# Grok fields are not visible in kibana

**URL:** <https://discuss.elastic.co/t/grok-fields-are-not-visible-in-kibana/64808>\
**Category:** Logstash\
**Created:** [November 3, 2016, 7:26am UTC](https://discuss.elastic.co/t/grok-fields-are-not-visible-in-kibana/64808 "2016-11-03T07:26:19Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![bopa](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@bopa](https://discuss.elastic.co/u/bopa)\
**Post date:** [November 3, 2016, 7:26am UTC](https://discuss.elastic.co/t/grok-fields-are-not-visible-in-kibana/64808/1 "2016-11-03T07:26:19Z")

</div>

I have used filebeat to capture IIS logs. and I have used following grok to filter IIS logs.

**match =\> ["message", "%{TIMESTAMP\_ISO8601:timestamp} %{IPORHOST:serverip} %{WORD:verb} %{NOTSPACE:request} %{NOTSPACE:querystring} %{NUMBER:port} %{NOTSPACE:auth} %{IPORHOST:clientip} %{NOTSPACE:browser}/%{NOTSPACE:agent} %{NOTSPACE:referrer} %{NUMBER:response} %{NUMBER:sub\_response} %{NUMBER:sc\_status} %{NUMBER:responsetime}"]**

but in kibana I couldn't received the filtered data according to the grok filter.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/e/e4b878ddceca85811fb5a56239a19f37f3e54641.jpg)

I tried refresh the index

remove and add the index again but no luck 😕

please help

my logstash.conf is as follows

input {  
beats {  
port =\> 5000  
}  
}

# First filter

filter {  
#ignore log comments  
if [message] =~ "^#" {  
drop {}  
}

grok {  
#patterns\_dir =\> "./patterns"

match =\> ["message", "%{TIMESTAMP\_ISO8601:timestamp} %{IPORHOST:serverip} %{WORD:verb} %{NOTSPACE:request} %{NOTSPACE:querystring} %{NUMBER:port} %{NOTSPACE:auth} %{IPORHOST:clientip} %{NOTSPACE:browser}/%{NOTSPACE:agent} %{NOTSPACE:referrer} %{NUMBER:response} %{NUMBER:sub\_response} %{NUMBER:sc\_status} %{NUMBER:responsetime}"]  
}

date {  
match =\> ["timestamp", "yyyy-MM-dd HH:mm:ss"]  
locale =\> "en"  
}  
}

# Second filter

filter {  
if "\_grokparsefailure" in [tags] {

```
} else {
# on success remove the message field to save space
mutate {
 remove_field => ["message", "timestamp"]
}

```

}  
}

output {  
elasticsearch {  
hosts =\> ["172.24.80.86:9200"]  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 3, 2016, 8:14am UTC](https://discuss.elastic.co/t/grok-fields-are-not-visible-in-kibana/64808/2 "2016-11-03T08:14:18Z")

</div>

Please show what an example event looks like. Please don't use screenshots. Either copy/paste from the JSON tab in Kibana or use a `stdout { codec => rubydebug }` output that you copy/paste from.

---

<div class="post-metadata">

**Author:** ![bopa](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@bopa](https://discuss.elastic.co/u/bopa)\
**Post date:** [November 3, 2016, 8:33am UTC](https://discuss.elastic.co/t/grok-fields-are-not-visible-in-kibana/64808/3 "2016-11-03T08:33:32Z")

</div>

Following is the event generated in kibana at the moment.

@timestamp:November 3rd 2016, 13:58:58.473offset:307,298@version:1input\_type:logbeat.hostname:BLIFE-TESTbeat.name:BLIFE-TESTbeat.version:5.0.0host:BLIFE-TESTsource:C:\inetpub\logs\LogFiles\W3SVC2\u\_ex161103.logmessage:2016-11-03 08:28:04 BLIFE-TEST 172......... POST /Medical\_Payment/MedicalUI/LabTestPaymentUI.aspx - 80 172......... HTTP/1.1 [http://blife-test/Medical\_Payment/MedicalUI/LabTestPaymentUI.aspx](http://blife-test/Medical_Payment/MedicalUI/LabTestPaymentUI.aspx) blife-test 200 0 0 31186 24882 50type:logtags:beats\_input\_codec\_plain\_applied, \_grokparsefailure\_id:AVgpVqlj6ezIdl4F1huS\_type:log\_index:filebeat-2016.11.03\_score: -

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 3, 2016, 9:56am UTC](https://discuss.elastic.co/t/grok-fields-are-not-visible-in-kibana/64808/4 "2016-11-03T09:56:00Z")

</div>

No fields are created because your grok expression doesn't match your input logs.

You did not copy/paste from the JSON tab in Kibana like I asked you to do. In this particular case it didn't matter but another time it might.

---

<div class="post-metadata">

**Author:** ![bopa](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@bopa](https://discuss.elastic.co/u/bopa)\
**Post date:** [November 3, 2016, 10:03am UTC](https://discuss.elastic.co/t/grok-fields-are-not-visible-in-kibana/64808/5 "2016-11-03T10:03:58Z")

</div>

Sorry I couldn't find JASON tab in Kibana 5.0 Please help

Following is my raw log from IIS

> 2016-11-02 02:29:47 172....... GET /Secworks/Signin.asp - 80 - 172.......... Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+NT+5.1;+SV1;+.NET+CLR+2.0.50727;+.NET4.0C) - 200 0 0 286  
> 2016-11-02 02:29:55 172.......... POST /Secworks/Signin\_handler.asp - 80 - 172.24.102.88 Mozilla/4.0+(compatible;+MSIE+6.0;+Windows+NT+5.1;+SV1;+.NET+CLR+2.0.50727;+.NET4.0C) [http://blife-test/Secworks/Signin.asp](http://blife-test/Secworks/Signin.asp) 200 0 0 448

I tested my grok filter in [http://grokconstructor.appspot.com](http://grokconstructor.appspot.com) . in their it worked. It matches the log in the way I needed. but when the same grok filter applies to logstash.conf it wasn't working.

Please help

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 3, 2016, 11:34am UTC](https://discuss.elastic.co/t/grok-fields-are-not-visible-in-kibana/64808/6 "2016-11-03T11:34:14Z")

</div>

> Sorry I couldn't find JASON tab in Kibana 5.0 Please help

Maybe it has disappeared or is called something else in Kibana 5. I don't know.

> Following is my raw log from IIS

I can't spot any obvious errors with your grok expression. I suggest you start with the simplest possible one, `%{TIMESTAMP_ISO8601:timestamp}`, and verify that it works. Then build the expression from there. At some point it's going to start failing again and then you know what part didn't work. I strongly suggest you to use a `stdout { codec => rubydebug }` output while testing this.

---

<div class="post-metadata">

**Author:** ![bopa](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@bopa](https://discuss.elastic.co/u/bopa)\
**Post date:** [November 3, 2016, 11:36am UTC](https://discuss.elastic.co/t/grok-fields-are-not-visible-in-kibana/64808/7 "2016-11-03T11:36:31Z")

</div>

I'm bit new to grok and ELK

Could you please explain me how to use \> stdout { codec =\> rubydebug }

should it be in the logstash.conf file or any where else. Please help

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 3, 2016, 11:40am UTC](https://discuss.elastic.co/t/grok-fields-are-not-visible-in-kibana/64808/8 "2016-11-03T11:40:00Z")

</div>

Yes, it's a Logstash output that goes in your Logstash configuration.

---

<div class="post-metadata">

**Author:** ![bopa](https://avatars.discourse-cdn.com/v4/letter/b/a6a055/32.png) [@bopa](https://discuss.elastic.co/u/bopa)\
**Post date:** [November 3, 2016, 11:40am UTC](https://discuss.elastic.co/t/grok-fields-are-not-visible-in-kibana/64808/9 "2016-11-03T11:40:35Z")

</div>

ok thank you magnus

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:31am UTC](https://discuss.elastic.co/t/grok-fields-are-not-visible-in-kibana/64808/10 "2017-07-06T04:31:19Z")

</div>


