# Getting grokfailure, but grok constructor test works

**URL:** https://discuss.elastic.co/t/getting-grokfailure-but-grok-constructor-test-works/54331
**Category:** Logstash
**Created:** [June 29, 2016, 8:48pm UTC](https://discuss.elastic.co/t/getting-grokfailure-but-grok-constructor-test-works/54331 "2016-06-29T20:48:13Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![stecino](https://avatars.discourse-cdn.com/v4/letter/s/ea666f/32.png) [@stecino](https://discuss.elastic.co/u/stecino)
#### Post date: [June 29, 2016, 8:48pm UTC](https://discuss.elastic.co/t/getting-grokfailure-but-grok-constructor-test-works/54331/1 "2016-06-29T20:48:13Z")

</div>

Hello,

I am getting this discrepancy between [http://grokconstructor.appspot.com/do/match](http://grokconstructor.appspot.com/do/match) and logstash grok filter. In the grok constructor site I am getting following parsed:

"10.1.40.20 22.77.167.65 - [29/Jun/2016:19:07:42 +0000] "GET /de-soto-mo/real-estate-appraisers HTTP/1.1" 200 29960 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" "-" 0.701"

using following pattern:

"%{IPORHOST:remote\_addr} %{IPORHOST:http\_x\_forwarded\_for} - [%{HTTPDATE:timestamp}]\ \"%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}\" %{NUMBER:response} (?:%{NUMBER:bytes}|undefined) \"(%{URI:referrer}|-)\" \"%{DATA:agent}\" \"%{DATA:cookie}\" %{NUMBER:response\_time}"

When I run logstash with following grok filter

```
       grok {
            break_on_match => false
            match => ["message", "%{IPORHOST:remote_addr} %{IPORHOST:http_x_forwarded_for} - \[%{HTTPDATE:timestamp}]\ \\"%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}\\" %{NUMBER:response} (?:%{NUMBER:bytes}|undefined) \\"(%{URI:referrer}|-)\\" \\"%{DATA:agent}\\" \\"%{DATA:cookie}\\" %{NUMBER:response_time}" ]
           }

```

I am getting

{  
"@timestamp" =\> "2016-06-29T19:07:43.060Z",  
"input\_type" =\> "log",  
"message" =\> "10.1.40.20 22.77.167.65 - [29/Jun/2016:19:07:42 +0000] "GET /de-soto-mo/real-estate-appraisers HTTP/1.1" 200 29960 "-" "Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)" "-" 0.701",  
"offset" =\> 8039375,  
"source" =\> "/usr/local/nextgen/ypu-logs/access.log",  
"type" =\> "nginx",  
"@version" =\> "1",  
"kafka" =\> {  
"msg\_size" =\> 448,  
"topic" =\> "ypu-logs-wc1",  
"consumer\_group" =\> "logstash",  
"partition" =\> 7,  
"key" =\> nil  
},  
"nginx\_host" =\> "[blah.com](http://blah.com)",  
**"tags" =\> [**  
\*\* [0] "\_grokparsefailure"\*\*  
]  
}

Any reason why this is the case?

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [June 30, 2016, 10:48am UTC](https://discuss.elastic.co/t/getting-grokfailure-but-grok-constructor-test-works/54331/2 "2016-06-30T10:48:25Z")

</div>

Start with the simplest possible expression, `%{IPORHOST:remote_addr}` and see if it works. If yes, add the next token to the end of the expression. If no, you've found the problem. Repeat.

---

<div class="post-metadata">

### Author: ![stecino](https://avatars.discourse-cdn.com/v4/letter/s/ea666f/32.png) [@stecino](https://discuss.elastic.co/u/stecino)
#### Post date: [June 30, 2016, 5:17pm UTC](https://discuss.elastic.co/t/getting-grokfailure-but-grok-constructor-test-works/54331/3 "2016-06-30T17:17:40Z")

</div>

That's what I have done on the grok testing site, after which I have implemented this in logstash. And that's where it's failing. I don't have any custom patterns

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 4:50am UTC](https://discuss.elastic.co/t/getting-grokfailure-but-grok-constructor-test-works/54331/4 "2017-07-06T04:50:06Z")

</div>


