# Grok Parse Failure - CSV input via Filebeat

**URL:** <https://discuss.elastic.co/t/grok-parse-failure-csv-input-via-filebeat/153662>\
**Category:** Logstash\
**Created:** [October 23, 2018, 5:43pm UTC](https://discuss.elastic.co/t/grok-parse-failure-csv-input-via-filebeat/153662 "2018-10-23T17:43:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![phoenix66](https://avatars.discourse-cdn.com/v4/letter/p/4af34b/32.png) [@phoenix66](https://discuss.elastic.co/u/phoenix66)\
**Post date:** [October 23, 2018, 5:43pm UTC](https://discuss.elastic.co/t/grok-parse-failure-csv-input-via-filebeat/153662/1 "2018-10-23T17:43:20Z")

</div>

Hi all,

I am having a problem with a Grok filter failing to parse, despite it working fine in the Kibana Grok debugger.

Here is an example message (CSV into Filebeat to Logstash)

```
{
       "message" => "\"46642378\",\"Information\",\"2017-09- 15\",\"10:37:52\",\"RVP\\administrator\",\"192.168.0.43\",\"rvpl- 43\",\"RVPL-02- Backups/BFWTestFileRights.tmp\",\"SAMBA\",\"Delete\"",
        "offset" => 434039,
    "prospector" => {
        "type" => "log"
    },
        "source" => "/mnt/nfs/accesslogs/20170915-3.csv",
    "@timestamp" => 2018-10-23T16:58:25.946Z,
          "host" => {
        "name" => "elk01.rvp.local"
    },
         "input" => {
        "type" => "log"
    },
      "@version" => "1",
          "beat" => {
         "version" => "6.4.2",
        "hostname" => "elk01.rvp.local",
            "name" => "elk01.rvp.local"
    },
          "tags" => [
        [0] "beats_input_codec_plain_applied",
        [1] "_grokparsefailure"
    ]
}

```

And here is the filter I am applying:

```
filter {
    grok {
            match => { "message" => "\\"%{INT:Message_ID}\\",\\"%{WORD:Severity}\\",\\"%{YEAR:Year}-%{MONTHNUM:Month}-%{MONTHDAY:Day}\\",\\"%{TIME:Time}\\",\\"%{WORD:Domain}\\\\%{WORD:User}\\",\\"%{IPV4:Client_IP}\\",\\"%{HOSTNAME:Hostname}\\",\\"%{GREEDYDATA:File}\\",\\"%{WORD:Protocol}\\",\\"%{WORD:Action}\\""
                            }
        }
}

```

Does anyone have any tips on how to debug this sort of thing?

Thanks

---

<div class="post-metadata">

**Author:** ![phoenix66](https://avatars.discourse-cdn.com/v4/letter/p/4af34b/32.png) [@phoenix66](https://discuss.elastic.co/u/phoenix66)\
**Post date:** [October 23, 2018, 11:20pm UTC](https://discuss.elastic.co/t/grok-parse-failure-csv-input-via-filebeat/153662/2 "2018-10-23T23:20:15Z")

</div>

I figured it out. It seems that slashes "\" are handled differently in logstash to in the kibana debugger.

Thanks,

---

<div class="post-metadata">

**Author:** ![balumurari1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/balumurari1/32/39203_2.png) [@balumurari1](https://discuss.elastic.co/u/balumurari1)\
**Post date:** [October 25, 2018, 7:24am UTC](https://discuss.elastic.co/t/grok-parse-failure-csv-input-via-filebeat/153662/3 "2018-10-25T07:24:53Z")

</div>

to load csv from logstash,

> [@Load csv file in logstash](https://discuss.elastic.co/t/load-csv-file-in-logstash/151319/3):
>
> Thanks for reply,hope this works fine, input { file { path =\> "D:/Balu/ELK-stack/csvfile.csv" start\_position =\> "beginning" sincedb\_path =\> "NUL" } } filter { csv { separator =\> "," columns =\> ["open","high","low","close","volume"] } } output { elasticsearch { hosts =\> "[http://localhost:9200](http://localhost:9200)" index =\> "wallet-address-index" } stdout { codec =\> rubydebug } }

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 22, 2018, 7:24am UTC](https://discuss.elastic.co/t/grok-parse-failure-csv-input-via-filebeat/153662/4 "2018-11-22T07:24:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
