# \_grokparsefailure problem

**URL:** <https://discuss.elastic.co/t/grokparsefailure-problem/194038>\
**Category:** Logstash\
**Created:** [August 6, 2019, 2:48pm UTC](https://discuss.elastic.co/t/grokparsefailure-problem/194038 "2019-08-06T14:48:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Manal\_Sadgal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manal_sadgal/32/51763_2.png) [@Manal\_Sadgal](https://discuss.elastic.co/u/Manal_Sadgal)\
**Post date:** [August 6, 2019, 2:48pm UTC](https://discuss.elastic.co/t/grokparsefailure-problem/194038/1 "2019-08-06T14:48:36Z")

</div>

Hello,  
I have a problem with my filter, i get the "\_grokparsefailure" tag when the concerned logs are processed.  
Here is my filter file:  
filter {  
if [source] == "/var/log/auth.log"{  
grok {  
match =\> ["message", "%{SYSLOGTIMESTAMP:date} %{SYSLOGHOST:host} %{DATA:program}(?:[%{POSINT:pid}])?: %{GREEDYDATA:smt}: %{GREEDYDATA:smt2} for user %{USER:user}" ]  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
date {  
match =\> ["date", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}  
I tried it with the input: "Aug 6 12:17:01 stack CRON[14336]: pam\_unix(cron:session): session closed for user root" on [http://grokdebug.herokuapp.com/](http://grokdebug.herokuapp.com/) and it works fine.  
Is there any problem with my code ?  
Thank you,  
Manal

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 6, 2019, 2:55pm UTC](https://discuss.elastic.co/t/grokparsefailure-problem/194038/2 "2019-08-06T14:55:35Z")

</div>

Assuming you escape the square brackets

```
grok { match => ["message", "%{SYSLOGTIMESTAMP:date} %{SYSLOGHOST:host} %{DATA:program}(?:\[%{POSINT:pid}\])?: %{GREEDYDATA:smt}: %{GREEDYDATA:smt2} for user %{USER:user}" ] }

```

that works for me

```
   "message" => "Aug 6 12:17:01 stack CRON[14336]: pam_unix(cron:session): session closed for user root",
   "program" => "CRON",
      "host" => [
    [0] "myHost",
    [1] "stack"
],
       "pid" => "14336",
       "smt" => "pam_unix(cron:session)",
      "smt2" => "session closed",
      "user" => "root",
      "date" => "Aug 6 12:17:01"
```

---

<div class="post-metadata">

**Author:** ![Manal\_Sadgal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/manal_sadgal/32/51763_2.png) [@Manal\_Sadgal](https://discuss.elastic.co/u/Manal_Sadgal)\
**Post date:** [August 7, 2019, 7:42am UTC](https://discuss.elastic.co/t/grokparsefailure-problem/194038/3 "2019-08-07T07:42:22Z")

</div>

A space was missing , that's why it wasn't working. I fixed it. Thank you !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 4, 2019, 7:42am UTC](https://discuss.elastic.co/t/grokparsefailure-problem/194038/4 "2019-09-04T07:42:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
