# Grok failure even after the fields were filtered out successfully

**URL:** <https://discuss.elastic.co/t/grok-failure-even-after-the-fields-were-filtered-out-successfully/110688>\
**Category:** Logstash\
**Created:** [December 7, 2017, 2:32pm UTC](https://discuss.elastic.co/t/grok-failure-even-after-the-fields-were-filtered-out-successfully/110688 "2017-12-07T14:32:17Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![George\_Cherian](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/george_cherian/32/25879_2.png) [@George\_Cherian](https://discuss.elastic.co/u/George_Cherian)\
**Post date:** [December 7, 2017, 2:32pm UTC](https://discuss.elastic.co/t/grok-failure-even-after-the-fields-were-filtered-out-successfully/110688/1 "2017-12-07T14:32:17Z")

</div>

Hi Everyone,

I am encountering the following problem: I have been filtering out the "Via\_IP1" field from "Via1" which matches on both grok debugger and grok constructor.But when running on logstash ,i could observe grokparsefailure in my tag.

i am using below grok filter ,

```
   grok{
         id => "grok5"
         match => {"via1" => "^(?:.*SIP/2.0/UDP)(?<Via_IP1>[\s]\d+.\d+.\d+.\d+)?(?:.*)?$" }
         }

```

Output:

```
"tags" => [
[0] "multiline",
[1] "_grokparsefailure"
],
"SipFromUser:" => "2002005498",
    "path" => "/var/log/prod_logs/XS/basatlxs01/XS_Invite.txt",
  "@timestamp" => 2017-12-07T14:26:42.313Z,
"channel:" => "Sip ",
    "via2" => " tag=0ee7cb75^M\nCall-ID: sAP9-qj5ZJVY4xLJ3f2DTg..^M\n",
    "via1" => "SIP/2.0^M\nVia: SIP/2.0/UDP 5060;branch=z9hG4bK-524287-1---d0be5d0eb41a1b32;rport^M\nVia: SIP/2.0/UDP 96.118.191.49:5060;branch=z9hG4bK-524287-1---d0be5d0eb41a1b32;rport^M\nMax-Forwards: 70^M\nContact: <sip:2002005498@96.118.191.49:5060>^M\n",
  "ServerName" => "basatlxs01",
"@version" => "1",
    "host" => "prod-platform",
  "Sip_Method" => "INVITE^M",
 "Via_IP1" => " 96.118.000.49"

```

Could you help me in understating and debugging on this grokparsefailure ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 8, 2017, 6:38am UTC](https://discuss.elastic.co/t/grok-failure-even-after-the-fields-were-filtered-out-successfully/110688/2 "2017-12-08T06:38:03Z")

</div>

I suspect you have more than one grok filter in your configuration. Perhaps an extra file in /etc/logstash/conf.d that you've forgotten about?

---

<div class="post-metadata">

**Author:** ![George\_Cherian](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/george_cherian/32/25879_2.png) [@George\_Cherian](https://discuss.elastic.co/u/George_Cherian)\
**Post date:** [December 8, 2017, 10:33am UTC](https://discuss.elastic.co/t/grok-failure-even-after-the-fields-were-filtered-out-successfully/110688/3 "2017-12-08T10:33:05Z")

</div>

Hi Magnus ,

We are using multiple grok in the configuration to filter out the fields.

```
     grok{
         id => "grok5"
          match => {"via1" => "^(?:.*SIP/2.0/UDP)(?<Via_IP1>[\s]\d+.\d+.\d+.\d+)?(?:.*)?$" }
         }
          grok{
                id => "grok6"
          match => {"via2" => "^(?:.*SIP/2.0/UDP)(?<Via_IP2>[\s]\d+.\d+.\d+.\d+)?(?:.*)?$" }
         }

                   grok {
                id => "grok7"
       match => { "cid" => "(?<correlationid:>callhalf-\d+:\d{1})?$" }
       }
                   grok{
                id => "grok8"
       match => { "path" => "(?:[\w\W]*\/)(?<ServerName>\w+)(?:\/[\w\W]*)" }
       }

```

is that a problem ?

when we commented out the grok specified above(grok5 and grok6) grokfailure doesn't occur.

We are using command line to run the logstash filter and explicitly specifying the conf path like

`sudo bin/ -f /home/conf_file/logstash_xslog_updated_test.conf ...`

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 8, 2017, 10:52am UTC](https://discuss.elastic.co/t/grok-failure-even-after-the-fields-were-filtered-out-successfully/110688/4 "2017-12-08T10:52:02Z")

</div>

> is that a problem ?

No.

> when we commented out the grok specified above(grok5 and grok6) grokfailure doesn't occur.

Well, that's a pretty good clue. If we look at the grok6 filter it expects the field to contain "SIP/2.0/UDP" but the `via2` field doesn't contain that string.

---

<div class="post-metadata">

**Author:** ![George\_Cherian](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/george_cherian/32/25879_2.png) [@George\_Cherian](https://discuss.elastic.co/u/George_Cherian)\
**Post date:** [December 11, 2017, 6:10am UTC](https://discuss.elastic.co/t/grok-failure-even-after-the-fields-were-filtered-out-successfully/110688/5 "2017-12-11T06:10:34Z")

</div>

Thanks Magnus:grinning:  
We could solve the issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 8, 2018, 6:10am UTC](https://discuss.elastic.co/t/grok-failure-even-after-the-fields-were-filtered-out-successfully/110688/6 "2018-01-08T06:10:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
