# GROKPARSE Failure and after Successful debug

**URL:** <https://discuss.elastic.co/t/grokparse-failure-and-after-successful-debug/254324>\
**Category:** Logstash\
**Created:** [November 4, 2020, 8:10pm UTC](https://discuss.elastic.co/t/grokparse-failure-and-after-successful-debug/254324 "2020-11-04T20:10:49Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 4, 2020, 8:43pm UTC](https://discuss.elastic.co/t/grokparse-failure-and-after-successful-debug/254324/2 "2020-11-04T20:43:47Z")

</div>

I never use [grokdebug.herokuapp.com](http://grokdebug.herokuapp.com) or other grok debuggers (including kibana) because they sometimes interpret ambiguous regexps differently to grok. And many regexps that use DATA, or especially GREEDYDATA, are ambiguous. The process I suggest to develop complex grok patterns is documented [here](https://discuss.elastic.co/t/help-needed-in-grok/213827/2).

Please edit your post, select the log file entries and click on \</\> in the toolbar above the edit pane. In the preview pane you will see the display change to

```
at java.util.regex.Matcher.appendReplacement(Matcher.java:880)
at java.util.regex.Matcher.replaceAll(Matcher.java:955)
at java.lang.String.replaceAll(String.java:2223)

```

Then do the same for the configuration. Please do not do it to the whole post.

---

_[View the full topic](https://discuss.elastic.co/t/grokparse-failure-and-after-successful-debug/254324)._
