Grokparse failure - but grokdebugger works

also shouldn't you be matching on "message" field instead?
and how are you matchin

This should be fine because of codec => json.