# Is there a way to get a more verbose response than just "\_grokparsefailure"

**URL:** <https://discuss.elastic.co/t/is-there-a-way-to-get-a-more-verbose-response-than-just--grokparsefailure/98915>\
**Category:** Logstash\
**Created:** [August 30, 2017, 11:53pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-get-a-more-verbose-response-than-just--grokparsefailure/98915 "2017-08-30T23:53:38Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![cchooks2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cchooks2/32/21987_2.png) [@cchooks2](https://discuss.elastic.co/u/cchooks2)\
**Post date:** [August 30, 2017, 11:53pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-get-a-more-verbose-response-than-just--grokparsefailure/98915/1 "2017-08-30T23:53:38Z")

</div>

Hello,

I have been using grok filtering for a couple months now and have noticed the pain point of the very vague grok parse failure tag. I am wondering if there is a way for that to give a little bit more detail on where exactly did it fail.

I found this doc : [https://www.elastic.co/blog/do-you-grok-grok](https://www.elastic.co/blog/do-you-grok-grok) that was very helpful as it had a very similar log as to the one I am trying to parse out. I have never used the HTTPDATE grok, before or others that are mentioned in the link. I usually create regexes for the data, but have found that Logstash sometimes doesn't like those. I felt pretty confident since it is using all GROK in house patterns, but no luck.

I am trying to parse out this event:

Event:  
10.100.200.00 - - [30/Aug/2017:15:31:19 -0400] "GET /some/path/some/path HTTP/1.1" 200 3093 0 9 "[https://someurl/some/path/some/log](https://someurl/some/path/some/log)" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.101 Safari/537.36" "image/png" 2CE9B72CBD4D03C457A2893EF60128F6 10.100.200.200 11132

My Grok Pattern:  
^%{IP:client\_ip}%{SPACE}%{USER:client\_port}%{SPACE}%{USER:ident}%{SPACE}[%{HTTPDATE:event\_ts}]%{SPACE}"%{WORD:method}%{SPACE}%{DATA:uri\_path}%{SPACE}HTTP/%{NUMBER:http\_version}"%{SPACE}%{NUMBER:status}%{SPACE}(?:-|%{NUMBER:bytes})%{SPACE}%{NUMBER:request\_time\_in\_secs}%{SPACE}%{NUMBER:keep\_alives}%{SPACE}"%{GREEDYDATA:referer}"%{SPACE}"%{GREEDYDATA:user\_agent}"%{SPACE}"%{GREEDYDATA:contenttype}"%{SPACE}%{DATA:jsession\_id}%{SPACE}%{IP:x\_clientip}%{SPACE}%{NUMBER:response\_time\_in\_secs}$

stdout put on a test:  
"referer" =\> "[https://someurl/docs/DOC-00000](https://someurl/docs/DOC-00000)",  
"method" =\> "POST",  
"response\_time\_in\_secs" =\> "97849",  
"ident" =\> "-",  
"http\_version" =\> "1.1",  
"message" =\> "10.100.200.00 - - [30/Aug/2017:16:20:47 -0400] "POST /some/path/here HTTP/1.1" 200 109 0 0 "[https://someurl/docs/DOC-00000](https://someurl/docs/DOC-00000)" "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko" "application/json" 2CE9B72CBD4D03C457A2893EF60128F6 10.100.200.200 97849",  
"keep\_alives" =\> "0",  
"x\_clientip" =\> "10.100.200.200",  
"contenttype" =\> "application/json",  
"path" =\> "/apps/logstash-5.5.0/bin/test.txt",  
"client\_port" =\> "-",  
"jsession\_id" =\> "3F966A293216B6A0315DF0D1FFCE7AEB",  
"@timestamp" =\> 2017-08-30T20:20:47.000Z,  
"uri\_path" =\> "some/path/here",  
"bytes" =\> "109",  
"event\_ts" =\> "30/Aug/2017:16:20:47 -0400",  
"@version" =\> "1",  
"host" =\> "myserver",  
"request\_time\_in\_secs" =\> "0",  
"client\_ip" =\> "10.100.200.200",  
"user\_agent" =\> "Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko",  
"status" =\> "200"

My config:  
else if ([service] == "myservice"){  
if([attributes][file\_path] == "some/path/access.log") {  
grok {  
patterns\_dir =\> ["/apps/logstash-patterns"]  
match =\> ["body", "%{Access}"]  
}  
date {  
match =\> ["event\_ts" ,"dd/MMM/yyyy:HH:mm:ss Z"]  
target =\> "@timestamp"  
timezone =\> "America/New\_York"  
}  
}

Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 31, 2017, 5:16am UTC](https://discuss.elastic.co/t/is-there-a-way-to-get-a-more-verbose-response-than-just--grokparsefailure/98915/2 "2017-08-31T05:16:36Z")

</div>

> I am wondering if there is a way for that to give a little bit more detail on where exactly did it fail.

No, there isn't.

> stdout put on a test:

So... what's the problem? If that's what you get things seem to be working.

---

<div class="post-metadata">

**Author:** ![cchooks2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cchooks2/32/21987_2.png) [@cchooks2](https://discuss.elastic.co/u/cchooks2)\
**Post date:** [August 31, 2017, 3:42pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-get-a-more-verbose-response-than-just--grokparsefailure/98915/3 "2017-08-31T15:42:38Z")

</div>

> [@magnusbaeck](#):
>
> So… what’s the problem? If that’s what you get things seem to be working.

That's what i thought as well, but I am still getting a \_grokparsefailure. Data parses out perfectly in the grok debugger, but not in my environment. We have it going from Rocana -\> Kafka -\> Logstash -\> Elastic -\> Kibana.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 31, 2017, 4:37pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-get-a-more-verbose-response-than-just--grokparsefailure/98915/4 "2017-08-31T16:37:57Z")

</div>

What do you mean by "stdout put on a test"? It looks like output from Logstash.

---

<div class="post-metadata">

**Author:** ![cchooks2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cchooks2/32/21987_2.png) [@cchooks2](https://discuss.elastic.co/u/cchooks2)\
**Post date:** [August 31, 2017, 4:41pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-get-a-more-verbose-response-than-just--grokparsefailure/98915/5 "2017-08-31T16:41:57Z")

</div>

> [@magnusbaeck](#):
>
> What do you mean by “stdout put on a test”? It looks like output from Logstash.

I created a test.conf on one of my logstash servers and had it read from a test.txt that contained the events I am trying to parse out. Just to test out that my grok pattern is actually working. Here in the stdout is shows that it is parsing out correctly which was what i pasted up top.

test.conf:

input {  
file {  
path =\> "/apps/logstash-5.5.0/bin/test.txt"  
start\_position =\> "beginning"

```
}

```

}

filter {  
grok {  
patterns\_dir =\> ["/apps/grok-patterns"]  
match =\> ["message", "^%{IP:client\_ip}%{SPACE}%{USER:client\_port}%{SPACE}%{USER:ident}%{SPACE}[%{HTTPDATE:event\_ts}]%{SPACE}"%{WORD:method}%{SPACE}%{DATA:uri\_path}%{SPACE}HTTP/%{NUMBER:http\_version}"%{SPACE}%{NUMBER:status}%{SPACE}(?:-|%{NUMBER:bytes})%{SPACE}%{NUMBER:request\_time\_in\_secs}%{SPACE}%{NUMBER:keep\_alives}%{SPACE}"%{GREEDYDATA:referer}"%{SPACE}"%{GREEDYDATA:user\_agent}"%{SPACE}"%{GREEDYDATA:contenttype}"%{SPACE}%{DATA:jsession\_id}%{SPACE}%{IP:x\_clientip}%{SPACE}%{NUMBER:response\_time\_in\_secs}$" ]  
}  
#kv {  
# source =\> "kvpairs"  
# field\_split =\> ", "  
# value\_split =\> " = "  
# remove\_field =\> ["kvpairs"]  
#}  
date {  
match =\> ["event\_ts" ,"dd/MMM/yyyy:HH:mm:ss Z"]  
target =\> "@timestamp"  
timezone =\> "America/New\_York"  
}  
}

output {  
stdout {  
codec =\> rubydebug {}  
}  
}

---

<div class="post-metadata">

**Author:** ![cchooks2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cchooks2/32/21987_2.png) [@cchooks2](https://discuss.elastic.co/u/cchooks2)\
**Post date:** [August 31, 2017, 6:09pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-get-a-more-verbose-response-than-just--grokparsefailure/98915/6 "2017-08-31T18:09:24Z")

</div>

> [@cchooks2](#):
>
> Rocana -\> Kafka -\> Logstash -\> Elastic -\> Kibana.

I don't know if this will help to narrow down where the grok failure is taking place...

I added a mutate field to add a new filed ... that actually came through into kibana, but I am still seeing the grokparsefailure....

any thoughts?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 28, 2017, 6:09pm UTC](https://discuss.elastic.co/t/is-there-a-way-to-get-a-more-verbose-response-than-just--grokparsefailure/98915/7 "2017-09-28T18:09:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
