protocol =\> "http"  
host =\> "localhost"  
}  
}

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 27, 2015, 12:36am UTC](https://discuss.elastic.co/t/example-in-the-0-60-video-cannot-reproduce/1306/2 "2015-05-27T00:36:19Z")

</div>

Have a play around with [http://grokdebug.herokuapp.com/](http://grokdebug.herokuapp.com/) and see if you can get the event matched up with the grok pattern.

It's a great way to learn how things work.

---

<div class="post-metadata">

**Author:** ![Paolo](https://avatars.discourse-cdn.com/v4/letter/p/6f9a4e/32.png) [@Paolo](https://discuss.elastic.co/u/Paolo)\
**Post date:** [May 27, 2015, 10:56am UTC](https://discuss.elastic.co/t/example-in-the-0-60-video-cannot-reproduce/1306/3 "2015-05-27T10:56:03Z")

</div>

Thank you Mark, I was missing some spaces in the conf file and this was confusing grok.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:39am UTC](https://discuss.elastic.co/t/example-in-the-0-60-video-cannot-reproduce/1306/4 "2017-07-06T05:39:13Z")

</div>


