# Grokparsefailure in logstash

**URL:** <https://discuss.elastic.co/t/grokparsefailure-in-logstash/132558>\
**Category:** Elasticsearch\
**Created:** [May 19, 2018, 7:31am UTC](https://discuss.elastic.co/t/grokparsefailure-in-logstash/132558 "2018-05-19T07:31:06Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![aarthinim](https://avatars.discourse-cdn.com/v4/letter/a/35a633/32.png) [@aarthinim](https://discuss.elastic.co/u/aarthinim)\
**Post date:** [May 19, 2018, 7:31am UTC](https://discuss.elastic.co/t/grokparsefailure-in-logstash/132558/1 "2018-05-19T07:31:06Z")

</div>

In filebeat my file format is "2018-05-19 11:00:11,044 (default task-551) 329.0 user1 ip1 twKtby8RnvKWV4hq5nyJ4Dru4Ah1XuZLi9dR9\_0S.lrpv2-testing VPL-tbl-btnTblExportinput "  
In logstash My logstash.conf file is {  
beats { port =\> 5044 }  
}  
filter {  
if "newsamp" in [tags]{  
grok {  
match =\> {"message" =\>"%{TIMESTAMP\_ISO8601:mtimestamp} %{WORD:linename} %{NUMBER:consumetime} %{WORD:username} %{WORD:ipaddress} %{WORD:info} %{WORD:modulename}"}  
}  
mutate {  
convert =\> {  
"consumetime" =\> "integer"  
}  
}  
date {  
match =\> ["mtimestamp","yyyy-MM-dd HH:mm:ss"]  
target =\> "mtimestamp"  
}  
}  
}  
output{  
if "newsamp" in [tags] {  
stdout {  
codec =\> "rubydebug"  
}  
elasticsearch {  
hosts =\> "localhost:9200"  
user =\> "elastic"  
password =\> "elastic"  
manage\_template =\> false  
index =\> "testreport"  
document\_type =\> "test"  
}  
}  
}

In kibana I get output as  
{  
"\_index": "testreport",  
"\_type": "test",  
"\_id": "3GVAd2MBHMZ4DJSStT5I",  
"\_score": 1,  
"\_source": {  
"tags": [  
"newsamp",  
"beats\_input\_codec\_plain\_applied",  
"\_grokparsefailure"  
],  
"prospector": {  
"type": "log"  
},  
"@timestamp": "2018-05-19T07:15:17.158Z",  
"@version": "1",  
"offset": 300,  
"host": "Venkateshs-MacBook-Pro.local",  
"message": "2018-05-19 11:00:11,153 (default task-581) 437.0 expline 192.168.20.54\tdx-6xcrO6g6T4aKb7RxBhYeTKGoVaQP8mxSi\_uPI.lrpv2-testing FCN-FCN\_btnCustomCustomer",  
"beat": {  
"hostname": "Venkateshs-MacBook-Pro.local",  
"version": "6.2.3",  
"name": "Venkateshs-MacBook-Pro.local"  
},  
"source": "/Users/nfrteam/Desktop/ELKSamp/test1.log"  
}  
}  
]  
}  
}

And I need mtimestamp,linename,consumetime,username,ipaddress,info ,modulename as seperate fields .How do I get these ?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 26, 2018, 7:01am UTC](https://discuss.elastic.co/t/grokparsefailure-in-logstash/132558/2 "2018-05-26T07:01:52Z")

</div>

> [@aarthinim](#):
>
> "tags": [  
> "newsamp",  
> "beats\_input\_codec\_plain\_applied",  
> "\_grokparsefailure"  
> ],

The `_grokparsefailure` indicates that the grok pattern failed to match. Have a look at [this blog post](https://www.elastic.co/blog/a-practical-introduction-to-logstash) which describes how to work with Logstash and create a config using grok.

---

<div class="post-metadata">

**Author:** ![aarthinim](https://avatars.discourse-cdn.com/v4/letter/a/35a633/32.png) [@aarthinim](https://discuss.elastic.co/u/aarthinim)\
**Post date:** [May 28, 2018, 10:45am UTC](https://discuss.elastic.co/t/grokparsefailure-in-logstash/132558/3 "2018-05-28T10:45:07Z")

</div>

Thank you, I changed the grok pattern as given in the blog now its working .

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 25, 2018, 10:45am UTC](https://discuss.elastic.co/t/grokparsefailure-in-logstash/132558/4 "2018-06-25T10:45:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
