# \_grokparsefailure on \[fields\]\[document\_type\]

**URL:** https://discuss.elastic.co/t/grokparsefailure-on-fields-document-type/117312
**Category:** Logstash
**Created:** [January 27, 2018, 3:05pm UTC](https://discuss.elastic.co/t/grokparsefailure-on-fields-document-type/117312 "2018-01-27T15:05:11Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![mr.szop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mr.szop/32/27028_2.png) [@mr.szop](https://discuss.elastic.co/u/mr.szop)
#### Post date: [January 27, 2018, 3:05pm UTC](https://discuss.elastic.co/t/grokparsefailure-on-fields-document-type/117312/1 "2018-01-27T15:05:11Z")

</div>

Hey guys,

I'm having a hard time to understand my mistake getting a \_grokparsefailure on a Logstash filter. Im unsing an Apache access log and a NGINX access log which are prospected by Filebeat and then send to Logstash:

```
filebeat.prospectors:
- input_type: log
  paths:
    - /var/log/apache2/*access*log
  encoding: plain
  fields_under_root: false
  fields:
    document_type: apache-access-log
  scan_frequency: 10s
  harvester_buffer_size: 16384
  tail_files: false
  backoff: 1s
  max_backoff: 10s
  backoff_factor: 2
  max_bytes: 10485760

filebeat.prospectors:
- input_type: log
  paths:
    - /var/log/nginx/*access*log
  encoding: plain
  fields_under_root: false
  fields:
    document_type: nginx-access-log
  scan_frequency: 10s
  harvester_buffer_size: 16384
  tail_files: false
  backoff: 1s
  max_backoff: 10s
  backoff_factor: 2
  max_bytes: 10485760

```

On Logstash side I'm using following:

```
input {
  beats {
    port => 5050
    type => "logs"
  }
}

filter {
  if [fields][document_type] == "apache-access-log" {
    grok {
      match => { "message" => "%{COMBINEDAPACHELOG}"}
      add_tag => ["apache-access-log" , "grokked"]
    }
    geoip {
      source => "clientip"
    }
  }

output {
  elasticsearch { hosts => ["10.6.247.12:9200"] }
}

```

This is fine and Kibana is adding my defined tags "apache-access-log" and "grokked". But when I add a second filter for my NGINX access log like this:

```
input {
  beats {
    port => 5050
    type => "logs"
  }
}

filter {
  if [fields][document_type] == "apache-access-log" {
    grok {
      match => { "message" => "%{COMBINEDAPACHELOG}"}
      add_tag => ["apache-access-log" , "grokked"]
    }
    geoip {
      source => "clientip"
    }
  }

  if [fields][document_type] == "nginx-access-log" {
    grok {
      add_tag => ["nginx-access-log" , "grokked"]
    }
  }
}

output {
  elasticsearch { hosts => ["10.6.247.12:9200"] }
}

```

My NGINX access logs don't get aditional tags, moreover I get a \_grokparsefailure tag.

Running Filebeat in debug mode I see my defined fields:

```
2018/01/27 15:06:42.978815 client.go:214: DBG Publish: {
  "@timestamp": "2018-01-27T15:06:41.052Z",
  "beat": {
    "hostname": "SOME-HOSTNAME",
    "name": "SOME-DOMAIN",
    "version": "5.6.6"
  },
  "fields": {
    "document_type": "nginx-access-log"
  },
  "input_type": "log",
  "message": "[27/Jan/2018:16:06:38 +0100] Cache: - 10.6.247.12:8080 0.093 200 15121 SOMEIP /mountain-air-adventure/",
  "offset": 1598409,
  "source": "/var/log/nginx/SOME-DOMAIN.access_log",
  "type": "log"
}

```

Even when I run the NGINX access log filter on it's own, the result stays the same.

 ![kibana_grokfailure](https://us1.discourse-cdn.com/elastic/original/3X/9/b/9bda87ffb1dd2bce863bf1c32e4494bf8fa4f0f9.png)

Apache access log grok is working like expected:

![kibana_apache_grok](https://us1.discourse-cdn.com/elastic/original/3X/6/5/658942d00cc892fa96248b698c6e30346dbde004.png)

---

<div class="post-metadata">

### Author: ![jpcarey](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpcarey/32/46668_2.png) [@jpcarey](https://discuss.elastic.co/u/jpcarey)
#### Post date: [January 27, 2018, 4:05pm UTC](https://discuss.elastic.co/t/grokparsefailure-on-fields-document-type/117312/2 "2018-01-27T16:05:20Z")

</div>

You have a `match =>` pattern defined for the `apache-access-log` type, but not for the `nginx-access-log`. `_grokparsefailure` is added when the grok filter is not successful.

---

<div class="post-metadata">

### Author: ![mr.szop](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mr.szop/32/27028_2.png) [@mr.szop](https://discuss.elastic.co/u/mr.szop)
#### Post date: [January 27, 2018, 4:21pm UTC](https://discuss.elastic.co/t/grokparsefailure-on-fields-document-type/117312/3 "2018-01-27T16:21:33Z")

</div>

Yeah, and since I'm just adding a tag, I've to use mutate and not grok filter:

```
filter {
  if [fields][document_type] == "nginx-access-log" {
    mutate {
      add_tag => ["nginx-access-log" , "grokked"]
    }
  }
}

```

This topic can be closed.

Cheers,  
David

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 24, 2018, 4:34pm UTC](https://discuss.elastic.co/t/grokparsefailure-on-fields-document-type/117312/4 "2018-02-24T16:34:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
