# How Can I parse why I got the error tag : \_grokparsefailure

**URL:** <https://discuss.elastic.co/t/how-can-i-parse-why-i-got-the-error-tag--grokparsefailure/29610>\
**Category:** Logstash\
**Created:** [September 19, 2015, 12:03am UTC](https://discuss.elastic.co/t/how-can-i-parse-why-i-got-the-error-tag--grokparsefailure/29610 "2015-09-19T00:03:48Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jianfeng\_ye](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jianfeng_ye/32/4753_2.png) [@jianfeng\_ye](https://discuss.elastic.co/u/jianfeng_ye)\
**Post date:** [September 19, 2015, 12:03am UTC](https://discuss.elastic.co/t/how-can-i-parse-why-i-got-the-error-tag--grokparsefailure/29610/1 "2015-09-19T00:03:48Z")

</div>

I know that my be my grok error, but when I try my grok in this website:

```
http://grokconstructor.appspot.com/do/match#result

```

it return ok.

my grok pattern is:

```
%{WORD:http_host} %{URIHOST:api_domain} %{IP:inner_ip} %{IP:lvs_ip} \[%{HTTPDATE:timestamp}\] \"%{WORD:http_verb} %{URIPATH:baseurl}(?:\?%{NOTSPACE:request}|) HTTP/%{NUMBER:http_version}\" (?:-|%{NOTSPACE:request}) %{NUMBER:http_status_code} (?:%{NUMBER:bytes_read}|-) %{QS:referrer} %{QS:agent} %{NUMBER:time_duration:float} %{NUMBER:time_backend_response:float}

```

my error data is:

```
120_55_72_142 api.test.com 10.174.106.171 100.97.180.80 [18/Sep/2015:20:14:55 +0800] "GET /api1.4/message/getunreadcount/?channel=aisi&source=ios&token=6b69d5869c41fa7176835a81f2cc0927&uid=892473 HTTP/1.0" - 499 0 "-" "autoguru/com.baichebao.carmaste (2; OS Version 9.0 (Build 13A344))" 0.062 -

```

I really want to know where my pattern error and Is there any setting that can show more detail error for debug that?

Help~ Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 19, 2015, 8:26pm UTC](https://discuss.elastic.co/t/how-can-i-parse-why-i-got-the-error-tag--grokparsefailure/29610/2 "2015-09-19T20:26:41Z")

</div>

For starters, the input string ends with "0.062 -" and you're trying to use two NUMBER patterns to match it. I suggest you follow the example of the `bytes_read` field and use `(?:%{NUMBER:time_backend_response:float}|-)` instead.

---

<div class="post-metadata">

**Author:** ![Allen704](https://avatars.discourse-cdn.com/v4/letter/a/919ad9/32.png) [@Allen704](https://discuss.elastic.co/u/Allen704)\
**Post date:** [May 2, 2016, 1:49pm UTC](https://discuss.elastic.co/t/how-can-i-parse-why-i-got-the-error-tag--grokparsefailure/29610/3 "2016-05-02T13:49:49Z")

</div>

Is there an answer to the actual question though? Is there a way to get more detail on where the error is occuring?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 3, 2016, 11:07am UTC](https://discuss.elastic.co/t/how-can-i-parse-why-i-got-the-error-tag--grokparsefailure/29610/4 "2016-05-03T11:07:25Z")

</div>

> Is there an answer to the actual question though? Is there a way to get more detail on where the error is occuring?

I think the best you can do is truncating your grok expression to the bare minimum and then keep extending it until things stop working.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:59am UTC](https://discuss.elastic.co/t/how-can-i-parse-why-i-got-the-error-tag--grokparsefailure/29610/5 "2017-07-06T04:59:35Z")

</div>


