# Kibana can't parse the logs in discover tab

**URL:** <https://discuss.elastic.co/t/kibana-cant-parse-the-logs-in-discover-tab/126565>\
**Category:** Logstash\
**Created:** [April 3, 2018, 12:18pm UTC](https://discuss.elastic.co/t/kibana-cant-parse-the-logs-in-discover-tab/126565 "2018-04-03T12:18:13Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![keremcan](https://avatars.discourse-cdn.com/v4/letter/k/97f17d/32.png) [@keremcan](https://discuss.elastic.co/u/keremcan)\
**Post date:** [April 3, 2018, 12:18pm UTC](https://discuss.elastic.co/t/kibana-cant-parse-the-logs-in-discover-tab/126565/1 "2018-04-03T12:18:14Z")

</div>

Hey! I'm working on nginx logs analysing with ELK stack. I'm using filebeat\>logstash\>elasticsearch\>kibana in order.

this is my custom pattern

`NGINX %{DATA:ipadress} %{DATA:ident} %{DATA:auth} \[%{HTTPDATE:timestamp}\] \"(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|-)\" %{NUMBER:response_code} %{NUMBER:bytes:int} %{NUMBER:request_time:float} %{NUMBER:upstream_response_time:float} %{NOTSPACE:referer} %{QS:agent} %{DATA:zipcode}`

```
input {
        beats{
        port => "5044"
        }
}
filter {
    grok {
        match => { "message" => "%{NGINX}" }
    }
    date {
        match => ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]
    }
    useragent {
        source => "agent"
        target => "user_agent"
  }
}
output {
    elasticsearch {
        hosts => ["localhost:9200"]
        index => "accesslog"
        document_type => "logs"
    }
}

```

everything is working fine but parsing the logs. this is [my discover tab](http://prntscr.com/j07up6) , no parsing just message.

but when i go to my dev tab and GET myindexname/\_search

```
"hits": {
    "total": 1800375,
    "max_score": 1,
    "hits": [
      {
        "_index": "myindexname",
        "_type": "logs",
        "_id": "dIG0imIBIdydw1SjW1tG",
        "_score": 1,
        "_source": {
          "offset": 833276,
          "prospector": {
            "type": "log"
          },
          "@timestamp": "2017-08-08T04:29:43.000Z",
          "bytes": 804,
          "host": "tez-elastic",
          "timestamp": "08/Aug/2017:07:29:43 +0300",
          "source": "/access.log.195-enc",
          "agent": """"/4.1.2 CFNetwork/811.5.4 Darwin/16.7.0"""",
          "beat": {
            "hostname": "tez-elastic",
            "name": "tez-elastic",
            "version": "6.2.3"
          },
          "ipadress": "84e959425aeceef330c1d18c5647ecd6",
          "@version": "1",
          "message": """84e959425aeceef330c1d18c5647ecd6 - - [08/Aug/2017:07:29:43 +0300] "GET /some/path HTTP/1.1" 200 804 0.079 0.079 ."-" "/4.1.2 CFNetwork/811.5.4 Darwin/16.7.0" "-"""",
          "request": "/some/path",
          "upstream_response_time": 0.079,
          "response_code": "200",
          "tags": [
            "beats_input_codec_plain_applied"
          ],
          "user_agent": {
            "device": "iOS-Device",
            "os_name": "iOS",
            "major": "811",
            "build": "",
            "minor": "5",
            "name": "CFNetwork",
            "os": "iOS",
            "patch": "4"
          },
          "ident": "-",
          "verb": "GET",
          "httpversion": "1.1",
          "request_time": 0.079,
          "auth": "-",
          "referer": """."-""""
        }
      }

```

I can see the elasticsearch parsing my logs. and the most funny thing is that i can visualise logs with parameters in Kibana. What do you think about my problem? Thanks in advance!

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [April 10, 2018, 12:26am UTC](https://discuss.elastic.co/t/kibana-cant-parse-the-logs-in-discover-tab/126565/2 "2018-04-10T00:26:05Z")

</div>

In the pasted screenshot, the document includes the `_grokparsefailure` tag, which indicates that grok parsing failed.

I hand-copied the text from the screenshot:

```auto
cc08d0e73 - - [26/May/2017:08:50:29 +0300] "GET /assets/img/icons/iosStore.png HTTP/1.1" 200 476 0.000 - ."REDACTED" Mozilla/5.0 (Windows NT 6.1; rv:51.0) Gecko/20100101 Firefox/51.0" "-"

```

And used the [Grok Constructor](http://grokconstructor.appspot.com/do/match#result) to determine where the pattern failed; since the constructor can't break into named patterns, I pasted your _definition_`of`NGINX` as the pattern to match against.

I got:

```auto
NOT MATCHED. The longest regex prefix matching the beginning of this line is as follows:

prefix: %{NOTSPACE:ipadress} %{DATA:ident} %{DATA:auth} \[%{HTTPDATE:timestamp}\] \"(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|-)\" %{NUMBER:response_code} %{NUMBER:bytes:int} %{NUMBER:request_time:float}
after match: - ."REDACTED" Mozilla/5.0 (Windows NT 6.1; rv:51.0) Gecko/20100101 Firefox/51.0" "-"

```

where your pattern expected to encounter a `NUMBER`, it instead got a literal hyphen (`-`).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 8, 2018, 12:26am UTC](https://discuss.elastic.co/t/kibana-cant-parse-the-logs-in-discover-tab/126565/3 "2018-05-08T00:26:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
