# Grok parse error

**URL:** <https://discuss.elastic.co/t/grok-parse-error/33909>\
**Category:** Logstash\
**Created:** [November 5, 2015, 7:18pm UTC](https://discuss.elastic.co/t/grok-parse-error/33909 "2015-11-05T19:18:04Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Don\_Pich](https://avatars.discourse-cdn.com/v4/letter/d/b487fb/32.png) [@Don\_Pich](https://discuss.elastic.co/u/Don_Pich)\
**Post date:** [November 5, 2015, 7:18pm UTC](https://discuss.elastic.co/t/grok-parse-error/33909/1 "2015-11-05T19:18:04Z")

</div>

So I'm getting a parse error on my grok filter.

I have gone to the following url to debug it: [http://grokdebug.herokuapp.com/](http://grokdebug.herokuapp.com/)

My input is this:

```
66.249.69.48|-|2015-11-05T10:57:51-06:00|/northwest-a-tacs-camo-seat-covers/?utm_campaign=product_ads&utm_source=google&utm_medium=cpc&utm_content=854976&productid=854976&cparam=2346273|499|0|http://www.realtruck.com/northwest-a-tacs-camo-seat-covers/?utm_campaign=product_ads&utm_source=google&utm_medium=cpc&utm_content=854976&productid=854976&cparam=2346273|Mozilla/5.0 (iPhone; CPU iPhone OS 8_3 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12F70 Safari/600.1.4 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)|0.237|-|.

```

My grok filter is this:

```
%{IP:visitor_ip}\|[^|]+\|%{TIMESTAMP_ISO8601:entryDateTime}\|%{URIPATH:url}%{URIPARAM:query_string}?\|%{INT:http_response}\|%{INT:response_length}\|(?<http_referrer>[^|]+)\|(?<user_agent>[^|]+)\|%{BASE16FLOAT:request_time}\|%{BASE16FLOAT:upstream_response_time}

```

I am expecting a time stamp to come out of this, but it is getting a "No Matches" and causing logstash grok parse errors.

I am at a loss as it works part of the time. Anyone have a quick second to look at this?

This is a snapshot of the error in Kibana:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/1/1b7177ea62c183bb3e78dfa318e52a746de4169a.PNG)

This is a snapshot of one that works:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/2/27c1c3e37a3b075155fcc436a914677faada4b04.png)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 5, 2015, 8:30pm UTC](https://discuss.elastic.co/t/grok-parse-error/33909/2 "2015-11-05T20:30:51Z")

</div>

The final `%{BASE16FLOAT:upstream_response_time}` doesn't match the hyphen that it's getting. Replace with `(%{BASE16FLOAT:upstream_response_time}|-)`.

---

<div class="post-metadata">

**Author:** ![Jackal9301](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jackal9301/32/5748_2.png) [@Jackal9301](https://discuss.elastic.co/u/Jackal9301)\
**Post date:** [November 5, 2015, 8:44pm UTC](https://discuss.elastic.co/t/grok-parse-error/33909/3 "2015-11-05T20:44:37Z")

</div>

Magnus beat me to it. However to add the reason it works sometimes and not others means somtimes you are getting a value back for the upstream response time. Otherwise you would just get a null for that value.

---

<div class="post-metadata">

**Author:** ![Don\_Pich](https://avatars.discourse-cdn.com/v4/letter/d/b487fb/32.png) [@Don\_Pich](https://discuss.elastic.co/u/Don_Pich)\
**Post date:** [November 5, 2015, 9:05pm UTC](https://discuss.elastic.co/t/grok-parse-error/33909/4 "2015-11-05T21:05:46Z")

</div>

Hey Guys,

@Magnus, thanks for that input!!

When looking through nginx HTTP codes, 499 is saying that google closed the connection before we could get it all setup. So I think a null value or 'zero' would be just fine because we wouldn't get any statistics on it anyway.

Would it be smarter to put a regex test in there to say if the value that is returned is "-", input 0, and then if it isn't put in the value?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:23am UTC](https://discuss.elastic.co/t/grok-parse-error/33909/5 "2017-07-06T05:23:44Z")

</div>


