I have a problem. I use grok to parsing the document for special data, my problem with this is that I am facing a _grokparsefailure in some documents. When I compare them with documents where I get the result which I want, I can see no difference.
So my first question is, is there a possibility to see why I am getting the parsing error and my second question is, is it possible to say grok that he just parse a specific field?
If you want help with a grok filter then show us the filter and the event that does not match. Either the output from output { stdout { codec => rubydebug } } or copy an event from the JSON tab in Kibana.
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.