# Grokparsefailure with nginx logs

**URL:** <https://discuss.elastic.co/t/grokparsefailure-with-nginx-logs/230753>\
**Category:** Logstash\
**Created:** [May 1, 2020, 6:42pm UTC](https://discuss.elastic.co/t/grokparsefailure-with-nginx-logs/230753 "2020-05-01T18:42:48Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 2, 2020, 12:40am UTC](https://discuss.elastic.co/t/grokparsefailure-with-nginx-logs/230753/2 "2020-05-02T00:40:35Z")

</div>

> [@cloudbadmin](#):
>
> How can I go about troubleshooting which field is causing the problem?

My answer to that is [here](https://discuss.elastic.co/t/help-needed-in-grok/213827/2). Start with a pattern that matches the first field on a line, then add one field at a time.

---

_[View the full topic](https://discuss.elastic.co/t/grokparsefailure-with-nginx-logs/230753)._
