# Grokfilter Parser error

**URL:** <https://discuss.elastic.co/t/grokfilter-parser-error/241236>\
**Category:** Logstash\
**Created:** [July 15, 2020, 7:25am UTC](https://discuss.elastic.co/t/grokfilter-parser-error/241236 "2020-07-15T07:25:57Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 20, 2020, 5:10pm UTC](https://discuss.elastic.co/t/grokfilter-parser-error/241236/6 "2020-07-20T17:10:27Z")

</div>

I would use dissect to extract the IP and timestamp, then a kv filter to parse the rest of the line. See [this](https://discuss.elastic.co/t/filter-logs-from-firewall/172494/3) example.

---

_[View the full topic](https://discuss.elastic.co/t/grokfilter-parser-error/241236)._
