# \_grokparsefailure but grok debugger looks good

**URL:** <https://discuss.elastic.co/t/grokparsefailure-but-grok-debugger-looks-good/279269>\
**Category:** Logstash\
**Created:** [July 21, 2021, 1:06pm UTC](https://discuss.elastic.co/t/grokparsefailure-but-grok-debugger-looks-good/279269 "2021-07-21T13:06:08Z")\
**Posts on this page:** 1\
**Showing post:** 17

<div class="post-metadata">

**Author:** ![Cad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cad/32/86661_2.png) [@Cad](https://discuss.elastic.co/u/Cad)\
**Post date:** [July 22, 2021, 12:12pm UTC](https://discuss.elastic.co/t/grokparsefailure-but-grok-debugger-looks-good/279269/17 "2021-07-22T12:12:12Z")

</div>

I think, if it is a problem of permission, an error will be write in logsatsh log file.  
You have to give permission to user or group `logstash` to access the file.  
`chmod -R logstash /path/to/patterns`

If you can't change access to files, grok have an option named pattern\_definitions (example [here](https://discuss.elastic.co/t/grok-multiple-pattern-definitions/254797/2)).

---

_[View the full topic](https://discuss.elastic.co/t/grokparsefailure-but-grok-debugger-looks-good/279269)._
