# \_grokparsefailure because of time match

**URL:** <https://discuss.elastic.co/t/grokparsefailure-because-of-time-match/209585>\
**Category:** Logstash\
**Created:** [November 26, 2019, 9:52pm UTC](https://discuss.elastic.co/t/grokparsefailure-because-of-time-match/209585 "2019-11-26T21:52:48Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![04Konst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/04konst/32/53595_2.png) [@04Konst](https://discuss.elastic.co/u/04Konst)\
**Post date:** [November 26, 2019, 9:52pm UTC](https://discuss.elastic.co/t/grokparsefailure-because-of-time-match/209585/1 "2019-11-26T21:52:48Z")

</div>

Hi,

I am facing an issue while transferiang a data with converted time. In the logstash output everithing looks fine, but in Kibana I can see \_grokparsefailure. After few test I found out, that when I am deleting the "date" block from the configuration file everithing work. So this means that issue is in that block.

Config File:

> input {  
> file {  
> path =\> ["C:/ELK/LogFiles/Web/test.log"]  
> start\_position =\> "beginning"  
> type =\> "rest\_log"  
> }  
> }  
> filter{  
> grok{  
> match =\> ["message","%{IP:client\_ip}%{SPACE}-%{SPACE}-%{SPACE}[%{HTTPDATE:apache\_timestamp}]%{SPACE}"%{WORD:request\_method}%{SPACE}%{NOTSPACE:request\_url}%{SPACE}%{NOTSPACE:http\_version}"%{SPACE}%{NUMBER:response\_code}%{SPACE}%{NOTSPACE:bytes}%{SPACE}%{NOTSPACE}D:%{NOTSPACE:responsetime\_ms}%{SPACE}%{GREEDYDATA:user\_string}""]  
> }  
> date{  
> match =\> ["apache\_timestamp" , "dd/MMM/yyyy:HH:mm:ss +0100", "dd/MMM/yyyy:HH:mm:ss Z", "ISO8601"]  
> target =\> "@timestamp"  
> }  
> mutate {  
> convert =\> {  
> "bytes" =\> "integer"  
> "responsetime\_ms" =\> "integer"  
> }  
> }  
> }  
> output{  
> stdout {codec =\> rubydebug}  
> elasticsearch {  
> hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
> index =\> "my\_index"  
> }  
> }

Log Example:  
11.12.13.14 - - [12/Nov/2019:21:40:22 +0100] "GET //user/login HTTP/1.1" 404 208 "D:75"

Logstash Output

> "request\_url" =\> "/user/login",  
> "response\_code" =\> "404",  
> "http\_version" =\> "HTTP/1.1",  
> "request\_method" =\> "GET",  
> "responsetime\_ms" =\> 75,  
> "@timestamp" =\> 2019-11-12T20:40:30.000Z,  
> "path" =\> "C:/ELK/LogFiles/Web/test.log",  
> "host" =\> "CSTRL0047685567",  
> "message" =\> "11.12.13.14 - - [12/Nov/2019:21:40:30 +0100] "GET /user/login HTTP/1.1" 404 208 "D:75"",  
> "client\_ip" =\> "11.12.13.14",  
> "bytes" =\> 208,  
> "apache\_timestamp" =\> "12/Nov/2019:21:40:30 +0100",  
> "@version" =\> "1"  
> Blockquote

Thanks for your help!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 26, 2019, 10:24pm UTC](https://discuss.elastic.co/t/grokparsefailure-because-of-time-match/209585/2 "2019-11-26T22:24:13Z")

</div>

Try using

```
    grok{ match => { "message" => "%{IP:client_ip}%{SPACE}-%{SPACE}-%{SPACE}\[%{HTTPDATE:apache_timestamp}\]%{SPACE}\"%{WORD:request_method}%{SPACE}%{NOTSPACE:request_url}%{SPACE}%{NOTSPACE:http_version}\"%{SPACE}%{NUMBER:response_code}%{SPACE}%{NOTSPACE:bytes:int}%{SPACE}%{NOTSPACE}D:%{NOTSPACE:responsetime_ms:int}%{SPACE}%{GREEDYDATA:user_string}\"" } }
    date { match => ["apache_timestamp", "dd/MMM/yyyy:HH:mm:ss Z"] }
```

---

<div class="post-metadata">

**Author:** ![04Konst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/04konst/32/53595_2.png) [@04Konst](https://discuss.elastic.co/u/04Konst)\
**Post date:** [November 27, 2019, 8:43am UTC](https://discuss.elastic.co/t/grokparsefailure-because-of-time-match/209585/3 "2019-11-27T08:43:12Z")

</div>

> [@Badger](#):
>
> Try using

Thanks for your reply.

2 issues:

- Same error in Kibana -\> \_grokparsefailure (in cmd everithing looks good)
- time wasn't parsed propperly "apache\_timestamp" =\> "12/Nov/2019:21:40:12 +0100"

I can't explain that. Today I openned this config file if VSCode and Code highlighting looks strange to me:

 ![000043](https://us1.discourse-cdn.com/elastic/original/3X/5/f/5f6c829fe5284c36af1607736be4ad49a49899ab.jpeg)

I tryied to find issue in regex but without success.

---

<div class="post-metadata">

**Author:** ![04Konst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/04konst/32/53595_2.png) [@04Konst](https://discuss.elastic.co/u/04Konst)\
**Post date:** [November 27, 2019, 12:43pm UTC](https://discuss.elastic.co/t/grokparsefailure-because-of-time-match/209585/4 "2019-11-27T12:43:59Z")

</div>

Sorry have to correct myself. With this configuration I am getting the same issue (logstash output is ok), but \_grokparsefailure in Kibana

```
grok{ match => { "message" => "%{IP:client_ip}%{SPACE}-%{SPACE}-%{SPACE}\[%{HTTPDATE:apache_timestamp}\]%{SPACE}\"%{WORD:request_method}%{SPACE}%{NOTSPACE:request_url}%{SPACE}%{NOTSPACE:http_version}\"%{SPACE}%{NUMBER:response_code}%{SPACE}%{NOTSPACE:bytes:int}%{SPACE}%{NOTSPACE}D:%{NOTSPACE:responsetime_ms:int}%{SPACE}%{GREEDYDATA:user_string}\"" } }
date { 
  match => ["apache_timestamp", "dd/MMM/yyyy:HH:mm:ss Z"] 
  target => "@timestamp"
}
```

---

<div class="post-metadata">

**Author:** ![04Konst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/04konst/32/53595_2.png) [@04Konst](https://discuss.elastic.co/u/04Konst)\
**Post date:** [November 27, 2019, 1:22pm UTC](https://discuss.elastic.co/t/grokparsefailure-because-of-time-match/209585/5 "2019-11-27T13:22:55Z")

</div>

Ok, I found the issue (workaround).

I changed the target for apache\_timestamp:

```
date { 
  match => ["apache_timestamp" , "dd/MMM/yyyy:HH:mm:ss +0100", "dd/MMM/yyyy:HH:mm:ss Z", "ISO8601"]
  target => "@my_timestamp"
}

```

Than in Kibana I selected "my\_timestamp" as leading one by Idex creation.

@Badger: Thanks for your support!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 25, 2019, 1:23pm UTC](https://discuss.elastic.co/t/grokparsefailure-because-of-time-match/209585/6 "2019-12-25T13:23:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
