# Grokparsefailure, but works in grok debugger

**URL:** <https://discuss.elastic.co/t/grokparsefailure-but-works-in-grok-debugger/45613>\
**Category:** Logstash\
**Created:** [March 28, 2016, 5:21pm UTC](https://discuss.elastic.co/t/grokparsefailure-but-works-in-grok-debugger/45613 "2016-03-28T17:21:32Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mikeface](https://avatars.discourse-cdn.com/v4/letter/m/77aa72/32.png) [@mikeface](https://discuss.elastic.co/u/mikeface)\
**Post date:** [March 28, 2016, 5:21pm UTC](https://discuss.elastic.co/t/grokparsefailure-but-works-in-grok-debugger/45613/1 "2016-03-28T17:21:32Z")

</div>

Hey guys, need some help with grok, kind of at a loss. I've used Logstash quite a bit in the past, never run into this issue. On Logstash v2.2.2, I can't seem to get grok to parse some logs from Nginx. They have some custom fields added, but as mentioned in the title, the pattern I have works fine in [https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/).

Here is a sample message and my logstash config:  
[http://pastebin.com/VfU7iB6B](http://pastebin.com/VfU7iB6B)

Any ideas?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 29, 2016, 5:46am UTC](https://discuss.elastic.co/t/grokparsefailure-but-works-in-grok-debugger/45613/2 "2016-03-29T05:46:10Z")

</div>

The standard advice is to start with the very simplest grok expression, in your case just `%{URIHOST}`, and verify that that works. If so, add the next token and try again. At some point things are going to start failing and then you should be able to narrow down where the error is.

---

<div class="post-metadata">

**Author:** ![mikeface](https://avatars.discourse-cdn.com/v4/letter/m/77aa72/32.png) [@mikeface](https://discuss.elastic.co/u/mikeface)\
**Post date:** [March 29, 2016, 3:30pm UTC](https://discuss.elastic.co/t/grokparsefailure-but-works-in-grok-debugger/45613/3 "2016-03-29T15:30:17Z")

</div>

Thanks magnus, I completely forgot about doing it that way. Got it sorted out!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:04am UTC](https://discuss.elastic.co/t/grokparsefailure-but-works-in-grok-debugger/45613/4 "2017-07-06T05:04:54Z")

</div>


