# Grok seems not working anymore

**URL:** <https://discuss.elastic.co/t/grok-seems-not-working-anymore/42840>\
**Category:** Logstash\
**Created:** [February 26, 2016, 10:09am UTC](https://discuss.elastic.co/t/grok-seems-not-working-anymore/42840 "2016-02-26T10:09:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Weizhen\_Yan](https://avatars.discourse-cdn.com/v4/letter/w/9f8e36/32.png) [@Weizhen\_Yan](https://discuss.elastic.co/u/Weizhen_Yan)\
**Post date:** [February 26, 2016, 10:09am UTC](https://discuss.elastic.co/t/grok-seems-not-working-anymore/42840/1 "2016-02-26T10:09:56Z")

</div>

I'm trying to import nginx logs into ES, i'm using this patterns  
`NGUSERNAME [a-zA-Z\.\@\-\+_%]+ NGUSER %{NGUSERNAME} NGINXACCESS %{IPORHOST:clientip} - %{NOTSPACE:remote_user} \[%{HTTPDATE:timestamp}\] \"(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})\" %{NUMBER:response} (?:%{NUMBER:bytes}|-) %{QS:referrer} %{QS:agent} %{NOTSPACE:http_x_forwarded_for}`

all logs were successfully imported, here is a screenshot in kibana

 ![](https://us1.discourse-cdn.com/elastic/original/2X/a/a919bb961ccb3a372c902a790a177e6398957ad7.png)

but when I test my pattern , the result is

 ![](https://us1.discourse-cdn.com/elastic/original/2X/a/a6ef9fe12ed02f6a36f48124f9cef6010dcf1432.png)

why I did not get all the fields? like clientip, agent? in kibana there is a message field, without clientip field I can not analyze the ip count

here is the grok in logstash config file, :

```
filter {
if [type] == "nginx-access"{
grok {
    match => { "message" => "%{NGINXACCESS}" }
}
date {
    match => ["timestamp" , "dd/MMM/YYYY:HH:mm:ss Z"]
}
geoip {
    source => "clientip"
}
}
}

```

hope someone can help me look it to it Thank you

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 26, 2016, 2:37pm UTC](https://discuss.elastic.co/t/grok-seems-not-working-anymore/42840/2 "2016-02-26T14:37:01Z")

</div>

Your actual log entry ends with a user agent string but that's not what your grok pattern ends with. You won't get any fields unless you get a match. This is different from wherever you tested your pattern, where apparently all matched fields are shown even though the expression as a whole didn't match. That site also tells you "NOT MATCHED".

---

<div class="post-metadata">

**Author:** ![Weizhen\_Yan](https://avatars.discourse-cdn.com/v4/letter/w/9f8e36/32.png) [@Weizhen\_Yan](https://discuss.elastic.co/u/Weizhen_Yan)\
**Post date:** [March 1, 2016, 9:48am UTC](https://discuss.elastic.co/t/grok-seems-not-working-anymore/42840/3 "2016-03-01T09:48:36Z")

</div>

I see ! sorry for the late reply! thank you !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:09am UTC](https://discuss.elastic.co/t/grok-seems-not-working-anymore/42840/4 "2017-07-06T05:09:11Z")

</div>


