# \_grokparsefailure in Kibana tag (Synology messages)

**URL:** <https://discuss.elastic.co/t/grokparsefailure-in-kibana-tag-synology-messages/111496>\
**Category:** Logstash\
**Created:** [December 13, 2017, 7:09am UTC](https://discuss.elastic.co/t/grokparsefailure-in-kibana-tag-synology-messages/111496 "2017-12-13T07:09:44Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![hispeed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hispeed/32/16232_2.png) [@hispeed](https://discuss.elastic.co/u/hispeed)\
**Post date:** [December 13, 2017, 7:09am UTC](https://discuss.elastic.co/t/grokparsefailure-in-kibana-tag-synology-messages/111496/1 "2017-12-13T07:09:44Z")

</div>

Hi,

I recieve a \_grokparsefailure in Kibana tags but all the fields are splitted correct. How can I remove the grokparsefailure for those incomming messages?

```
   if [logsource] == "BackupStation" {
     mutate {
       add_tag => ["SynologyBackupstation"]
       }

      kv {
               value_split => ":"
               field_split => ","
       }
  }

```

How could I track that failure down to the problem from where it is comming from?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 13, 2017, 1:42pm UTC](https://discuss.elastic.co/t/grokparsefailure-in-kibana-tag-synology-messages/111496/2 "2017-12-13T13:42:53Z")

</div>

Show an example event that exhibits the problem. Copy/paste from Kibana's JSON tab.

---

<div class="post-metadata">

**Author:** ![hispeed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hispeed/32/16232_2.png) [@hispeed](https://discuss.elastic.co/u/hispeed)\
**Post date:** [December 13, 2017, 3:12pm UTC](https://discuss.elastic.co/t/grokparsefailure-in-kibana-tag-synology-messages/111496/3 "2017-12-13T15:12:52Z")

</div>

Hi Magnus,

No problem:

```
{
  "_index": "logstash-2017.12.13",
  "_type": "syslog",
  "_id": "ArxpUGABKDf7kXJ8cWPV",
  "_version": 1,
  "_score": null,
  "_source": {
    "severity": 6,
    " User": "Marc XXXXX",
    "syslog_severity_code": 5,
    "syslog_facility": "user-level",
    " IP": "192.168.0.29\n",
    "syslog_facility_code": 1,
    " Size": "3.07 MB",
    "message": "WinFileService Event: read, Path: /Privat Marc XXX/Eigene Dateien/Weiterbildung/XXXXX/5. Semester/Führung und Personalmanagement/Gruppenarbeit/XXXXX.docx, File/Folder: File, Size: 3.07 MB, User: Marc XXX, IP: 192.168.0.29\n",
    "type": "syslog",
    "priority": 14,
    "logsource": "Titanserver",
    " Path": "/Privat Marc XXXX/Eigene Dateien/Weiterbildung/Dipl. XXXX/5. Semester/Führung und Personalmanagement/Gruppenarbeit/ParkSpace4U.docx",
    "syslog_severity": "notice",
    "tags": [
      "syslog",
      "_grokparsefailure",
      "SynologyTitanserver"
    ],
    "WinFileService Event": "read",
    "@timestamp": "2017-12-13T15:06:15.000Z",
    "@version": "1",
    "host": "192.168.0.20",
    " File/Folder": "File",
    "facility": 1,
    "severity_label": "Informational",
    "timestamp": "Dec 13 16:06:15",
    "facility_label": "user-level"
  },
  "fields": {
    "@timestamp": [
      "2017-12-13T15:06:15.000Z"
    ]
  },
  "highlight": {
    "logsource": [
      "@kibana-highlighted-field@Titanserver@/kibana-highlighted-field@"
    ]
  },
  "sort": [
    1513177575000
  ]
}

```

For this Synology Server I have the same filter as above.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 13, 2017, 8:11pm UTC](https://discuss.elastic.co/t/grokparsefailure-in-kibana-tag-synology-messages/111496/4 "2017-12-13T20:11:12Z")

</div>

What does your full configuration look like?

---

<div class="post-metadata">

**Author:** ![hispeed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hispeed/32/16232_2.png) [@hispeed](https://discuss.elastic.co/u/hispeed)\
**Post date:** [December 13, 2017, 8:35pm UTC](https://discuss.elastic.co/t/grokparsefailure-in-kibana-tag-synology-messages/111496/5 "2017-12-13T20:35:16Z")

</div>

I sent you a link for downloading the files.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 14, 2017, 6:22am UTC](https://discuss.elastic.co/t/grokparsefailure-in-kibana-tag-synology-messages/111496/6 "2017-12-14T06:22:02Z")

</div>

I only spend time on publicly posted questions and details so please post the link publicly.

---

<div class="post-metadata">

**Author:** ![hispeed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hispeed/32/16232_2.png) [@hispeed](https://discuss.elastic.co/u/hispeed)\
**Post date:** [December 20, 2017, 3:06pm UTC](https://discuss.elastic.co/t/grokparsefailure-in-kibana-tag-synology-messages/111496/7 "2017-12-20T15:06:38Z")

</div>

Okey here is the link for downloading all the configuration files.

[https://mega.nz/#!QbxFBYza!00uFmeOn5QM9irEORlMSpiqOnfhNxap52YPgVgSdg5Y](https://mega.nz/#!QbxFBYza!00uFmeOn5QM9irEORlMSpiqOnfhNxap52YPgVgSdg5Y)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 21, 2017, 7:18am UTC](https://discuss.elastic.co/t/grokparsefailure-in-kibana-tag-synology-messages/111496/8 "2017-12-21T07:18:01Z")

</div>

Nothing obviously wrong there. You don't have any extra files in /etc/logstash/conf.d apart from the five .conf files you included in the archive? What does an example input syslog event look like?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 18, 2018, 7:18am UTC](https://discuss.elastic.co/t/grokparsefailure-in-kibana-tag-synology-messages/111496/9 "2018-01-18T07:18:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
