# Grok parse exception

**URL:** <https://discuss.elastic.co/t/grok-parse-exception/51039>\
**Category:** Logstash\
**Created:** [May 26, 2016, 9:31am UTC](https://discuss.elastic.co/t/grok-parse-exception/51039 "2016-05-26T09:31:50Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sandhya\_Rathinapandi](https://avatars.discourse-cdn.com/v4/letter/s/6bbea6/32.png) [@Sandhya\_Rathinapandi](https://discuss.elastic.co/u/Sandhya_Rathinapandi)\
**Post date:** [May 26, 2016, 9:31am UTC](https://discuss.elastic.co/t/grok-parse-exception/51039/1 "2016-05-26T09:31:50Z")

</div>

Hi

I am trying to convert the response time in seconds using the below ruby code in the filter segment.

```
         code => "event['responsetime'] = (event['responsetime'].to_f / 1000000)

```

This was throwing grok parse exception when the response time is 0.

Tried changing the code as below but still showing the same error.

```
                    code => "if event['responsetime'] !=0
                            event['responsetime'] = (event['responsetime'].to_f / 1000000)
                            else event['responsetime'] = 0.0
                    end

```

Kindly help to resolve this.

Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 26, 2016, 10:44am UTC](https://discuss.elastic.co/t/grok-parse-exception/51039/2 "2016-05-26T10:44:03Z")

</div>

I don't see why the change you made would make any difference. 0 / 1000000 is still 0. What does the grok filter look like?

---

<div class="post-metadata">

**Author:** ![Sandhya\_Rathinapandi](https://avatars.discourse-cdn.com/v4/letter/s/6bbea6/32.png) [@Sandhya\_Rathinapandi](https://discuss.elastic.co/u/Sandhya_Rathinapandi)\
**Post date:** [May 26, 2016, 10:59am UTC](https://discuss.elastic.co/t/grok-parse-exception/51039/3 "2016-05-26T10:59:21Z")

</div>

any idea on why it is throwing grokparse.

Also I am using the below pattern for it. will this be a problem.

match =\> { "message" =\> "%{COMBINEDAPACHELOG} %{POSINT:responsetime}" }

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 26, 2016, 1:28pm UTC](https://discuss.elastic.co/t/grok-parse-exception/51039/4 "2016-05-26T13:28:36Z")

</div>

And what does a line of input look like, i.e. what kind of string are you trying to parse with that grok filter?

---

<div class="post-metadata">

**Author:** ![Sandhya\_Rathinapandi](https://avatars.discourse-cdn.com/v4/letter/s/6bbea6/32.png) [@Sandhya\_Rathinapandi](https://discuss.elastic.co/u/Sandhya_Rathinapandi)\
**Post date:** [May 27, 2016, 6:11am UTC](https://discuss.elastic.co/t/grok-parse-exception/51039/5 "2016-05-27T06:11:01Z")

</div>

The String that I am trying to parse is apache logs something like below.

10.12.123.123 - - [04/Apr/2016:19:27:26 +0000] "GET /path/abc.mp4?a=true HTTP/1.1" 200 1545 "-" "-" 0 "-"

and it is of the format

%{COMBINEDAPACHELOG} %{POSINT:responsetime}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 27, 2016, 11:19am UTC](https://discuss.elastic.co/t/grok-parse-exception/51039/6 "2016-05-27T11:19:58Z")

</div>

Your grok expression ends with POSINT but your example log line doesn't end with a positive integer.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:55am UTC](https://discuss.elastic.co/t/grok-parse-exception/51039/8 "2017-07-06T04:55:54Z")

</div>


