# Grokparsefailure

**URL:** <https://discuss.elastic.co/t/grokparsefailure/362450>\
**Category:** Logstash\
**Created:** [July 3, 2024, 11:04am UTC](https://discuss.elastic.co/t/grokparsefailure/362450 "2024-07-03T11:04:20Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [July 3, 2024, 11:04am UTC](https://discuss.elastic.co/t/grokparsefailure/362450/1 "2024-07-03T11:04:20Z")

</div>

Hi there,

i'm trying to use grok pattern here and as you can see my pattern is already match the log

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/2/c21afb104603f50839c1fc1e82ad5b6a56738f10.png)

but when I see in kibana, idk why the tags always show \_grokparsefailure

this is my code in pipeline

```auto
if [kubernetes][namespace] in ["ff-rr"]{
grok {
  match => ["message", "%{WORD:type}:\s+(?<data_customer>%{WORD}\s+%{WORD}):\s+%{GREEDYDATA:bodydata}"]
 }
json {
  source => "bodydata"
  skip_on_invalid_json => true
 }
}

```

what should I do? no character needs to escape in my grok pattern

Thanks

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 3, 2024, 11:44am UTC](https://discuss.elastic.co/t/grokparsefailure/362450/2 "2024-07-03T11:44:37Z")

</div>

> [@yuswanul](#):
>
> what should I do?

Please share the result message you are getting in Kibana.

Go to discover, find a document where you have this tag, expand it, then go to the json tab and copy the content.

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [July 3, 2024, 11:55am UTC](https://discuss.elastic.co/t/grokparsefailure/362450/3 "2024-07-03T11:55:53Z")

</div>

here is the value:

```auto
"message": "Response: LINK CUSTOMER: {\"responseCode\":\"xx\",\"responseDesc\":\"Blokir \\/ Tidak \",\"data\":null}",

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 3, 2024, 12:05pm UTC](https://discuss.elastic.co/t/grokparsefailure/362450/4 "2024-07-03T12:05:23Z")

</div>

You need to share the entire document you have in Elasticsearch.

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [July 3, 2024, 12:08pm UTC](https://discuss.elastic.co/t/grokparsefailure/362450/5 "2024-07-03T12:08:10Z")

</div>

it's a production data. i need to take some time to masking it or if you can tell me what part you exactly want to see

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 3, 2024, 12:20pm UTC](https://discuss.elastic.co/t/grokparsefailure/362450/6 "2024-07-03T12:20:48Z")

</div>

Share the kubernetes fields, also share your entire logstash pipeline.

It is pretty hard to troubleshoot things without more context like the entire pipeline and what is the real output.

From what you share I see no issue in the grok filter you are using, it worked for me, so it may have something wrong with your pipeline, or maybe it is not matching the conditional you are using.

What is the source of data?

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [July 3, 2024, 12:26pm UTC](https://discuss.elastic.co/t/grokparsefailure/362450/7 "2024-07-03T12:26:26Z")

</div>

idk why is this happen. when i change this line  
from:

```auto
if [kubernetes][namespace] in ["ff-rr"]{

```

to:

```auto
if [kubernetes][namespace] == "ff-rr" {

```

it looks work. i tested it before on my local environment using first line, it works well. but when i apply it in production, it's not working. is there any difference between them?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 3, 2024, 12:35pm UTC](https://discuss.elastic.co/t/grokparsefailure/362450/8 "2024-07-03T12:35:35Z")

</div>

> [@yuswanul](#):
>
> is there any difference between them?

Yes, you cannot use _in_ to test membership of an array with one member. It is parsed as a field reference, so logstash is testing the (non-existent) field ["ff-rr"] and the expression evaluates to false. It's very hard to fix this. It is tracked [here](https://github.com/elastic/logstash/issues/9932).

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [July 4, 2024, 5:59am UTC](https://discuss.elastic.co/t/grokparsefailure/362450/9 "2024-07-04T05:59:35Z")

</div>

ok, thanks for the info. i'll remember that
