# Grok failure and Failed to parse query

**URL:** <https://discuss.elastic.co/t/grok-failure-and-failed-to-parse-query/137742>\
**Category:** Logstash\
**Created:** [June 28, 2018, 6:43am UTC](https://discuss.elastic.co/t/grok-failure-and-failed-to-parse-query/137742 "2018-06-28T06:43:38Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dave061](https://avatars.discourse-cdn.com/v4/letter/d/7feea3/32.png) [@Dave061](https://discuss.elastic.co/u/Dave061)\
**Post date:** [June 28, 2018, 6:43am UTC](https://discuss.elastic.co/t/grok-failure-and-failed-to-parse-query/137742/1 "2018-06-28T06:43:38Z")

</div>

Hello, Guys  
I'am trying couple of days to setup logstash 6.3.0 on Windows Server 2012 r2.I want to parse IIS logs version on IIS is (8.5.9600) to ElasticSearch.Here is my logstash config ---\>

input {  
file {  
type =\> "IISLog"  
path =\> "C:/inetpub/logs/LogFiles/W3SVC\*/\*.log"  
start\_position =\> "beginning"  
}  
}

filter {

```
if [message] =~ "^#" {
	drop {}
}

grok {
    match => ["message", "%{TIMESTAMP_ISO8601:log_timestamp} %{IPORHOST:site} %{WORD:method} %{URIPATH:page} %{NOTSPACE:querystring} %{NUMBER:port} %{NOTSPACE:username} %{IPORHOST:clienthost} %{NOTSPACE:useragent} (%{URI:referer})? %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:scstatus} %{NUMBER:time_taken}"]
}

date {
	match => ["log_timestamp", "YYYY-MM-dd HH:mm:ss"]
	timezone => "Etc/UCT"
}

useragent {
	source=> "useragent"
	prefix=> "browser_"
}

mutate {
	remove_field => ["log_timestamp"]
}

```

}

output {  
stdout { codec =\> rubydebug }  
elasticsearch { hosts =\> ["10.8.238.11:9200"] }  
}

But for some reason \_grokparsefailure

```
      "type" => "IISLog",
"@timestamp" => 2018-06-28T06:26:37.447Z,
      "tags" => [
    [0] "_grokparsefailure"
],
      "host" => "WIN-Example",
  "@version" => "1",
   "message" => "2018-06-28 05:22:23 W3SVC7 WIN-Example 1.1.1.1 GET

```

/api/sportmatch/Get sportID=2357 80 - 192.168.0.1 Mozilla/5.0+(Windows+NT+6.  
1;+WOW64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/64.0.3282.186+YaBrowser/  
18.3.1.1232+Yowser/2.5+Safari/537.36 [https://example.net/sport](https://example.net/sport)  
200 0 0 2759\r",  
"path" =\> "C:/inetpub/logs/LogFiles/W3SVC7/u\_ex180628.log"  
}  
{  
Elasticsearch version is 6.3.0

Output from Elastich search is

type": "query\_shard\_exception",  
"reason": "Failed to parse query [host:()]",  
"index\_uuid": "XCV-7yPnTdSpJXY-xD5sqA",  
"index": "logstash-2018.06.28"

Please help where am i wrong.Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 28, 2018, 6:50am UTC](https://discuss.elastic.co/t/grok-failure-and-failed-to-parse-query/137742/2 "2018-06-28T06:50:14Z")

</div>

The string

```
2018-06-28 05:22:23 W3SVC7 WIN-Example 1.1.1.1 GET

```

obviously doesn't match this grok expression:

```
%{TIMESTAMP_ISO8601:log_timestamp} %{IPORHOST:site} %{WORD:method} %{URIPATH:page} %{NOTSPACE:querystring} %{NUMBER:port} %{NOTSPACE:username} %{IPORHOST:clienthost} %{NOTSPACE:useragent} (%{URI:referer})? %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:scstatus} %{NUMBER:time_taken}

```

I'm pretty sure WIN-Example doesn't match WORD and it's not obvious that 1.1.1.1 matches URIPATH.

---

<div class="post-metadata">

**Author:** ![Dave061](https://avatars.discourse-cdn.com/v4/letter/d/7feea3/32.png) [@Dave061](https://discuss.elastic.co/u/Dave061)\
**Post date:** [June 28, 2018, 7:00am UTC](https://discuss.elastic.co/t/grok-failure-and-failed-to-parse-query/137742/3 "2018-06-28T07:00:16Z")

</div>

So how can i parse this message, there i get hostname which endpoint is requested ip on host and client broweser etc.. ☹

---

<div class="post-metadata">

**Author:** ![Dave061](https://avatars.discourse-cdn.com/v4/letter/d/7feea3/32.png) [@Dave061](https://discuss.elastic.co/u/Dave061)\
**Post date:** [June 28, 2018, 7:02am UTC](https://discuss.elastic.co/t/grok-failure-and-failed-to-parse-query/137742/4 "2018-06-28T07:02:30Z")

</div>

Example ISS log which i want to parse.

2018-06-25 20:13:43 W3SVC7 WIN-ExampleHost IP-AddressHost GET /ui/externallogin logintoken=&viewtype=Europe&oddformat=American&search=&lang=en-US&deviceType=desktop 80 - 162.158.122.130 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/67.0.3396.87+Safari/537.36 [https://www.example.site/esports](https://www.example.site/esports) 302 0 0 11927  
2018-06-25 20:13:44 W3SVC7 WIN-ExampleHost HostIP GET /UI - 80 - 162.158.122.130 Mozilla/5.0+(Windows+NT+6.3;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/67.0.3396.87+Safari/537.36 [https://www.examplesite.ag/esports](https://www.examplesite.ag/esports) 200 0 0 1448

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 28, 2018, 7:42am UTC](https://discuss.elastic.co/t/grok-failure-and-failed-to-parse-query/137742/5 "2018-06-28T07:42:15Z")

</div>

Perhaps NOTSPACE would be a better grok pattern to use. It matches any number of non-whitespace characters.

You might prefer to use a dissect or csv filter to parse this simple whitespace-separated log.

---

<div class="post-metadata">

**Author:** ![Dave061](https://avatars.discourse-cdn.com/v4/letter/d/7feea3/32.png) [@Dave061](https://discuss.elastic.co/u/Dave061)\
**Post date:** [June 28, 2018, 8:05am UTC](https://discuss.elastic.co/t/grok-failure-and-failed-to-parse-query/137742/6 "2018-06-28T08:05:33Z")

</div>

Okay, i made changes in iis logs to csv and separate with comma .Check log

162.158.210.14, -, 6/28/2018, 7:50:33, W3SVC7, WIN-BAEV4FMVCD5, 46.16.78.130, 7108, 763, 485, 200, 0, GET, /api/sportmatch/Get, categoryID=6445&sportID=2357,

Input LogStash --\>

```
     "host" => "WIN-BAEV4FMVCD5",
   "message" => "162.158.210.14, -, 6/28/2018, 8:02:13, W3SVC7, WIN-BAEV4FMV

```

CD5, 46.16.78.130, 49, 887, 2204, 200, 0, POST, /api/sportmatch/GetLive, isGetTo  
p=false&liveIds=%5B1185048%5D,\r",  
"@version" =\> "1",  
"type" =\> "IISLog",  
"tags" =\> [  
[0] "\_grokparsefailure"  
],  
"path" =\> "C:/inetpub/logs/LogFiles/W3SVC7/u\_in18062808.log",  
"@timestamp" =\> 2018-06-28T08:02:31.803Z  
}

And again [0] "\_grokparsefailure"

---

<div class="post-metadata">

**Author:** ![Dave061](https://avatars.discourse-cdn.com/v4/letter/d/7feea3/32.png) [@Dave061](https://discuss.elastic.co/u/Dave061)\
**Post date:** [June 28, 2018, 8:10am UTC](https://discuss.elastic.co/t/grok-failure-and-failed-to-parse-query/137742/7 "2018-06-28T08:10:17Z")

</div>

Is that mean grok filter is trying to parse message field.But there is no such field in iis log ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 28, 2018, 8:31am UTC](https://discuss.elastic.co/t/grok-failure-and-failed-to-parse-query/137742/8 "2018-06-28T08:31:01Z")

</div>

You didn't have to add the comma. The csv filter has a configurable delimiter.

I can't help with your `_grokparsefailure` if I don't know what your configuration looks like.

---

<div class="post-metadata">

**Author:** ![Dave061](https://avatars.discourse-cdn.com/v4/letter/d/7feea3/32.png) [@Dave061](https://discuss.elastic.co/u/Dave061)\
**Post date:** [June 28, 2018, 8:34am UTC](https://discuss.elastic.co/t/grok-failure-and-failed-to-parse-query/137742/9 "2018-06-28T08:34:10Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/e/6/e6430fd3f47cc7cbf23c3e5c0d38be34ce6e2abb.png)

I want this logging fields, should i have to choose W3C or ISS logs?

---

<div class="post-metadata">

**Author:** ![Dave061](https://avatars.discourse-cdn.com/v4/letter/d/7feea3/32.png) [@Dave061](https://discuss.elastic.co/u/Dave061)\
**Post date:** [June 28, 2018, 8:37am UTC](https://discuss.elastic.co/t/grok-failure-and-failed-to-parse-query/137742/10 "2018-06-28T08:37:57Z")

</div>

I think my grook filter now is trying to parse something, which is missing

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 28, 2018, 8:50am UTC](https://discuss.elastic.co/t/grok-failure-and-failed-to-parse-query/137742/11 "2018-06-28T08:50:54Z")

</div>

> I want this logging fields, should i have to choose W3C or ISS logs?

Either way. Logstash can parse either format.

---

<div class="post-metadata">

**Author:** ![Dave061](https://avatars.discourse-cdn.com/v4/letter/d/7feea3/32.png) [@Dave061](https://discuss.elastic.co/u/Dave061)\
**Post date:** [June 28, 2018, 9:08am UTC](https://discuss.elastic.co/t/grok-failure-and-failed-to-parse-query/137742/12 "2018-06-28T09:08:37Z")

</div>

Okay, I will use IIS logs

---

<div class="post-metadata">

**Author:** ![Dave061](https://avatars.discourse-cdn.com/v4/letter/d/7feea3/32.png) [@Dave061](https://discuss.elastic.co/u/Dave061)\
**Post date:** [June 28, 2018, 9:22am UTC](https://discuss.elastic.co/t/grok-failure-and-failed-to-parse-query/137742/13 "2018-06-28T09:22:14Z")

</div>

Can you help me to configure grok filter ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 28, 2018, 9:57am UTC](https://discuss.elastic.co/t/grok-failure-and-failed-to-parse-query/137742/14 "2018-06-28T09:57:31Z")

</div>

Then I need to know:

- What does your current configuration look like?
- What does your stdout output produce?

---

<div class="post-metadata">

**Author:** ![Dave061](https://avatars.discourse-cdn.com/v4/letter/d/7feea3/32.png) [@Dave061](https://discuss.elastic.co/u/Dave061)\
**Post date:** [June 28, 2018, 10:26am UTC](https://discuss.elastic.co/t/grok-failure-and-failed-to-parse-query/137742/15 "2018-06-28T10:26:05Z")

</div>

Thanks a lot ☀

Lets start from the begging.

I have one file first-pipeline.conf for logstash

input {  
file {  
type =\> "IISLog"  
path =\> "C:/inetpub/logs/LogFiles/W3SVC\*/\*.log"  
start\_position =\> "beginning"  
}  
}

filter {

if [message] =~ "^#" {  
drop {}  
}

grok {  
match =\> ["message", "%{TIMESTAMP\_ISO8601:log\_timestamp} %{IPORHOST:site} %{WORD:method} %{URIPATH:page} %{NOTSPACE:querystring} %{NUMBER:port} %{NOTSPACE:username} %{IPORHOST:clienthost} %{NOTSPACE:useragent} (%{URI:referer})? %{NUMBER:response} %{NUMBER:subresponse} %{NUMBER:scstatus} %{NUMBER:time\_taken}"]  
}

date {  
match =\> ["log\_timestamp", "YYYY-MM-dd HH:mm:ss"]  
timezone =\> "Etc/UCT"  
}

useragent {  
source=\> "useragent"  
prefix=\> "browser\_"  
}

mutate {  
remove\_field =\> ["log\_timestamp"]  
}  
}

output {  
stdout { codec =\> rubydebug }  
elasticsearch { hosts =\> ["10.8.238.11:9200"] }  
}

Elasticsearch.yml ----\>

# Set the bind address to a specific IP (IPv4 or IPv6):

# 

network.host: 10.8.238.11

# 

# Set a custom port for HTTP:

# 

http.port: 9200

# 

I use Grafana 5.0.0  
this is my Datasource config

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/f/ff9146b0f426b36439dd78ee6417cf09d4d1ec90.png)

I have already dashboard but i receive error

"root\_cause": [  
{  
"type": "query\_shard\_exception",  
"reason": "Failed to parse query [host:()]",  
"index\_uuid": "XCV-7yPnTdSpJXY-xD5sqA",  
"index": "logstash-2018.06.28"  
}  
],  
"type": "search\_phase\_execution\_exception",  
"reason": "all shards failed",  
"phase": "query",  
"grouped": true,  
"failed\_shards": [  
{  
"shard": 0,  
"index": "logstash-2018.06.28",  
"node": "SyyrXc0bS5CYpcVmGcaqGA",  
"reason": {  
"type": "query\_shard\_exception",  
"reason": "Failed to parse query [host:()]",  
"index\_uuid": "XCV-7yPnTdSpJXY-xD5sqA",  
"index": "logstash-2018.06.28",  
"caused\_by": {  
"type": "parse\_exception",  
"reason": "Cannot parse 'host:()': Encountered " ")" ") "" at line 1, column 6.\r\nWas expecting one of:\r\n ...\r\n "+" ...\r\n "-" ...\r\n ...\r\n "(" ...\r\n "\*" ...\r\n ...\r\n ...\r\n ...\r\n ...\r\n ...\r\n "[" ...\r\n "{" ...\r\n ...\r\n ...\r\n ",

---

<div class="post-metadata">

**Author:** ![Dave061](https://avatars.discourse-cdn.com/v4/letter/d/7feea3/32.png) [@Dave061](https://discuss.elastic.co/u/Dave061)\
**Post date:** [June 28, 2018, 11:11am UTC](https://discuss.elastic.co/t/grok-failure-and-failed-to-parse-query/137742/16 "2018-06-28T11:11:05Z")

</div>

Example log from iis Logging

162.158.210.14, -, 6/28/2018, 9:09:25, W3SVC7, WIN-BAEV4FMVCD5, 10.10.0.71, 58, 763, 485, 200, 0, GET, /api/sportmatch/Get, categoryID=3597&sportID=2357,  
162.158.210.14, -, 6/28/2018, 9:09:29, W3SVC7, WIN-BAEV4FMVCD5, 10.10.0.71, 14646, 773, 6474, 200, 0, GET, /sport/outrights, -,  
162.158.210.14, -, 6/28/2018, 9:09:29, W3SVC7, WIN-BAEV4FMVCD5, 10.10.0.71, 93, 695, 4205, 200, 0, GET, /signalr/hubs, -,

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 29, 2018, 6:20am UTC](https://discuss.elastic.co/t/grok-failure-and-failed-to-parse-query/137742/17 "2018-06-29T06:20:52Z")

</div>

> "reason": "Cannot parse 'host:()': Encountered " ")" ") "" at line 1, column 6.\r\nWas expecting one of:\r\n ...\r\n "+" ...\r\n "-" ...\r\n ...\r\n "(" ...\r\n "\*" ...\r\n ...\r\n ...\r\n ...\r\n ...\r\n ...\r\n "[" ...\r\n "{" ...\r\n ...\r\n ...\r\n ",

This looks more like a Grafana bug or configuration problem.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 27, 2018, 6:20am UTC](https://discuss.elastic.co/t/grok-failure-and-failed-to-parse-query/137742/18 "2018-07-27T06:20:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
