# \_grokparsefailure

**URL:** <https://discuss.elastic.co/t/grokparsefailure/273447>\
**Category:** Logstash\
**Created:** [May 19, 2021, 9:11pm UTC](https://discuss.elastic.co/t/grokparsefailure/273447 "2021-05-19T21:11:47Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![legolas\_bilbao](https://avatars.discourse-cdn.com/v4/letter/l/3da27b/32.png) [@legolas\_bilbao](https://discuss.elastic.co/u/legolas_bilbao)\
**Post date:** [May 19, 2021, 9:11pm UTC](https://discuss.elastic.co/t/grokparsefailure/273447/1 "2021-05-19T21:11:47Z")

</div>

Good night,

I've use the dev tools for deploy the grook rule for squid logs

The config file is the following

> > input {  
> > file {  
> > path =\> "/var/elastik/access.log"  
> > start\_position =\> "beginning"  
> > }
> > 
> > }  
> > filter {  
> > grok {
> > 
> > ```
> > match => ["message","%{NUMBER:timestamp}%{SPACE}%{NUMBER:duration}\s%{IP:client_address}\s%{WORD:cache_result}/%{POSINT:status_code}\s%{NUMBER:bytes}\s%{WORD:request_method}\s%{NOTSPACE:url}\s%{NOTSPACE:user}\s%{WORD:hierarchy_code}/%{NOTSPACE:server}\s%{NOTSPACE:content_type}"]
> > }
> > date {
> > match => ["timestamp", "UNIX"]
> > remove_field => ["timestamp"]
> > }
> > 
> > }
> > 
> > ```
> > 
> > output {  
> > elasticsearch {  
> > "hosts" =\> "localhost:9200"  
> > "index" =\> "squid"  
> > }  
> > stdout { codec =\> json\_lines }  
> > }

The input in the grok dev tool

1616454089.572 259 172.25.157.81 TCP\_TUNNEL/200 5630 CONNECT [api-eu1.xbc.trendmicro.com:443](http://api-eu1.xbc.trendmicro.com:443) - HIER\_DIRECT/18.156.104.89 -

And the result is the following  
{  
"server": "18.156.104.89",  
"status\_code": "200",  
"hierarchy\_code": "HIER\_DIRECT",  
"request\_method": "CONNECT",  
"url": "[api-eu1.xbc.trendmicro.com:443](http://api-eu1.xbc.trendmicro.com:443)",  
"duration": "259",  
"content\_type": "-",  
"bytes": "5630",  
"cache\_result": "TCP\_TUNNEL",  
"client\_address": "172.25.157.81",  
"user": "-",  
"timestamp": "1616454089.572"  
}

in the deploy into the kibana appears the following error, any idea?

tags \_grokparsefailure and the fiels defined in the index are incorrect

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 16, 2021, 9:11pm UTC](https://discuss.elastic.co/t/grokparsefailure/273447/2 "2021-06-16T21:11:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
