# Grokparse failure - but grokdebugger works

**URL:** <https://discuss.elastic.co/t/grokparse-failure-but-grokdebugger-works/280>\
**Category:** Logstash\
**Created:** [May 6, 2015, 11:31am UTC](https://discuss.elastic.co/t/grokparse-failure-but-grokdebugger-works/280 "2015-05-06T11:31:37Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jayem](https://avatars.discourse-cdn.com/v4/letter/j/b487fb/32.png) [@jayem](https://discuss.elastic.co/u/jayem)\
**Post date:** [May 6, 2015, 11:31am UTC](https://discuss.elastic.co/t/grokparse-failure-but-grokdebugger-works/280/1 "2015-05-06T11:31:37Z")

</div>

hi all

I have the following log line:

> {"rule":{"level":12,"comment":"apache error tagged by modsecurity","sidid":130401},"location":"(cli-git) 52.16.98.219-\>/var/log/apache2/error.log","full\_log":"[Tue May 05 09:09:08.901326 2015] [:error] [pid 7085] [client 212.48.71.196] ModSecurity: Warning. Pattern match "(?i:\\\\bor\\\\b ?(?:\\\\d{1,10}|[\\\\'\\"][^=]{1,10}[\\\\'\\"]) ?[=\<\>]+|(?i:'\\\\s+x?or\\\\s+.{1,20}[+\\\\-!\<\>=])|\\\\b(?i:x?or)\\\\b\\\\s+(\\\\d{1,10}|'[^=]{1,10}')|\\\\b(?i:x?or)\\\\b\\\\s+(\\\\d{1,10}|'[^=]{1,10}')\\\\s\*?[=\<\>])" at ARGS:id. [file "/usr/share/modsecurity-crs/activated\_rules/modsecurity\_crs\_41\_sql\_injection\_attacks.conf"] [line "133"] [id "959071"] [rev "2"] [msg "SQL Injection Attack"] [data "Matched Data: ' or true -- found within ARGS:id: ' or true -- "] [severity "CRITICAL"] [ver "OWASP\_CRS/2.2.9"] [maturity "9"] [accuracy "8"] [tag "OWASP\_CRS/WEB\_ATTACK/SQL\_INJECTION"] [tag "WASCTC/WASC-19"] [tag "OWASP\_TOP\_10/A1"] [tag "OWASP\_AppSensor/CIE1"] [tag "PCI/6.5.2"] [hostname "52.16.98.219"] [uri "/dvwa/vulnerabilities/sqli/"] [unique\_id "VUiItH8AAAEAAButAp4AAAAE"]"}

I am using the following filter and pattern. My input is stdin and codec =\> json.

> filter {  
> grok {  
> patterns\_dir =\> "./patterns"  
> match =\> ["full\_log", "%{FULLDATE:thedate}.+%{CLIENT:clientip}.+%{ATTACKVECTOR:attack}.+%{HOSTNAME:thehost}%{GREEDYDATA:therest}"]  
> }

In patterns/test:

> FULLDATE %{DAY} %{MONTH} %{MONTHDAY} %{TIME} %{YEAR}  
> ATTACKVECTOR msg \".+?\"  
> CLIENT client %{IPV4}  
> HOSTNAME hostname \"%{IPV4}\"

But the output (using stdout and codec =\> rubydebug) results in "full\_log" not being parsed and the line:

```
[0] "_grokparsefailure"

```

I've tested the filter & pattern on grokdebug and it works. I don't know why it doesn't work in real-life. I'm running OpenJDK java version "1.7.0\_79" on Ubuntu 14.04 with Logstash 1.4.2.

Thanks

Jay

---

<div class="post-metadata">

**Author:** ![nellicus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nellicus/32/51566_2.png) [@nellicus](https://discuss.elastic.co/u/nellicus)\
**Post date:** [May 7, 2015, 8:58am UTC](https://discuss.elastic.co/t/grokparse-failure-but-grokdebugger-works/280/2 "2015-05-07T08:58:17Z")

</div>

perhaps any whitespaces in the actual grok definition file?

---

<div class="post-metadata">

**Author:** ![nellicus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nellicus/32/51566_2.png) [@nellicus](https://discuss.elastic.co/u/nellicus)\
**Post date:** [May 7, 2015, 9:01am UTC](https://discuss.elastic.co/t/grokparse-failure-but-grokdebugger-works/280/3 "2015-05-07T09:01:18Z")

</div>

also shouldn't you be matching on "message" field instead?  
and how are you matchin

```
{"rule":{"level":12,"comment":"apache error tagged by modsecurity","sidid":130401},"location":"(cli-git) 52.16.98.219->/var/log/apache2/error.log","full_log":"[

```

?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 7, 2015, 10:43am UTC](https://discuss.elastic.co/t/grokparse-failure-but-grokdebugger-works/280/4 "2015-05-07T10:43:48Z")

</div>

> also shouldn't you be matching on "message" field instead?  
> and how are you matchin

This should be fine because of `codec => json`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:40am UTC](https://discuss.elastic.co/t/grokparse-failure-but-grokdebugger-works/280/5 "2017-07-06T05:40:09Z")

</div>


