# \_Grokparsefailure even though pattern works in Grok Debugger

**URL:** <https://discuss.elastic.co/t/grokparsefailure-even-though-pattern-works-in-grok-debugger/149179>\
**Category:** Logstash\
**Created:** [September 19, 2018, 6:47pm UTC](https://discuss.elastic.co/t/grokparsefailure-even-though-pattern-works-in-grok-debugger/149179 "2018-09-19T18:47:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Samvid\_Kulkarni](https://avatars.discourse-cdn.com/v4/letter/s/439d5e/32.png) [@Samvid\_Kulkarni](https://discuss.elastic.co/u/Samvid_Kulkarni)\
**Post date:** [September 19, 2018, 6:47pm UTC](https://discuss.elastic.co/t/grokparsefailure-even-though-pattern-works-in-grok-debugger/149179/1 "2018-09-19T18:47:43Z")

</div>

I am trying to parse IIS logs and I did test my pattern in the Grok Dubugger (inside Kibana) and it is working perfectly fine but logstash is giving me \_grokparsefailure.

Here is my config file

```
input {
	file {
    type => "w3svc"
    start_position => "beginning"
    sincedb_path => "/dev/null"
    path => "/Users/samvidkulkarni/Desktop/Input/joust2-20180913_145201-w3svc2.txt"
  }
}

filter {
    if [type] == "w3svc"
    {
    grok {

    match => ["message", "^%{TIMESTAMP_ISO8601:timestamp} %{NOTSPACE:s-ip} %{WORD:cs-method} %{NOTSPACE:cs-uri-stem} %{NOTSPACE:cs-uri-query} %{NUMBER:s-port} %{NOTSPACE:cs-username} %{NOTSPACE:c-ip} %{NOTSPACE:csUser-Agent} %{NOTSPACE:csReferer} %{NUMBER:sc-status} %{NUMBER:sc-substatus} %{NUMBER:sc-win32-status} %{NUMBER:time-taken}"]  
   
   }

   geoip {
      add_tag => ["ClientGeoIP"]
      tag_on_failure => []
      source => "c-ip"
      target => "c-ip"
      add_field => ["[c-ip][coordinates]", "%{[c-ip][longitude]}" ]
      add_field => ["[c-ip][coordinates]", "%{[c-ip][latitude]}" ]
    }

    geoip {
      add_tag => ["ServerGeoIP"]
      tag_on_failure => []
      source => "s-ip"
      target => "s-ip"
      add_field => ["[s-ip][coordinates]", "%{[s-ip][longitude]}" ]
      add_field => ["[s-ip][coordinates]", "%{[s-ip][latitude]}" ]
    } 
   
 }
 }
	

output
{
	  if [type] == "w3svc" {
    elasticsearch {
      manage_template => false
      hosts => ["localhost:9200"]
      index => "w3svc-%{+YYYY.MM.dd}"
    }
    stdout { codec => rubydebug }

  }
}

```

Here is my output from IIS log file

```auto
2018-09-13 21:45:05 10.3.47.10 POST /EWS/Exchange.asmx &request_id=88de1f28-f7c8-4349-a85d-f169f12a9683 444 swfs\\tmsxe 10.4.47.11 TMSXE+5.5.0+(ExchangeServicesClient/15.00.0913.015) - 200 0 0 66

```

here is the output of logstash in console

```
{
          "path" => "/Users/samvidkulkarni/Desktop/Input/joust2-20180913_145201-w3svc2.txt",
          "tags" => [
        [0] "_grokparsefailure"
    ],
       "message" => "2018-09-13 21:45:05 10.3.47.10 POST /EWS/Exchange.asmx &request_id=88de1f28-f7c8-4349-a85d-f169f12a9683 444 swfs\\tmsxe 10.4.47.11 TMSXE+5.5.0+(ExchangeServicesClient/15.00.0913.015) - 200 0 0 66\r",
          "host" => "sam-MacBook-Air.local",
          "type" => "w3svc",
      "@version" => "1",
    "@timestamp" => 2018-09-19T18:37:13.798Z
}
```

---

<div class="post-metadata">

**Author:** ![yahuu](https://avatars.discourse-cdn.com/v4/letter/y/90db22/32.png) [@yahuu](https://discuss.elastic.co/u/yahuu)\
**Post date:** [September 25, 2018, 3:40pm UTC](https://discuss.elastic.co/t/grokparsefailure-even-though-pattern-works-in-grok-debugger/149179/2 "2018-09-25T15:40:31Z")

</div>

In the documentation a "=\>" is used after "message".  
Also they use a "{" bracket instead of "[",

```
filter {
  grok {
    match => { "message" => "%{SYSLOGBASE} %{POSTFIX_QUEUEID:queue_id}: %{GREEDYDATA:syslog_message}" }
  }
}
```

---

<div class="post-metadata">

**Author:** ![Samvid\_Kulkarni](https://avatars.discourse-cdn.com/v4/letter/s/439d5e/32.png) [@Samvid\_Kulkarni](https://discuss.elastic.co/u/Samvid_Kulkarni)\
**Post date:** [October 1, 2018, 11:00pm UTC](https://discuss.elastic.co/t/grokparsefailure-even-though-pattern-works-in-grok-debugger/149179/3 "2018-10-01T23:00:48Z")

</div>

thanks you sir. It works now.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 29, 2018, 11:01pm UTC](https://discuss.elastic.co/t/grokparsefailure-even-though-pattern-works-in-grok-debugger/149179/4 "2018-10-29T23:01:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
