# \_grokparsefailure shows always

**URL:** <https://discuss.elastic.co/t/grokparsefailure-shows-always/121014>\
**Category:** Logstash\
**Created:** [February 22, 2018, 9:05am UTC](https://discuss.elastic.co/t/grokparsefailure-shows-always/121014 "2018-02-22T09:05:12Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![chianingwang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chianingwang/32/28037_2.png) [@chianingwang](https://discuss.elastic.co/u/chianingwang)\
**Post date:** [February 22, 2018, 9:05am UTC](https://discuss.elastic.co/t/grokparsefailure-shows-always/121014/1 "2018-02-22T09:05:12Z")

</div>

Hi I got the input string as below

```
" Object update sweep completed on /srv/node/d3 in 0.00s seconds:, 0 successes, 0 failures, 0 quarantines, 0 unlinks, 0 errors (pid: 26739)"

```

And my grok pattern is as below.

grok {  
match =\> { "message" =\> " Object update sweep completed on %{URIPATHPARAM:UpdSweepPath} in %{NUMBER:UpdSPRunTime:float}s seconds:, %{BASE10NUM:UpdSPNumOfSuc} successes, %{BASE10NUM:UpdSPNumOfFail} failures, %{BASE10NUM:UpdSPNumOfQuaranties} quarantines, %{BASE10NUM:UpdSPNumOfUnlink} unlinks, %{BASE10NUM:UpdSPNumOfErr} errors (pid: %{WORD:UpdSPPID})" }  
remove\_tag =\> ["\_grokparsefailure"]  
add\_tag =\> ["OBJ\_UPD\_SWEEPPARTITON\_COMPLETE"]  
}

Why I get \_grokparsefailure always ?  
"tags": [  
"OBJ\_UPD\_SWEEPPARTITON\_COMPLETE",  
"\_grokparsefailure"  
],

I got other similar grok pattern but those doesn't have \_grokparsefailure .

Thanks,  
Johnny

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 22, 2018, 9:06am UTC](https://discuss.elastic.co/t/grokparsefailure-shows-always/121014/2 "2018-02-22T09:06:36Z")

</div>

Any other grok filter in your configuration? Perhaps in another file in /etc/logstash/conf.d or wherever you keep your configuration files?

---

<div class="post-metadata">

**Author:** ![stevesimpson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stevesimpson/32/41437_2.png) [@stevesimpson](https://discuss.elastic.co/u/stevesimpson)\
**Post date:** [February 22, 2018, 10:08am UTC](https://discuss.elastic.co/t/grokparsefailure-shows-always/121014/3 "2018-02-22T10:08:47Z")

</div>

I think you might need to escape your brackets in the match.

```
grok {
match => { "message" => " Object update sweep completed on %{URIPATHPARAM:UpdSweepPath} in %{NUMBER:UpdSPRunTime:float}s seconds:, %{BASE10NUM:UpdSPNumOfSuc} successes, %{BASE10NUM:UpdSPNumOfFail} failures, %{BASE10NUM:UpdSPNumOfQuaranties} quarantines, %{BASE10NUM:UpdSPNumOfUnlink} unlinks, %{BASE10NUM:UpdSPNumOfErr} errors \(pid: %{WORD:UpdSPPID}\)" }
remove_tag => ["_grokparsefailure"]
add_tag => ["OBJ_UPD_SWEEPPARTITON_COMPLETE"]
}

```

specifically `errors \(pid: %{WORD:UpdSPPID}\)"`

---

<div class="post-metadata">

**Author:** ![chianingwang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chianingwang/32/28037_2.png) [@chianingwang](https://discuss.elastic.co/u/chianingwang)\
**Post date:** [February 22, 2018, 3:51pm UTC](https://discuss.elastic.co/t/grokparsefailure-shows-always/121014/4 "2018-02-22T15:51:13Z")

</div>

@magnusbaeck , Thanks ! You are totally correct, I rename original filter with \*.orig as backup. After I move to another folder the `_grokparsefailure` gone.

---

<div class="post-metadata">

**Author:** ![chianingwang](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/chianingwang/32/28037_2.png) [@chianingwang](https://discuss.elastic.co/u/chianingwang)\
**Post date:** [February 22, 2018, 3:55pm UTC](https://discuss.elastic.co/t/grokparsefailure-shows-always/121014/5 "2018-02-22T15:55:50Z")

</div>

@stevesimpson, Thanks for your info, I did escape `\( ... \)` in my filter but looks like `\` escape in message text if I am not use `Preformatted text`.

e.g w/o `preformatted text`  
(pid: %{WORD:UpdSPPID})

e.g w/ `preformatted text`  
`\(pid: %{WORD:UpdSPPID}\)`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2018, 3:56pm UTC](https://discuss.elastic.co/t/grokparsefailure-shows-always/121014/6 "2018-03-22T15:56:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
