# Grok parse error in Kibana

**URL:** <https://discuss.elastic.co/t/grok-parse-error-in-kibana/222391>\
**Category:** Logstash\
**Created:** [March 6, 2020, 1:31am UTC](https://discuss.elastic.co/t/grok-parse-error-in-kibana/222391 "2020-03-06T01:31:43Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![kaj](https://avatars.discourse-cdn.com/v4/letter/k/85e7bf/32.png) [@kaj](https://discuss.elastic.co/u/kaj)\
**Post date:** [March 6, 2020, 1:31am UTC](https://discuss.elastic.co/t/grok-parse-error-in-kibana/222391/1 "2020-03-06T01:31:43Z")

</div>

I've been constructing a grok filter for a log that has lines like the one below:

`2018-09-19 03:48:46.900-05:00 [HOST:hostname.domain.com][SERVER:VariableString][PID:35570][THR:3726157568][Kernel XML API][Trace] XML Command: <st><sst><st><cmd><get_svrdef_settings/></cmd></st></sst></st>`

I've got the following grok that finally stopped erroring out in the logstash logs, but now does not actually parse correctly:

```
grok {
    match => { "message" => "%{DATA:logdate}\[HOST:%{DATA:host}\]\[SERVER:%{DATA:server}\]\[PID:%{BASE10NUM}:pid}\]\[THR:%{BASE10NUM}:thread\]\[Kernel XML API\]\[Trace\]\s*%{GREEDYDATA:xml_stuff}"}
        }

```

I've gone through a couple revisions including changing the first DATA to %{TIMESTAMP\_ISO8601} but that had the same result.

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [March 6, 2020, 7:40am UTC](https://discuss.elastic.co/t/grok-parse-error-in-kibana/222391/2 "2020-03-06T07:40:46Z")

</div>

Hi,

Try this:

> %{DATA:logdate}[HOST:%{DATA:host}][SERVER:%{DATA:server}][PID:%{BASE10NUM:pid}][THR:%{BASE10NUM:thread}][Kernel XML API][Trace] XML Command:\s\*%{GREEDYDATA:xml\_stuff}

You had an error in the PID and Thread grok. I also removed the text prefix from the XML part.

I simply used trhe grok debugger in Kibana: [Debug grok expressions | Kibana Guide [8.11] | Elastic](https://www.elastic.co/guide/en/kibana/current/xpack-grokdebugger.html)

Just copy your log entry and grok pattern into it and remove parts of the pattern until you find the error cause.

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 3, 2020, 7:40am UTC](https://discuss.elastic.co/t/grok-parse-error-in-kibana/222391/3 "2020-04-03T07:40:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
