# Grokparsefailure but passes grok debugger

**URL:** <https://discuss.elastic.co/t/grokparsefailure-but-passes-grok-debugger/38377>\
**Category:** Logstash\
**Created:** [January 5, 2016, 6:58am UTC](https://discuss.elastic.co/t/grokparsefailure-but-passes-grok-debugger/38377 "2016-01-05T06:58:46Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![fijimunkii](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fijimunkii/32/6951_2.png) [@fijimunkii](https://discuss.elastic.co/u/fijimunkii)\
**Post date:** [January 5, 2016, 6:58am UTC](https://discuss.elastic.co/t/grokparsefailure-but-passes-grok-debugger/38377/1 "2016-01-05T06:58:46Z")

</div>

Hi, have been at this all night with no luck. Any help would be so appreciated!

```auto
Jan 5 04:26:13 ip-172-31-58-114 docker/user-repo/test-logs/c2f75d91f17f2d6831faa2283dbd28bc83abc1a1[13945]: 04:26:13 index-0 Tue, 05 Jan 2016 04:26:13 GMT -- ::ffff:172.17.0.28 -- - GET /styles/app.css 304 - https://domain.com/login 23.568 ms

```

```auto
filter {
  if [type] == "syslog" {
    grok {
      match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
    }
  }
}

```

```auto
"_source": {
    "message": "docker/user-repo/test-logs/c2f75d91f17f2d6831faa2283dbd28bc83abc1a1[13945]: 05:58:59 index-0 Tue, 05 Jan 2016 05:58:59 GMT -- ::ffff:172.17.0.28 -- - GET /styles/app.css 304 - https://domain.com/login 8.759 ms",
    "@version": "1",
    "@timestamp": "2016-01-05T05:59:16.573Z",
    "host": "52.91.107.130",
    "port": 49995,
    "type": "syslog",
    "tags": [
      "_grokparsefailure"
    ]
  },

```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 5, 2016, 7:01am UTC](https://discuss.elastic.co/t/grokparsefailure-but-passes-grok-debugger/38377/2 "2016-01-05T07:01:54Z")

</div>

This is what you claim that your message look like:

> ```
> Jan 5 04:26:13 ip-172-31-58-114 docker/user-repo/test-logs/c2f75d91f17f2d6831faa2283dbd28bc83abc1a1[13945]: 04:26:13 index-0 Tue, 05 Jan 2016 04:26:13 GMT -- ::ffff:172.17.0.28 -- - GET /styles/app.css 304 - https://domain.com/login 23.568 ms
> 
> ```

But this is what it actually looks like according to Logstash:

> ```
> docker/user-repo/test-logs/c2f75d91f17f2d6831faa2283dbd28bc83abc1a1[13945]: 05:58:59 index-0 Tue, 05 Jan 2016 05:58:59 GMT -- ::ffff:172.17.0.28 -- - GET /styles/app.css 304 - https://domain.com/login 8.759 ms"
> 
> ```

---

<div class="post-metadata">

**Author:** ![fijimunkii](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fijimunkii/32/6951_2.png) [@fijimunkii](https://discuss.elastic.co/u/fijimunkii)\
**Post date:** [January 5, 2016, 7:07am UTC](https://discuss.elastic.co/t/grokparsefailure-but-passes-grok-debugger/38377/3 "2016-01-05T07:07:21Z")

</div>

That makes sense. I was stuck on trying to parse the whole syslog entry rather than the message property. Thanks so much!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:16am UTC](https://discuss.elastic.co/t/grokparsefailure-but-passes-grok-debugger/38377/4 "2017-07-06T05:16:49Z")

</div>


