# Getting \_grokparsefailure as a tag

**URL:** <https://discuss.elastic.co/t/getting-grokparsefailure-as-a-tag/127263>\
**Category:** Logstash\
**Created:** [April 9, 2018, 7:11am UTC](https://discuss.elastic.co/t/getting-grokparsefailure-as-a-tag/127263 "2018-04-09T07:11:50Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![student](https://avatars.discourse-cdn.com/v4/letter/s/ecc23a/32.png) [@student](https://discuss.elastic.co/u/student)\
**Post date:** [April 9, 2018, 7:11am UTC](https://discuss.elastic.co/t/getting-grokparsefailure-as-a-tag/127263/1 "2018-04-09T07:11:50Z")

</div>

Hi

I was just wondering why i keep getting the tag \_grokparsefailure in my syslog messages?  
 ![Capture](https://us1.discourse-cdn.com/elastic/original/3X/5/e/5e26c6579973016d36deeafd4ce81c6d09ca473d.PNG)

My logstash config file looks like this

```
input {
  tcp {
    port => 5000
    type => syslog
  }
  udp {
    port => 5000
    type => syslog
  }
}

filter {
  if [type] == "syslog" {
    grok {
      match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?:
%{GREEDYDATA:syslog_message}" }
      add_field => ["received_at", "%{@timestamp}"]
      add_field => ["received_from", "%{host}"]
    }
    date {
      match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
    }
  }
}

output {
  elasticsearch {
 index => ["logstash_syslog_index"]
  hosts => ["localhost:9200"]
 }
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 9, 2018, 6:05pm UTC](https://discuss.elastic.co/t/getting-grokparsefailure-as-a-tag/127263/2 "2018-04-09T18:05:29Z")

</div>

> [@student](#):
>
> I was just wondering why i keep getting the tag \_grokparsefailure in my syslog messages?

Because the message field you show does not match the regexp you are giving to grok.

---

<div class="post-metadata">

**Author:** ![student](https://avatars.discourse-cdn.com/v4/letter/s/ecc23a/32.png) [@student](https://discuss.elastic.co/u/student)\
**Post date:** [April 13, 2018, 7:12am UTC](https://discuss.elastic.co/t/getting-grokparsefailure-as-a-tag/127263/3 "2018-04-13T07:12:46Z")

</div>

I'm fairly new to this so I don't understand your explanation. I took this logstash config from from [https://www.elastic.co/guide/en/logstash/current/config-examples.html](https://www.elastic.co/guide/en/logstash/current/config-examples.html)  
Could you try to lower your explanation level or give me a link where i can read up on this?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 13, 2018, 3:39pm UTC](https://discuss.elastic.co/t/getting-grokparsefailure-as-a-tag/127263/4 "2018-04-13T15:39:19Z")

</div>

> [@student](#):
>
> %{SYSLOGTIMESTAMP} %{SYSLOGHOST} %{DATA}(?:[%{POSINT}])?: %{GREEDYDATA}

That pattern, which is essentially what you are using, would match the kind of message I would expect to see on /var/log/syslog on a Solaris server. Those look like this:

```auto
May 11 10:40:48 scrooge disk-health-nurse[26783]: [ID 702911 user.error] m:SY-mon-full-500 c:H : partition health measures for /var did not suffice

```

But your message starts with a PRI, then has some number followed by a timestamp that appears to include a timezone name (unless you have a host called CET), which strikes me as rather not syslog.

Personally I would not even use grok for this. I think dissect is better (cheaper to run, easier to configure). With dissect I would use this (assuming CET is a timezone)

```auto
  dissect { mapping => { "message" => "<%{pri}>%{}: %{ts} %{+ts} %{+ts} %{+ts}: %{syslog_message}" } }
  date { match => ["ts", "MMM d HH:mm:ss ZZZ"] }

```

If you really want or need to use grok, start with something like this. If it really is a timezone you will need to glue it onto timestamp using mutate+add\_field before parsing it using date.

```auto
"<%{NUMBER}>%{NUMBER}: %{SYSLOGTIMESTAMP:syslog_timestamp} %{WORD:timezoneorhost}: %{GREEDYDATA:syslog_message}"

```

Note that in your date filter, you do not need two formats. You have

```auto
match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]

```

The first one should not have two spaces before the d, since your timestamp field does not. You can use

```auto
match => ["syslog_timestamp", "MMM d HH:mm:ss"]

```

since that will match both "Apr 9 08:46:53" and "Apr 19 08:46:53". I hope that helps.

---

<div class="post-metadata">

**Author:** ![student](https://avatars.discourse-cdn.com/v4/letter/s/ecc23a/32.png) [@student](https://discuss.elastic.co/u/student)\
**Post date:** [April 25, 2018, 9:12am UTC](https://discuss.elastic.co/t/getting-grokparsefailure-as-a-tag/127263/5 "2018-04-25T09:12:37Z")

</div>

Hi

I've tried your suggestion and after some tweaks i got it to work as i wanted, well almost. I've just have one question how can i get the severity level in dissect? As for now I get the PRI correctly, but I want to "translate" or somehow get the correct log level. Should I use Grok for this? Or is there some way in dissect?  
Once again thank you Badger for the reply and the help this far!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 25, 2018, 1:43pm UTC](https://discuss.elastic.co/t/getting-grokparsefailure-as-a-tag/127263/6 "2018-04-25T13:43:26Z")

</div>

If you want to translate the numeric PRI into a text string then the [translate filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html) is what to use.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 23, 2018, 1:43pm UTC](https://discuss.elastic.co/t/getting-grokparsefailure-as-a-tag/127263/7 "2018-05-23T13:43:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
