# Grokfilter Parser error

**URL:** <https://discuss.elastic.co/t/grokfilter-parser-error/241236>\
**Category:** Logstash\
**Created:** [July 15, 2020, 7:25am UTC](https://discuss.elastic.co/t/grokfilter-parser-error/241236 "2020-07-15T07:25:57Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Deepika\_Rawat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/deepika_rawat/32/71899_2.png) [@Deepika\_Rawat](https://discuss.elastic.co/u/Deepika_Rawat)\
**Post date:** [July 15, 2020, 7:25am UTC](https://discuss.elastic.co/t/grokfilter-parser-error/241236/1 "2020-07-15T07:25:57Z")

</div>

I have a log file with data like this  
indent preformatted text by 4 spaces  
172.16.3.254 Jun 22 11:00:40 date=2020-06-22 local7 notice time=11:00:39 devname="MIBLR\_FW\_1" devid="FG200ETK19907000" logid="0000000013" type="traffic" subtype="forward" level="notice" vd="root" eventtime=1592803839 srcip=10.212.134.155  
i made a conf program to import data to elk  
but it is not parsing grok filter  
My filter section is : `Preformatted text`filter {

grok {  
match =\> { "message" =\> "%{IP:client}%{TIMESTAMP\_ISO8601:date}\s+%{GREEDYDATA:KV}"}  
}

kv {  
source =\> "KV"  
field\_split =\> " "

}  
}  
Am i correct..if not kindly help me to correct my program

---

<div class="post-metadata">

**Author:** ![Deepika\_Rawat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/deepika_rawat/32/71899_2.png) [@Deepika\_Rawat](https://discuss.elastic.co/u/Deepika_Rawat)\
**Post date:** [July 15, 2020, 7:30am UTC](https://discuss.elastic.co/t/grokfilter-parser-error/241236/2 "2020-07-15T07:30:30Z")

</div>

my error is..  
indent preformatted text by 4 spaces  
[0] "\_grokparsefailure"

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [July 17, 2020, 6:42am UTC](https://discuss.elastic.co/t/grokfilter-parser-error/241236/4 "2020-07-17T06:42:25Z")

</div>

Your time stamp is not in ISO8601 format which means the grok does not work.

---

<div class="post-metadata">

**Author:** ![Deepika\_Rawat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/deepika_rawat/32/71899_2.png) [@Deepika\_Rawat](https://discuss.elastic.co/u/Deepika_Rawat)\
**Post date:** [July 20, 2020, 10:34am UTC](https://discuss.elastic.co/t/grokfilter-parser-error/241236/5 "2020-07-20T10:34:13Z")

</div>

well thank you but Is there another way to match this type of date format in grok..so far i found out `MMM dd HH:mm:ss` this for parsing but no idea how to write this in program

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 20, 2020, 5:10pm UTC](https://discuss.elastic.co/t/grokfilter-parser-error/241236/6 "2020-07-20T17:10:27Z")

</div>

I would use dissect to extract the IP and timestamp, then a kv filter to parse the rest of the line. See [this](https://discuss.elastic.co/t/filter-logs-from-firewall/172494/3) example.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 17, 2020, 5:54pm UTC](https://discuss.elastic.co/t/grokfilter-parser-error/241236/8 "2020-08-17T17:54:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
