# Grok parse faliure filebeat 6.0

**URL:** https://discuss.elastic.co/t/grok-parse-faliure-filebeat-6-0/110243
**Category:** Logstash
**Created:** [December 5, 2017, 3:17am UTC](https://discuss.elastic.co/t/grok-parse-faliure-filebeat-6-0/110243 "2017-12-05T03:17:06Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![ramzey1981](https://avatars.discourse-cdn.com/v4/letter/r/d26b3c/32.png) [@ramzey1981](https://discuss.elastic.co/u/ramzey1981)
#### Post date: [December 5, 2017, 3:17am UTC](https://discuss.elastic.co/t/grok-parse-faliure-filebeat-6-0/110243/1 "2017-12-05T03:17:07Z")

</div>

hello folks

i have the following filebeat log going to logstash

[https://pastebin.com/raw/hAGrDNLc](https://pastebin.com/raw/hAGrDNLc)

and the following logstash filter but the filter is throwing a grok parse failure. I am not certain why the if condition is not matching can you please advise. From the pastebin you can see that those fields are getting passed

input {  
redis {  
host =\> "localhost"  
data\_type =\> "list"  
key =\> "filebeat"  
}  
}

filter {

if [fileset][module] == "nginx" {  
grok {  
add\_tag =\> ["foundit"]  
}  
}  
}

output {  
#my output section here

}

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [December 5, 2017, 6:28am UTC](https://discuss.elastic.co/t/grok-parse-faliure-filebeat-6-0/110243/2 "2017-12-05T06:28:42Z")

</div>

If you unconditionally want to add a tag use a mutate filter and not a grok filter.

---

<div class="post-metadata">

### Author: ![ramzey1981](https://avatars.discourse-cdn.com/v4/letter/r/d26b3c/32.png) [@ramzey1981](https://discuss.elastic.co/u/ramzey1981)
#### Post date: [December 5, 2017, 3:56pm UTC](https://discuss.elastic.co/t/grok-parse-faliure-filebeat-6-0/110243/3 "2017-12-05T15:56:16Z")

</div>

Thanks Magnus for the prompt reply, I have actually added random tags within my logstash.conf file in other places to make sure the logs are hitting the correct if statements when the logstash process is filtering them. so I am a bit confused as why its working in other places but I will try your suggestion.

thanks

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [December 5, 2017, 7:55pm UTC](https://discuss.elastic.co/t/grok-parse-faliure-filebeat-6-0/110243/4 "2017-12-05T19:55:23Z")

</div>

`add_tag` and `add_field` work within any filter, but only when the filter considers the processing of the event successful. In the grok case those two options will only be processed if one of the grok expressions match. In your case you're not specifying any grok expression at all and hence the filter won't be successful and your `add_tag` will be ignored.

---

<div class="post-metadata">

### Author: ![ramzey1981](https://avatars.discourse-cdn.com/v4/letter/r/d26b3c/32.png) [@ramzey1981](https://discuss.elastic.co/u/ramzey1981)
#### Post date: [December 5, 2017, 8:15pm UTC](https://discuss.elastic.co/t/grok-parse-faliure-filebeat-6-0/110243/5 "2017-12-05T20:15:50Z")

</div>

thank you magnus for the explanation now i understand why my other filter grok add\_tag attribute is working and i also got this one working as well.

cheers

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 2, 2018, 8:15pm UTC](https://discuss.elastic.co/t/grok-parse-faliure-filebeat-6-0/110243/6 "2018-01-02T20:15:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
