# Grok parse failure in Logstash

**URL:** <https://discuss.elastic.co/t/grok-parse-failure-in-logstash/74601>\
**Category:** Logstash\
**Created:** [February 10, 2017, 5:34am UTC](https://discuss.elastic.co/t/grok-parse-failure-in-logstash/74601 "2017-02-10T05:34:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticheart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elasticheart/32/65189_2.png) [@elasticheart](https://discuss.elastic.co/u/elasticheart)\
**Post date:** [February 10, 2017, 5:34am UTC](https://discuss.elastic.co/t/grok-parse-failure-in-logstash/74601/1 "2017-02-10T05:34:29Z")

</div>

I am using filebeat to push files to kafka and then consume it using Logstash. Below is the filebeat output.

```
{
  "@timestamp": "2017-02-10T05:07:06.895Z",
  "beat": {
    "hostname": "mypc",
    "name": "mybeat",
    "version": "5.0.0"
  },
  "fields": {
    "logtype": "my_logfile"
  },
  "input_type": "log",
  "message": "192.168.24.208 [08/Feb/2017:07:10:57 +0000] \'http-www-8080-www-5\' 1841 677 241 42C8FGTR467FDSMKH7523DFV73B652C6F \'POST /module/submodule/action?trigger=e7s2\u0026locale=en_US\u0026llt=\u0026agentId=\u0026TKN_EXCHG=9190B0C7941A2784F4DE94F1572732EF HTTP/1.1\' \'gzip, deflate\' - gzip \'Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.99 Safari/537.36\'",
  "offset": 5685,
  "source": "/logfiles/mylog.2017-02-08.txt",
  "type": "logfile"
}

```

In Logstash, I am applying grok like;

```
grok{
	match => { "message" => "{GREEDYDATA:msg}" }	
}

```

But I am getting `"tags":["_grokparsefailure"]` in Logstash. Why is this happening and how can I fix this?

Thank you.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 10, 2017, 8:22am UTC](https://discuss.elastic.co/t/grok-parse-failure-in-logstash/74601/2 "2017-02-10T08:22:00Z")

</div>

`%{GREEDYDATA:msg}`, not `{GREEDYDATA:msg}`. That's of course a pretty useless grok filter, but maybe you're just playing around.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 10, 2017, 8:22am UTC](https://discuss.elastic.co/t/grok-parse-failure-in-logstash/74601/3 "2017-03-10T08:22:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
