# Grok parser question (Invalid json string)

**URL:** <https://discuss.elastic.co/t/grok-parser-question-invalid-json-string/344730>\
**Category:** Kibana\
**Created:** [October 10, 2023, 11:46am UTC](https://discuss.elastic.co/t/grok-parser-question-invalid-json-string/344730 "2023-10-10T11:46:21Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![superm0](https://avatars.discourse-cdn.com/v4/letter/s/e19b73/32.png) [@superm0](https://discuss.elastic.co/u/superm0)\
**Post date:** [October 10, 2023, 11:46am UTC](https://discuss.elastic.co/t/grok-parser-question-invalid-json-string/344730/1 "2023-10-10T11:46:22Z")

</div>

Hi,please assit me with creating custom grok pattern .

I've created custom pattern, it works perfectly in Grok Debugger.

But i cant add this expression for parsing data:

**Error: Invalid Json string.**

```auto
%{SYSLOGTIMESTAMP:syslog_timestamp} %{IPORHOST:syslog_server} %{SYSLOGPROG}: %{IP:client_ip}:%{INT:client_port} \[%{HAPROXYDATE:accept_date}\] %{NOTSPACE:frontend_name} %{NOTSPACE:backend_name}/%{NOTSPACE:server_name} %{INT:time_request}/%{INT:time_queue}/%{INT:time_backend_connect}/%{INT:time_backend_response}/%{NOTSPACE:time_duration} %{INT:http_status_code} %{NOTSPACE:bytes_read} %{DATA:captured_request_cookie} %{DATA:captured_response_cookie} %{NOTSPACE:termination_state} %{INT:actconn}/%{INT:feconn}/%{INT:beconn}/%{INT:srvconn}/%{NOTSPACE:retries} %{INT:srv_queue}/%{INT:backend_queue} {%{DATA:request_header_x_forwarded_for}\|%{DATA:request_header_user_agent}\|%{DATA:request_header_referer}} "%{WORD:http_verb} %{URIPATHPARAM:http_request}( HTTP/%{NUMBER:http_version}")?

```

ELK 7.12 / haproxy 1.8

Thanks for any help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 7, 2023, 11:46am UTC](https://discuss.elastic.co/t/grok-parser-question-invalid-json-string/344730/2 "2023-11-07T11:46:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
