# Grok parse failures

**URL:** <https://discuss.elastic.co/t/grok-parse-failures/257230>\
**Category:** Logstash\
**Created:** [December 1, 2020, 3:34pm UTC](https://discuss.elastic.co/t/grok-parse-failures/257230 "2020-12-01T15:34:24Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![naveenrt23](https://avatars.discourse-cdn.com/v4/letter/n/47e85d/32.png) [@naveenrt23](https://discuss.elastic.co/u/naveenrt23)\
**Post date:** [December 1, 2020, 3:34pm UTC](https://discuss.elastic.co/t/grok-parse-failures/257230/1 "2020-12-01T15:34:24Z")

</div>

Hello I'm playing around with grok filters and i'm running into parse failures..Any idea whats wrong ?

Filters:

```
filter {
  if [type] == "app-data" {
    mutate {
      rename => ["env", "environment"]
    }
    grok {
      break_on_match => false
      match => {
      "message" => "^%{DATA:timestamp_local}\|%{DATA:log_level}\|%{DATA:ID}\|%{WORD:Type}\|%{WORD:stage}\|%{NUMBER:accountNumber}\|%{WORD:region}"
      }
    }
  }
}

```

Here's the input being provided:

`2020-12-01T10:28:51.603Z|INFO|AP92|com.test.resource.6|preview-5|9244208|US-EAST-9`

Here's the error i see:

```
{
           "tags" => [
        [0] "_grokparsefailure"
    ],
           "type" => "app-data",
       "hostName" => "ELB-1",
       "@version" => "1",
           "path" => "/Users/metrics-poc/filebeat-output.log",
           "host" => "MA81",
     "@timestamp" => 2020-12-01T15:28:52.967Z,
        "message" => "2020-12-01T10:28:51.603Z|INFO|AP92|com.test.resource.6|preview-5|9244208|US-EAST-9",
    "environment" => "prod"
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 1, 2020, 3:41pm UTC](https://discuss.elastic.co/t/grok-parse-failures/257230/2 "2020-12-01T15:41:47Z")

</div>

> [@naveenrt23](#):
>
> com.test.resource.6|preview-5

WORD will not match either of those fields. WORD match word characters, which are `[a-zA-Z0-9_]`.

---

<div class="post-metadata">

**Author:** ![naveenrt23](https://avatars.discourse-cdn.com/v4/letter/n/47e85d/32.png) [@naveenrt23](https://discuss.elastic.co/u/naveenrt23)\
**Post date:** [December 1, 2020, 3:46pm UTC](https://discuss.elastic.co/t/grok-parse-failures/257230/3 "2020-12-01T15:46:44Z")

</div>

Gotcha..What difference does it makes if we generalize the type to DATA which seems like applicable to almost everything?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 1, 2020, 4:12pm UTC](https://discuss.elastic.co/t/grok-parse-failures/257230/4 "2020-12-01T16:12:21Z")

</div>

Sometimes DATA will [not do](https://discuss.elastic.co/t/doubts-about-grok/257129/2) what you expect. You might be better off with a custom pattern

```
<?(Type)[^|]*>

```

will match anything that is not a pipe character.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 29, 2020, 4:12pm UTC](https://discuss.elastic.co/t/grok-parse-failures/257230/5 "2020-12-29T16:12:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
