# "\_grokparsefailure" for pattern that works on grok debugger

**URL:** <https://discuss.elastic.co/t/grokparsefailure-for-pattern-that-works-on-grok-debugger/241224>\
**Category:** Logstash\
**Created:** [July 15, 2020, 5:33am UTC](https://discuss.elastic.co/t/grokparsefailure-for-pattern-that-works-on-grok-debugger/241224 "2020-07-15T05:33:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Khaled3500](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khaled3500/32/72453_2.png) [@Khaled3500](https://discuss.elastic.co/u/Khaled3500)\
**Post date:** [July 15, 2020, 5:33am UTC](https://discuss.elastic.co/t/grokparsefailure-for-pattern-that-works-on-grok-debugger/241224/1 "2020-07-15T05:33:21Z")

</div>

Hello, I created a grok pattern and it works well on grok debugger but when i add to filter inside the pipeline it pass the restart phase for the service but on kibana it give this tag ["\_grokparsefailure"] i tried to debug it but couldn't reach any solution here is l log sample which i created the grok for:

```auto
<14> Server MTM: 8871AC1 Alert Text: Login ID: USERID from webguis at IP address 10.0.6.87 has logged off. Type of Alert: System - Remote Login Severity: 4 Date(m/d/y): 07/14/2020 Time(h:m:s): 21:57:48 Contact: it@sumerge.com Location: Cairo IMM Text ID: Lenovo System x3650 M5 IMM Serial Number: J335FWW IMM UUID: 11797DCA56B611E79CC00894EF47086E Event ID: 4000009d00000000 Serviceable Event Indicator: Not Serviceable FRU list: Not available Room ID: Not available Rack ID: Not available Lowest U-position: 0 Blade Bay: Not available Test Alert: no Auxiliary Data: Not available Common Event ID: Not available Event Type: 0 Report Chain: Not available

```

and here is the grok pattern that works well on grok debugger:

```auto
%{SYSLOG5424PRI}%{SPACE}Server MTM:%{DATA:server_mtm} Alert Text: %{DATA:message} Type of Alert: %{DATA:alert_type} Severity: %{DATA:severity} Date\(m\/d\/y\): %{DATE:date} Time\(h\:m\:s\): %{DATA:time} Contact: %{DATA:contact} Location: %{DATA:location} IMM Text ID: %{DATA:text_id} Serial Number: %{DATA:serial_number} IMM UUID: %{DATA:imm_uuid} Event ID: %{DATA:event_id}%{SPACE} %{GREEDYDATA:data}

```

and here is my pipeline itself:

```auto
input {
  udp {
    port => 5516
    type => syslog
 }
}

filter {
  grok {
    match => {
       "message" => ["%{SYSLOG5424PRI}%{SPACE}Server MTM:%{DATA:server_mtm} Alert Text: %{DATA:message} Type of Alert: %{DATA:alert_type} Severity: %{DATA:severity} Date\(m\/d\/y\): %{DATE:date} Time\(h\:m\:s\): %{DATA:time} Contact: %{DATA:contact} Location: %{DATA:location} IMM Text ID: %{DATA:text_id} Serial Number: %{DATA:serial_number} IMM UUID: %{DATA:imm_uuid} Event ID: %{DATA:event_id}%{SPACE} %{GREEDYDATA:data}"]
    }
    overwrite => ["message"]
    add_field => ["received_at", "%{@timestamp}"]
    add_field => ["received_from", "%{host}"]
    remove_field => ["syslog5424_pri", "data"]
  }
}

output {
  elasticsearch {
    hosts => ["http://10.0.200.120:9200"]
    index => "lenovo-x3650-%{+YYYY.MM.dd}"
  }
}

```

here is a screenshot from kibana showing the log itself and the error that appears:

 ![grokfailure](https://us1.discourse-cdn.com/elastic/original/3X/7/3/7323cc7418ecc8be1edc052aa5ccdfd4a9941364.jpeg)

if anyone could help me i'd be greatful

Thank you

---

<div class="post-metadata">

**Author:** ![Khaled3500](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khaled3500/32/72453_2.png) [@Khaled3500](https://discuss.elastic.co/u/Khaled3500)\
**Post date:** [July 15, 2020, 12:53pm UTC](https://discuss.elastic.co/t/grokparsefailure-for-pattern-that-works-on-grok-debugger/241224/2 "2020-07-15T12:53:53Z")

</div>

after adding this line to pipeline i got to see the actual output on screen

```auto
  stdout { codec => rubydebug }

```

the log line being parsed is very different from the one that appears to me in kibana which obviously show why \_grokparsefailure appear

```auto
<14>\tServer MTM: 8871AC1\n\n\n\tAlert Text: Login ID: USERID from webguis at IP address 10.0.6.87 has logged off.\n\tType of Alert: System - Remote Login\n\n\tSeverity: 4\n\tDate(m/d/y): 07/15/2020\n\tTime(h:m:s): 14:19:28\n\n\tContact: it@sumerge.com\n\n\tLocation: Cairo\n\tIMM Text ID: Lenovo System x3650 M5\n\tIMM Serial Number: J335FWW\n\tIMM UUID: 11797DCA56B611E79CC00894EF47086E\n\tEvent ID: 4000009d00000000\n\tServiceable Event Indicator: Not Serviceable\n\tFRU list: Not available\n\tRoom ID: Not available\n\tRack ID: Not available\n\tLowest U-position: 0\n\tBlade Bay: Not available\n\tTest Alert: no\n\tAuxiliary Data: Not available\n\tCommon Event ID: Not available\n\tEvent Type: 0\n\tReport Chain: Not available

```

fixed the problem by mutating the log itself before parsing it and the pipeline is as follow:

```auto
input {
  udp {
    port => 5516
    type => syslog
 }
}

filter {
  mutate {
    gsub => ["message", "\n\n\t", " "]
    gsub => ["message", "\t", " "]
    gsub => ["message", "\n", ""]
  }
  grok {
    match => {
       "message" => ["%{SYSLOG5424PRI}%{SPACE}Server MTM:%{DATA:server_mtm} Alert Text: %{DATA:message} Type of Alert: %{DATA:alert_type} Severity: %{NUMBER:severity} Date\(m\/d\/y\): %{DATE:date} Time\(h\:m\:s\): %{TIME:time} Contact: %{DATA:contact} Location: %{DATA:location} IMM Text ID: %{DATA:imm_text_id} Serial Number: %{DATA:serial_number} IMM UUID: %{DATA:imm_uuid} Event ID: %{DATA:event_id}%{SPACE} %{GREEDYDATA:data}"]
    }
    overwrite => ["message"]
    add_field => ["received_at", "%{@timestamp}"]
    add_field => ["received_from", "%{host}"]
    remove_field => ["syslog5424_pri", "data"]
  }
}

output {
  elasticsearch {
    hosts => ["http://10.0.200.120:9200"]
    index => "lenovo-x3650-%{+YYYY.MM.dd}"
  }
}

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 16, 2020, 1:51am UTC](https://discuss.elastic.co/t/grokparsefailure-for-pattern-that-works-on-grok-debugger/241224/3 "2020-07-16T01:51:21Z")

</div>

I'll close this in favour of [Tag ["\_parsegrokfailure"] anyone could help me?](https://discuss.elastic.co/t/tag-parsegrokfailure-anyone-could-help-me/241190).

In future please don't post the same question multiple times, it makes it harder to get assistance 🙂

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 16, 2020, 1:51am UTC](https://discuss.elastic.co/t/grokparsefailure-for-pattern-that-works-on-grok-debugger/241224/4 "2020-07-16T01:51:23Z")

</div>


