# Fields matched but still Grokparsefaliure?

**URL:** <https://discuss.elastic.co/t/fields-matched-but-still-grokparsefaliure/201642>\
**Category:** Logstash\
**Created:** [September 30, 2019, 1:08pm UTC](https://discuss.elastic.co/t/fields-matched-but-still-grokparsefaliure/201642 "2019-09-30T13:08:41Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dan\_Kennedy](https://avatars.discourse-cdn.com/v4/letter/d/e0b2c6/32.png) [@Dan\_Kennedy](https://discuss.elastic.co/u/Dan_Kennedy)\
**Post date:** [September 30, 2019, 1:08pm UTC](https://discuss.elastic.co/t/fields-matched-but-still-grokparsefaliure/201642/1 "2019-09-30T13:08:41Z")

</div>

Hi. I am using logstash to collect infrastructure logs but seem to be having an issue. I used a groktest site to check the pattern which appears fine. But in logstash I can see I'm getting a \_grokparsefailure.

Can someone please point me in the correct direction?

Sample line from a devices is

\<187\>Sep 30 2019 12:41:08 cpe.test.one %%01INFO/3/SUPPRESS\_LOG(l)[21617]:Last message repeated 2 times.(InfoID=1086394383, ModuleName=SRM, InfoAlias=TXPOWER\_EXCEEDMINOR)

grok pattern is

(\<%{INT}\>)?%{DATE\_HUAWEI\_EXTRA:syslog\_timestamp} %{HOSTNAME\_EXTRA:syslog\_host} %{PROGRAM\_EXTRA:syslog\_program}/%{NUMBER:syslog\_severity}/%{TYPE\_EXTRA:syslog\_type}%{HUAWEI\_END\_1\_EXTRA} ?%{ANY\_EXTRA\_3:msg\_text}

custom patterns are

HOSTNAME\_EXTRA [A-Za-z\_0-9.]+  
HOSTNAME\_IP\_EXTRA (%{HOSTNAME\_EXTRA}|%{IP})  
PROGRAM\_EXTRA %%[\d]+[A-Z\_a-z-]+  
PROGRAM\_EXTRA\_2 %[A-Za-z]+  
TYPE\_EXTRA \b[A-Za-z\_-]+\b  
TYPE\_EXTRA\_2 [A-Za-z\_]+  
ANY\_EXTRA [A-Za-z0-9\_:.\s]+  
DATE\_HUAWEI\_EXTRA %{MONTH} +%{MONTHDAY} %{YEAR} %{TIME}  
DATE\_HUAWEI\_ONE\_EXTRA %{YEAR}-%{MONTHNUM}-%{MONTHDAY}[T]%{HOUR}:%{MINUTE}:%{SECOND}+00:00  
DATE\_HUAWEI\_2\_EXTRA %{YEAR}-%{MONTHNUM}-%{MONTHDAY}T%{HOUR}:%{MINUTE}:%{SECOND}.([0-9]+)Z  
DATESTAMP\_HUAWEI\_EXTRA (%{TIMESTAMP\_ISO8601}|%{DATE\_HUAWEI\_ONE\_EXTRA}|%{DATE\_HUAWEI\_2\_EXTRA})  
DATE\_CISCO\_EXTRA %{MONTH} +%{MONTHDAY} %{HOUR}:%{MINUTE}:%{SECOND}.%{INT}  
HUAWEI\_END\_1\_EXTRA ([a-z])([^:]+)?:  
ANY\_EXTRA\_3 (.\*)

---

<div class="post-metadata">

**Author:** ![Dan\_Kennedy](https://avatars.discourse-cdn.com/v4/letter/d/e0b2c6/32.png) [@Dan\_Kennedy](https://discuss.elastic.co/u/Dan_Kennedy)\
**Post date:** [September 30, 2019, 10:12pm UTC](https://discuss.elastic.co/t/fields-matched-but-still-grokparsefaliure/201642/2 "2019-09-30T22:12:32Z")

</div>

Ok, I found the cause to this, but I don't understand why.

I have another logstash input from filebeats for capturing fail2ban logs. When this is enabled (separate input port etc) I get \_grokparsefailure for this network logs. If I remove the filebeats.conf file and stop that input, the logs are fine and there is no grokparsefailure.

So I assume its trying to match both of these at some point? Can anyone suggest a cause?

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 30, 2019, 10:15pm UTC](https://discuss.elastic.co/t/fields-matched-but-still-grokparsefaliure/201642/3 "2019-09-30T22:15:21Z")

</div>

If you have two configuration files, each containing input, filter, and output sections, then if they are running in the same pipeline, events from both inputs are sent through both sets of filters and written to both outputs. If you want them to be self contained you can use conditionals, or multiple pipelines.

---

<div class="post-metadata">

**Author:** ![Dan\_Kennedy](https://avatars.discourse-cdn.com/v4/letter/d/e0b2c6/32.png) [@Dan\_Kennedy](https://discuss.elastic.co/u/Dan_Kennedy)\
**Post date:** [September 30, 2019, 10:57pm UTC](https://discuss.elastic.co/t/fields-matched-but-still-grokparsefaliure/201642/4 "2019-09-30T22:57:07Z")

</div>

That worked 🙂

Thanks for the tip.

Dan.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 28, 2019, 11:05pm UTC](https://discuss.elastic.co/t/fields-matched-but-still-grokparsefaliure/201642/5 "2019-10-28T23:05:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
