# Grok succeeds in debugger and through input{stdin. but with this config file I'm getting \_grokparsefailure

**URL:** <https://discuss.elastic.co/t/grok-succeeds-in-debugger-and-through-input-stdin-but-with-this-config-file-im-getting-grokparsefailure/253556>\
**Category:** Logstash\
**Created:** [October 28, 2020, 11:36am UTC](https://discuss.elastic.co/t/grok-succeeds-in-debugger-and-through-input-stdin-but-with-this-config-file-im-getting-grokparsefailure/253556 "2020-10-28T11:36:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vita\_Rosenberg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vita_rosenberg/32/77149_2.png) [@Vita\_Rosenberg](https://discuss.elastic.co/u/Vita_Rosenberg)\
**Post date:** [October 28, 2020, 11:36am UTC](https://discuss.elastic.co/t/grok-succeeds-in-debugger-and-through-input-stdin-but-with-this-config-file-im-getting-grokparsefailure/253556/1 "2020-10-28T11:36:02Z")

</div>

```auto
path => "C:/ELK/LocalLogs/*"
start_position => beginning
       }
     }
    filter {
      grok{
       match => { "message" => ["%{GREEDYDATA:first}%{DATE_US:date_}-%{TIME:time_}%{GREEDYDATA:last}"]}
       }

      date {
       match => ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]
            }
     }

    output{
      elasticsearch {
        index => "tst-%{+YYYY.MM.dd}"
        hosts => ["localhost:9200"]
      }
      stdout { codec => rubydebug }
    }

this is an example of the input:
library!WindowsService_3!2ec0!10/25/2020-00:00:26:: i INFO: Schedule ace8b126-f566-4324-aa48-a6123f81f28f executed at 10/21/2020 00:00:02.

while working with input{stdin and on any grok debugger it fails on the output to elasticsearch.
Please help. What am I doing wrong?

```

---

<div class="post-metadata">

**Author:** ![Vita\_Rosenberg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vita_rosenberg/32/77149_2.png) [@Vita\_Rosenberg](https://discuss.elastic.co/u/Vita_Rosenberg)\
**Post date:** [November 2, 2020, 9:12am UTC](https://discuss.elastic.co/t/grok-succeeds-in-debugger-and-through-input-stdin-but-with-this-config-file-im-getting-grokparsefailure/253556/2 "2020-11-02T09:12:55Z")

</div>

Hopefully this will help somebody...  
so I opened the log file with notepad++ and in the bottom right corner it shoes the type of encoding (attached)

then I entered this link : [https://www.elastic.co/guide/en/logstash/current/plugins-codecs-plain.html](https://www.elastic.co/guide/en/logstash/current/plugins-codecs-plain.html)

and found the closest name in the list' which is - "UCS-2BE"  
Then i added this line to the input{file{  
codec =\> plain {charset =\> "UCS-2BE"}  
Now it works.

![image](https://us1.discourse-cdn.com/elastic/original/3X/6/2/623792859e16581c7cf22e1a8b2bfbfc10570af3.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 2, 2020, 2:26pm UTC](https://discuss.elastic.co/t/grok-succeeds-in-debugger-and-through-input-stdin-but-with-this-config-file-im-getting-grokparsefailure/253556/3 "2020-11-02T14:26:18Z")

</div>

In general, if you have a 2 byte little-endian encoding, and tell the codec to use a 2 byte big-endian encoding I would not expect it to work. I would guess that because the file has a byte order mark (BOM) the codec works in UCS and decides whether to use BE or LE based on the BOM.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 30, 2020, 2:26pm UTC](https://discuss.elastic.co/t/grok-succeeds-in-debugger-and-through-input-stdin-but-with-this-config-file-im-getting-grokparsefailure/253556/4 "2020-11-30T14:26:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
