# Learning Grok

**URL:** <https://discuss.elastic.co/t/learning-grok/134773>\
**Category:** Logstash\
**Created:** [June 6, 2018, 9:39am UTC](https://discuss.elastic.co/t/learning-grok/134773 "2018-06-06T09:39:50Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jukocross](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jukocross/32/31988_2.png) [@Jukocross](https://discuss.elastic.co/u/Jukocross)\
**Post date:** [June 6, 2018, 9:39am UTC](https://discuss.elastic.co/t/learning-grok/134773/1 "2018-06-06T09:39:50Z")

</div>

Hi, i'm learning grok and trying out to craft my own filter.  
Below is the example which i have tried using [https://grokdebug.herokuapp.com](https://grokdebug.herokuapp.com) to debug.  
However, i still received grokparsefailure when output to elasticsearch

Original Log:  
"\<44\>Original Address=192.168.218.133 This is a test message generated by Kiwi SyslogGen"

Following grok filter:

```
filter {
 grok {
   match => { "message" => "%{SYSLOG5424PRI}%{GREEDYDATA:msgtype}=%{IP:source} %{GREEDYDATA:msg}"}
   add_tag => ["Kiwi_Gen_Tag"]
 }
}
```

---

<div class="post-metadata">

**Author:** ![Krunal\_kalaria](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krunal_kalaria/32/23862_2.png) [@Krunal\_kalaria](https://discuss.elastic.co/u/Krunal_kalaria)\
**Post date:** [June 6, 2018, 10:17am UTC](https://discuss.elastic.co/t/learning-grok/134773/2 "2018-06-06T10:17:49Z")

</div>

Hey @Jukocross,

Can you just add one more space in last braces following is your grok  
match =\> { "message" =\> "%{SYSLOG5424PRI}%{GREEDYDATA:msgtype}=%{IP:source} %{GREEDYDATA:msg}"}

Now in end of the line this sentence is their %{GREEDYDATA:msg}"} so put the space in last like %{GREEDYDATA:msg}" }

So your full grok look like,

**match =\> { "message" =\> "%{SYSLOG5424PRI}%{GREEDYDATA:msgtype}=%{IP:source} %{GREEDYDATA:msg}" }**

Try this bold one it may be worked for you!

Thanks & Regards,  
Krunal.

---

<div class="post-metadata">

**Author:** ![Jukocross](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jukocross/32/31988_2.png) [@Jukocross](https://discuss.elastic.co/u/Jukocross)\
**Post date:** [June 7, 2018, 3:34am UTC](https://discuss.elastic.co/t/learning-grok/134773/3 "2018-06-07T03:34:14Z")

</div>

Hi, Thanks for the advise, I have edit accordingly but the error still occur. Is there any method to debug such error?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 7, 2018, 8:37am UTC](https://discuss.elastic.co/t/learning-grok/134773/4 "2018-06-07T08:37:50Z")

</div>

Have a look at [this blog post](https://www.elastic.co/blog/a-practical-introduction-to-logstash), which shows how to work with Logstash when developing config. [This blog post on writing efficient grok config](https://www.elastic.co/blog/do-you-grok-grok) is also very useful.

---

<div class="post-metadata">

**Author:** ![verboese](https://avatars.discourse-cdn.com/v4/letter/v/3be4f8/32.png) [@verboese](https://discuss.elastic.co/u/verboese)\
**Post date:** [June 7, 2018, 9:32am UTC](https://discuss.elastic.co/t/learning-grok/134773/5 "2018-06-07T09:32:09Z")

</div>

Hi.  
I don't think "SYSLOG5424PRI" is known by logstash (at least not with my 5.6). Try to define a pattern file with definition of SYSLOG5424PRI ...

---

<div class="post-metadata">

**Author:** ![Jukocross](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jukocross/32/31988_2.png) [@Jukocross](https://discuss.elastic.co/u/Jukocross)\
**Post date:** [June 8, 2018, 2:49am UTC](https://discuss.elastic.co/t/learning-grok/134773/6 "2018-06-08T02:49:35Z")

</div>

Hi, i have remove "SYSLOG5424PRI" but the kiwi gen is generating new format of logs hence i have make some changes below. However, i still faced with the error and hope could get some advise on it.

Log: "\<44\> Jun 8 10:36:42 TestClient-PC SyslogGen This is a test message generated by Kiwi SyslogGen"

```
filter {
 grok {
   match => { "<%{NUMBER:priority}>%{CISCOTIMESTAMP:logtime} %{WORD:hostname}-%{WORD:device} %{WORD:origin} %{GREEDYDATA:msg}" }
   add_tag => ["Kiwi_Gen_Tag"]
   tag_on_failure => []
 }
 mutate { ... }
 translate { ... }
}
```

Even with tag\_on\_failure, i still have the \_grokparsefailure tag. However, all the field have translated as i wanted.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2018, 2:49am UTC](https://discuss.elastic.co/t/learning-grok/134773/7 "2018-07-06T02:49:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
