# Ingest pipeline error - ailed to parse with all enclosed parsers

**URL:** https://discuss.elastic.co/t/ingest-pipeline-error-ailed-to-parse-with-all-enclosed-parsers/263809
**Category:** Elasticsearch
**Tags:** ingest-pipeline
**Created:** [February 9, 2021, 9:30pm UTC](https://discuss.elastic.co/t/ingest-pipeline-error-ailed-to-parse-with-all-enclosed-parsers/263809 "2021-02-09T21:30:29Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![Glenn\_Glashagen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glenn_glashagen/32/78407_2.png) [@Glenn\_Glashagen](https://discuss.elastic.co/u/Glenn_Glashagen)
#### Post date: [February 9, 2021, 9:30pm UTC](https://discuss.elastic.co/t/ingest-pipeline-error-ailed-to-parse-with-all-enclosed-parsers/263809/1 "2021-02-09T21:30:29Z")

</div>

Hello everybody,

I'm recently encountering problem with my ingestion pipeline, where part of if tries to parse a date. If it fails to do so, it should continue and not create the fields `time_log` and `rest_message`.  
This works for any message that does not contain a date and the log is being parsed.  
However, for some datetime formats it crashes and does not event create an entry at all. E.g.  
`2021-01-12 13:39:28.620+0100` is being parsed and `2021-02-09 22:15:28` is not.  
The error message that I'm getting is:  
""type":"illegal\_argument\_exception","reason":"failed to parse date field [2021-02-09 22:15:28] with format [strict\_date\_optional\_time||epoch\_millis]","caused\_by":{"type":"date\_time\_parse\_exception","reason":"date\_time\_parse\_exception: Failed to parse with all enclosed parsers""

I thought that this case is just ignored, however is seems to parse the date but not to create the entry. How can I make sure that either:

1. the date is being parsed
2. the pipeline fails but does create a document  
?

This is the relevant part of my pipeline:  
{  
"grok": {  
"field": "message",  
"patterns": [  
"%{TIMESTAMP\_ISO8601:time\_log:data} %{GREEDYDATA:rest\_message}"  
],  
"ignore\_failure" : true  
}  
},

all the best,  
Glenn

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [February 10, 2021, 12:39am UTC](https://discuss.elastic.co/t/ingest-pipeline-error-ailed-to-parse-with-all-enclosed-parsers/263809/2 "2021-02-10T00:39:31Z")

</div>

Is there more to your pipeline, specifically a `date` processor?

---

<div class="post-metadata">

### Author: ![Glenn\_Glashagen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glenn_glashagen/32/78407_2.png) [@Glenn\_Glashagen](https://discuss.elastic.co/u/Glenn_Glashagen)
#### Post date: [February 10, 2021, 7:28am UTC](https://discuss.elastic.co/t/ingest-pipeline-error-ailed-to-parse-with-all-enclosed-parsers/263809/3 "2021-02-10T07:28:54Z")

</div>

Hey,

thanks a lot for your answer!  
yes, this is the entire pipeline (all the processors):

"processors": [  
{  
"set": {  
"field": "@timestamp",  
"value": "{{\_ingest.timestamp}}",  
"if": "!(ctx.containsKey('@timestamp'))",  
"on\_failure" : [  
{  
"set" : {  
"field" : "error.message",  
"value" : "field "foo" does not exist, cannot rename to "bar""  
}  
}  
]  
}  
},  
{  
"grok": {  
"field": "message",  
"patterns": [  
"%{TIMESTAMP\_ISO8601:time\_log:date} %{GREEDYDATA:rest\_message}"  
],  
"on\_failure": [  
{  
"set": {  
"field": "error.parsing",  
"value": "Could not parse timestamp of incoming message"  
}  
}  
]  
}  
},  
{  
"grok": {  
"field": "rest\_message",  
"patterns": [  
"[^{]\*RAM used:%{SPACE}%{NUMBER:stats.ram\_usage:float}",  
"Disk used:%{SPACE}%{NUMBER:stats.disk\_usage:float}%",  
"SWAP used:%{SPACE}%{NUMBER:stats.swap\_usage:float}%",  
"CPU usage:%{SPACE}%{NUMBER:stats.cpu\_usage:float}%",  
"GPU usage:%{SPACE}%{NUMBER:stats.gpu\_usage:float}%",  
"CPU temp:%{SPACE}%{NUMBER:stats.cpu\_temp:float}",  
"GPU temp:%{SPACE}%{NUMBER:stats.gpu\_temp:float}",  
"Board temp: %{NUMBER:stats.board\_temp:float}",  
"Case Temp: %{NUMBER:stats.case\_temp:float}",  
"Case Humidity: %{NUMBER:stats.case\_humidity:float}%",  
"Router Temperature: %{NUMBER:stats.router\_temp:float}°C",  
"Signal Strength: %{NUMBER:stats.signal:float}dB",  
"STATS: Video - %{NUMBER:fps.video:int} FPS; ANPR - %{NUMBER:fps.anpr:int} FPS; Vehicle Detection - %{NUMBER:fps.yolo:int} FPS",  
"DIRECTION: %{GREEDYDATA:detection.direction:string}",  
"ACCURACY: %{NUMBER:detection.accuracy:float}",  
"DETECTIONS: %{NUMBER:detection.number:integer}"  
],  
"on\_failure": [  
{  
"set": {  
"field": "warning.parsing",  
"value": "No matching pattern was found."  
}  
}  
]  
}  
},  
{  
"date": {  
"field": "time\_log",  
"target\_field": "time\_log",  
"formats": [  
"yyyy-MM-dd HH:mm:ss.SSSZ"  
],  
"on\_failure": [  
{  
"set": {  
"field": "error.parsing",  
"value": "Date could not be parsed"  
}  
}  
]  
}  
},  
{  
"remove": {  
"field": "rest\_message",

```
            "on_failure": [
                {
                    "set": {
                        "field": "error.parsing",
                        "value": "Date could not be parsed"
                    }
                }
            ]
        }
    }
]

```

all the best,  
Glenn

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [February 10, 2021, 7:53am UTC](https://discuss.elastic.co/t/ingest-pipeline-error-ailed-to-parse-with-all-enclosed-parsers/263809/4 "2021-02-10T07:53:58Z")

</div>

Thanks.  
It's better if you can format your code/logs/config using the `</>` button, or markdown style back ticks. It helps to make things easy to read which helps us help you 🙂

It looks like this is the issue;

> [@Glenn\_Glashagen](#):
>
> date": {  
> "field": "time\_log",  
> "target\_field": "time\_log",  
> "formats": [  
> "yyyy-MM-dd HH:mm:ss.SSSZ"  
> ],

As that does not match `2021-02-09 22:15:28`.  
You should add another pattern in the `formats` field that matches that, and you should be fine.

---

<div class="post-metadata">

### Author: ![Glenn\_Glashagen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/glenn_glashagen/32/78407_2.png) [@Glenn\_Glashagen](https://discuss.elastic.co/u/Glenn_Glashagen)
#### Post date: [February 10, 2021, 8:49am UTC](https://discuss.elastic.co/t/ingest-pipeline-error-ailed-to-parse-with-all-enclosed-parsers/263809/5 "2021-02-10T08:49:26Z")

</div>

thanks!  
I will try this as soon as possible. Apart from that: is there any way to catch the error or notify me?  
So let's say there will be another unsupported time format.  
I thought that the error would be caught by the `on_failure` section?

all the best,  
Glenn

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [February 10, 2021, 9:12pm UTC](https://discuss.elastic.co/t/ingest-pipeline-error-ailed-to-parse-with-all-enclosed-parsers/263809/6 "2021-02-10T21:12:04Z")

</div>

I'm not super familiar with that, but I would imagine if Elasticsearch cannot parse the timestamp then it can't do much else other than reject it.

You might be able to just dump the event into another error index though?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 10, 2021, 9:12pm UTC](https://discuss.elastic.co/t/ingest-pipeline-error-ailed-to-parse-with-all-enclosed-parsers/263809/7 "2021-03-10T21:12:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
