# Grok parse failure despite pattern working in debugger

**URL:** <https://discuss.elastic.co/t/grok-parse-failure-despite-pattern-working-in-debugger/206665>\
**Category:** Logstash\
**Created:** [November 5, 2019, 6:59pm UTC](https://discuss.elastic.co/t/grok-parse-failure-despite-pattern-working-in-debugger/206665 "2019-11-05T18:59:44Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mfisher](https://avatars.discourse-cdn.com/v4/letter/m/ed655f/32.png) [@mfisher](https://discuss.elastic.co/u/mfisher)\
**Post date:** [November 5, 2019, 6:59pm UTC](https://discuss.elastic.co/t/grok-parse-failure-despite-pattern-working-in-debugger/206665/1 "2019-11-05T18:59:44Z")

</div>

I've been getting grok parse failures for these messages.  
`"message": "<164>Nov 05 2019 12:46:04 NGFW1-IPICHIC : %ASA-4-434003: SFR requested to reset TCP connection from outside:13.249.87.36/443 to inside:38.142.127.155/60366\n"`

They parse correctly on the different grok debuggers online however these same patterns result in grok parse failures in logstash.

my pattern is this  
`SFR_ACTION requested to drop|requested to reset|requested ASA to bypass further packet redirection and process`

`CISCOFW434003 %{WORD:module} %{SFR_ACTION:sfr_action} %{WORD:protocol} connection from %{WORD:ingress_interface}(:)?%{IPV4:src_ip}(/)?%{INT:src_port} to %{WORD:egress_interface}(:)?%{IP:dst_ip}(/)?%{INT:dst_port}`

my logstash.conf  
input {

#### Receive Cisco ASA logs on the standard syslog UDP port 514

udp {  
port =\> "8514"  
type =\> "cisco-asa"  
}  
}

filter {  
if [type] == "cisco-asa" {  
# Split the syslog part and Cisco tag out of the message  
grok {  
patterns\_dir =\> ["/etc/logstash/conf.d/patterns/asa/patterns-asa"]  
match =\> ["message", "%{CISCO\_TAGGED\_SYSLOG} %{GREEDYDATA:cisco\_message}"]  
}

```
# Parse the syslog severity and facility
syslog_pri { }

# Parse the date from the "timestamp" field to the "@timestamp" field
date {
  match => ["timestamp",
    "MMM dd HH:mm:ss",
    "MMM d HH:mm:ss",
    "MMM dd yyyy HH:mm:ss",
    "MMM d yyyy HH:mm:ss"
  ]
  timezone => "America/Chicago"
}

# Clean up redundant fields if parsing was successful
if "_grokparsefailure" not in [tags] {
  mutate {
    rename => ["cisco_message", "message"]
    remove_field => ["timestamp"]
  }
}

# Extract fields from the each of the detailed message types
# The patterns provided below are included in Logstash since 1.2.0
grok {
  patterns_dir => ["/etc/logstash/conf.d/patterns/asa/patterns-asa"]
  match => [
    "message", "%{CISCOFW106001}",
    "message", "%{CISCOFW106006_106007_106010}",
    "message", "%{CISCOFW106014}",
    "message", "%{CISCOFW106015}",
    "message", "%{CISCOFW106021}",
    "message", "%{CISCOFW106023}",
    "message", "%{CISCOFW106100}",
    "message", "%{CISCOFW110002}",
    "message", "%{CISCOFW111001_111007}",
    "message", "%{CISCOFW111008}",
    "message", "%{CISCOFW111010}",
    "message", "%{CISCOFW113019}",
    "message", "%{CISCOFW209005}",
    "message", "%{CISCOFW302010}",
    "message", "%{CISCOFW302013_302014_302015_302016}",
    "message", "%{CISCOFW302020_302021}",
    "message", "%{CISCOFW305011}",
    "message", "%{CISCOFW313001_313004_313008}",
    "message", "%{CISCOFW313005}",
    "message", "%{CISCOFW402117}",
    "message", "%{CISCOFW402119}",
    "message", "%{CISCOFW419001}",
    "message", "%{CISCOFW419002}",
    "message", "%{CISCOFW434002}",
    "message", "%{CISCOFW434003}",
    "message", "%{CISCOFW434004}",
    "message", "%{CISCOFW500004}",
    "message", "%{CISCOFW602303_602304}",
    "message", "%{CISCOFW710001_710002_710003_710005_710006}",
    "message", "%{CISCOFW713172}",
    "message", "%{CISCOFW722033}",
    "message", "%{CISCOFW733100}",
    "message", "%{CISCOFW737034}",
    "message", "%{CISCOFW725001_725002_725007}",
    "message", "%{CISCOFW305006}",
    "message", "%{CISCOFW321006}",
    "message", "%{CISCOFW604103}",
    "message", "%{CISCOFW771002}",
    "message", "%{CISCOFW607001}",
    "message", "%{CISCOFW305013}",
    "message", "%{CISCOFW711004}"
 ]
}

geoip {
  source => "src_ip"
  target => "geoip"
}

if "_grokparsefailure" not in [tags] {
  mutate {
    remove_field => ["message"]
  }
}

```

}  
}

output {

elasticsearch {  
hosts =\> ["[https://localhost:9200](https://localhost:9200)"]  
manage\_template =\> true  
ilm\_enabled =\> "auto"  
ilm\_rollover\_alias =\> "cisco-asa"  
ilm\_pattern =\> "000001"  
ilm\_policy =\> "cisco\_asa\_rollover\_policy"  
index =\> "logstash-asa"  
#document\_type =\> "%{type}"  
#document\_id =\> "%{fingerprint}"  
}

}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 3, 2019, 6:59pm UTC](https://discuss.elastic.co/t/grok-parse-failure-despite-pattern-working-in-debugger/206665/2 "2019-12-03T18:59:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
