# Grokparsefailure on logstash

**URL:** <https://discuss.elastic.co/t/grokparsefailure-on-logstash/273047>\
**Category:** Logstash\
**Created:** [May 14, 2021, 4:31pm UTC](https://discuss.elastic.co/t/grokparsefailure-on-logstash/273047 "2021-05-14T16:31:56Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![srk1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/srk1/32/88697_2.png) [@srk1](https://discuss.elastic.co/u/srk1)\
**Post date:** [May 14, 2021, 4:31pm UTC](https://discuss.elastic.co/t/grokparsefailure-on-logstash/273047/1 "2021-05-14T16:31:56Z")

</div>

Hi ES users, i'm trying to send a simple log using filebeat on to ES via logstash and i'm experiencing grokparsefailure errors on kibana. Can someone please assist on what type of grok filter needs to be used? Below is the file i'm trying to input via filebeat.  
CreateTime:1621009744368 PING  
CreateTime:1621009748711 PING  
CreateTime:1621009753392 PING  
CreateTime:1621009757660 PING  
CreateTime:1621009761982 PING  
CreateTime:1621009766368 PING  
CreateTime:1621009770798 PING  
CreateTime:1621009775271 PING

Thanks,  
SRK

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 14, 2021, 4:34pm UTC](https://discuss.elastic.co/t/grokparsefailure-on-logstash/273047/2 "2021-05-14T16:34:23Z")

</div>

What does your grok filter configuration look like?

---

<div class="post-metadata">

**Author:** ![srk1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/srk1/32/88697_2.png) [@srk1](https://discuss.elastic.co/u/srk1)\
**Post date:** [May 14, 2021, 5:08pm UTC](https://discuss.elastic.co/t/grokparsefailure-on-logstash/273047/3 "2021-05-14T17:08:47Z")

</div>

Hi Badger,  
Following is the grok filter for existing file and the one i shared earlier is the new file without any grok.

filter{  
grok {  
match =\> { "message" =\> "[%{TIMESTAMP\_ISO8601:log-timestamp}] %{LOGLEVEL:log-level} %{GREEDYDATA:log-message}" }  
}  
mutate {  
remove\_field =\> ["message"]  
}  
}  
Thanks,  
SRK

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 14, 2021, 5:51pm UTC](https://discuss.elastic.co/t/grokparsefailure-on-logstash/273047/4 "2021-05-14T17:51:42Z")

</div>

That pattern in no way matches the example log entry you gave. It has a timestamp in milliseconds since the epoch, not an ISO8601 timestamp, it does not have square brackets, it does not have a LOGLEVEL. It is just completely the wrong pattern.

---

<div class="post-metadata">

**Author:** ![srk1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/srk1/32/88697_2.png) [@srk1](https://discuss.elastic.co/u/srk1)\
**Post date:** [May 14, 2021, 6:08pm UTC](https://discuss.elastic.co/t/grokparsefailure-on-logstash/273047/5 "2021-05-14T18:08:37Z")

</div>

Yes, that's what i am trying to show. That pattern is for existing log input file but i just added the new log output that i shared earlier and i want to know what grok pattern fits for the new log entry.

Thanks,  
SRK.

---

<div class="post-metadata">

**Author:** ![srk1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/srk1/32/88697_2.png) [@srk1](https://discuss.elastic.co/u/srk1)\
**Post date:** [May 18, 2021, 5:25am UTC](https://discuss.elastic.co/t/grokparsefailure-on-logstash/273047/6 "2021-05-18T05:25:44Z")

</div>

Hi Badger,  
I am trying to get the correct grok filter for the below line:  
CreateTime:1621314039222 PING

grok {  
match =\> { "message" =\> "%{GREEDYDATA:time}:%{NUMBER:timestamp} %{SPACE} %{GREEDYDATA:message}"  
}

Can you please correct it?

Thanks,  
SRK

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 18, 2021, 1:03pm UTC](https://discuss.elastic.co/t/grokparsefailure-on-logstash/273047/7 "2021-05-18T13:03:10Z")

</div>

You have spaces around %{SPACE} so that pattern will require at least two spaces in the [message] field. Remove the spaces.

---

<div class="post-metadata">

**Author:** ![srk1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/srk1/32/88697_2.png) [@srk1](https://discuss.elastic.co/u/srk1)\
**Post date:** [May 18, 2021, 3:36pm UTC](https://discuss.elastic.co/t/grokparsefailure-on-logstash/273047/8 "2021-05-18T15:36:02Z")

</div>

HI, I tried removing the spaces but looks like not working. Do you mind giving me the right format? Thanks and appreciate your help.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 18, 2021, 5:12pm UTC](https://discuss.elastic.co/t/grokparsefailure-on-logstash/273047/9 "2021-05-18T17:12:29Z")

</div>

I would expect

```
"%{GREEDYDATA:time}:%{NUMBER:timestamp}%{SPACE}%{GREEDYDATA:message}"

```

to match.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 15, 2021, 5:12pm UTC](https://discuss.elastic.co/t/grokparsefailure-on-logstash/273047/10 "2021-06-15T17:12:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
