# Logstash \_grokparsefailure error

**URL:** <https://discuss.elastic.co/t/logstash--grokparsefailure-error/89989>\
**Category:** Logstash\
**Created:** [June 19, 2017, 8:31pm UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-error/89989 "2017-06-19T20:31:02Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![sslv](https://avatars.discourse-cdn.com/v4/letter/s/c2a13f/32.png) [@sslv](https://discuss.elastic.co/u/sslv)\
**Post date:** [June 19, 2017, 8:31pm UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-error/89989/1 "2017-06-19T20:31:03Z")

</div>

Hi,  
I am trying to parse a simple log file to understand how logstash works.

This is my log format:  
2017-06-14 11:17:48 [ad8880] INFO: blah blah blah

And I have built the following grok regex using grok Constructor  
%{TIMESTAMP\_ISO8601:logsimestamp}%{SPACE}[%{WORD:threadID}]%{SPACE}%{LOGLEVEL:loglevel}:%{SPACE}%{GREEDYDATA:task}

But still I am getting \_grokparsefailure as below:  
"message":"2017-06-14 11:17:48 [ad8880] INFO: blah blah blah\r","tags":["\_grokparsefailure"]}

I tried changing the date format to :  
%{YEAR}-%{MONTHNUM}-%{MONTHDAY}%{SPACE}%{TIME}

but still no luck.

here is my config file:

input {  
file {  
path =\> "xxxxxx.txt"  
start\_position =\> "beginning"  
}  
}

filter {  
grok {  
match =\> { "Message" =\> "%{TIMESTAMP\_ISO8601:logsimestamp}%{SPACE}[%{WORD:threadID}]%{SPACE}%{LOGLEVEL:loglevel}:%{SPACE}%{GREEDYDATA:task}"}  
}  
}  
output {  
file{  
path =\> "xxx.txt"  
}  
}

---

<div class="post-metadata">

**Author:** ![pts0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pts0/32/17811_2.png) [@pts0](https://discuss.elastic.co/u/pts0)\
**Post date:** [June 19, 2017, 8:48pm UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-error/89989/2 "2017-06-19T20:48:17Z")

</div>

Hi,

when i just look at

`match => { "Message" => "%{TIMESTAMP_ISO8601:logsimestamp}%{SPACE}[%{WORD:threadID}]%{SPACE}%{LOGLEVEL:loglevel}:%{SPACE}%{GREEDYDATA:task}"}`

i think something is not good.

Try to escape `[` `]` with `\[,` and `\]` you probably get more luch 🙂

---

<div class="post-metadata">

**Author:** ![sslv](https://avatars.discourse-cdn.com/v4/letter/s/c2a13f/32.png) [@sslv](https://discuss.elastic.co/u/sslv)\
**Post date:** [June 19, 2017, 8:58pm UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-error/89989/3 "2017-06-19T20:58:32Z")

</div>

Hey! Thanks for the reply! Still no luck! there are characters like "" and " ' " in my [GREEDYDATA.IS](http://GREEDYDATA.IS) that a problem?

---

<div class="post-metadata">

**Author:** ![sslv](https://avatars.discourse-cdn.com/v4/letter/s/c2a13f/32.png) [@sslv](https://discuss.elastic.co/u/sslv)\
**Post date:** [June 19, 2017, 9:00pm UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-error/89989/4 "2017-06-19T21:00:26Z")

</div>

And also I am expecting output like  
logtimestamp: 2017-6-.....  
threadID:xyz  
loglevel:INFO

etc., will I see that after successfully parsing log without error? or I need to make some changes to config file?

---

<div class="post-metadata">

**Author:** ![pts0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pts0/32/17811_2.png) [@pts0](https://discuss.elastic.co/u/pts0)\
**Post date:** [June 19, 2017, 9:02pm UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-error/89989/5 "2017-06-19T21:02:35Z")

</div>

no, don't think so

try

[http://grokconstructor.appspot.com/do/construction](http://grokconstructor.appspot.com/do/construction)

or

[https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/)

are quite good place to get your custom pattern work.

---

<div class="post-metadata">

**Author:** ![sslv](https://avatars.discourse-cdn.com/v4/letter/s/c2a13f/32.png) [@sslv](https://discuss.elastic.co/u/sslv)\
**Post date:** [June 19, 2017, 9:14pm UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-error/89989/6 "2017-06-19T21:14:28Z")

</div>

I tried them.. thats how I got the [regex.Is](http://regex.Is) there something to do with \r?

---

<div class="post-metadata">

**Author:** ![pts0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pts0/32/17811_2.png) [@pts0](https://discuss.elastic.co/u/pts0)\
**Post date:** [June 19, 2017, 9:23pm UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-error/89989/7 "2017-06-19T21:23:54Z")

</div>

are u on windows or linux ?  
Windows uses `CRLF (\r\n, 0D 0A) l`ine endings while Unix just uses `LF (\n, 0A)`.  
just `\r` is nothing valid by default

If u get something special just set delimiter  
[https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-delimiter](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-delimiter)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 19, 2017, 9:25pm UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-error/89989/8 "2017-06-19T21:25:06Z")

</div>

Build your grok expression gradually and pay attention when things stop working. Start with `%{TIMESTAMP_ISO8601:logsimestamp}`. Does that work? Then continue with the next (`%{TIMESTAMP_ISO8601:logsimestamp}%{SPACE}\[%{WORD:threadID}\]`).

---

<div class="post-metadata">

**Author:** ![sslv](https://avatars.discourse-cdn.com/v4/letter/s/c2a13f/32.png) [@sslv](https://discuss.elastic.co/u/sslv)\
**Post date:** [June 19, 2017, 9:28pm UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-error/89989/9 "2017-06-19T21:28:27Z")

</div>

I am on Windows. @pts0

and @magnusbaeck I tried that.. nothing seems to work

---

<div class="post-metadata">

**Author:** ![pts0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pts0/32/17811_2.png) [@pts0](https://discuss.elastic.co/u/pts0)\
**Post date:** [June 19, 2017, 9:30pm UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-error/89989/10 "2017-06-19T21:30:25Z")

</div>

did you got more that one line ?  
try to convert to unix newline ?

---

<div class="post-metadata">

**Author:** ![sslv](https://avatars.discourse-cdn.com/v4/letter/s/c2a13f/32.png) [@sslv](https://discuss.elastic.co/u/sslv)\
**Post date:** [June 19, 2017, 9:35pm UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-error/89989/11 "2017-06-19T21:35:05Z")

</div>

It works if I use this expression  
(?(.|\r)\*)

and when I try to build on to that, it stops working

And can you please tell me what does conversion to unix newline mean?

---

<div class="post-metadata">

**Author:** ![pts0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pts0/32/17811_2.png) [@pts0](https://discuss.elastic.co/u/pts0)\
**Post date:** [June 19, 2017, 9:38pm UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-error/89989/12 "2017-06-19T21:38:25Z")

</div>

are u really sure you just have `\r` and not `\r\n` , just \r is really not windows

---

<div class="post-metadata">

**Author:** ![sslv](https://avatars.discourse-cdn.com/v4/letter/s/c2a13f/32.png) [@sslv](https://discuss.elastic.co/u/sslv)\
**Post date:** [June 19, 2017, 9:45pm UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-error/89989/13 "2017-06-19T21:45:22Z")

</div>

Yes! I am on windows.

May be since the default delimiter is "\n" (as I didnot set any explicitly),\n is getting chopped off before parsing, hence may be only \r is seen. Just my thought, you should be knowing better.I just started using logstash.

---

<div class="post-metadata">

**Author:** ![pts0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pts0/32/17811_2.png) [@pts0](https://discuss.elastic.co/u/pts0)\
**Post date:** [June 19, 2017, 10:24pm UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-error/89989/14 "2017-06-19T22:24:38Z")

</div>

then set delimiter to `\r\n`, should work.  
And I m just a user, no expert 🙂

---

<div class="post-metadata">

**Author:** ![sslv](https://avatars.discourse-cdn.com/v4/letter/s/c2a13f/32.png) [@sslv](https://discuss.elastic.co/u/sslv)\
**Post date:** [June 19, 2017, 10:40pm UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-error/89989/15 "2017-06-19T22:40:29Z")

</div>

Thanks for the reply. Tried that still no luck!

---

<div class="post-metadata">

**Author:** ![sslv](https://avatars.discourse-cdn.com/v4/letter/s/c2a13f/32.png) [@sslv](https://discuss.elastic.co/u/sslv)\
**Post date:** [June 20, 2017, 12:31am UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-error/89989/16 "2017-06-20T00:31:00Z")

</div>

I am able to overcome \r error. But still not able to get the pattern working.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 20, 2017, 5:37am UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-error/89989/17 "2017-06-20T05:37:30Z")

</div>

Works fine here:

```nohighlight
$ cat data
2017-06-14 11:17:48 [ad8880] INFO: blah blah blah
$ cat test.config 
input { stdin { } }
output { stdout { codec => rubydebug } }
filter {
  grok {
    match => [
      "message",
      "%{TIMESTAMP_ISO8601:logsimestamp}%{SPACE}\[%{WORD:threadID}\]%{SPACE}%{LOGLEVEL:loglevel}:%{SPACE}%{GREEDYDATA:task}"
    ]
  }
}
$ /opt/logstash/bin/logstash -f test.config < data
Settings: Default pipeline workers: 8
Pipeline main started
{
         "message" => "2017-06-14 11:17:48 [ad8880] INFO: blah blah blah",
        "@version" => "1",
      "@timestamp" => "2017-06-20T05:36:58.681Z",
            "host" => "lnxolofon",
    "logsimestamp" => "2017-06-14 11:17:48",
        "threadID" => "ad8880",
        "loglevel" => "INFO",
            "task" => "blah blah blah"
}
Pipeline main has been shutdown
stopping pipeline {:id=>"main"}

```

---

<div class="post-metadata">

**Author:** ![sslv](https://avatars.discourse-cdn.com/v4/letter/s/c2a13f/32.png) [@sslv](https://discuss.elastic.co/u/sslv)\
**Post date:** [June 20, 2017, 6:03am UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-error/89989/18 "2017-06-20T06:03:19Z")

</div>

Thanks for the reply Magnus!  
I have a few thoughts why the result might be different:  
I performed this test on Windows 10 with "File input plugin". Are there any chances that there can be any problems with EOL characters or with File opening or closing?

I also performed a small test to analyse the issue.I decided to go step by step upon your advice, So I wanted to see if the setup was correct,  
My input file contained:  
123  
456  
789

If the grok pattern is  
{  
match=\>{"message",%{NUMBER}} // This gave me \_grokparefailure  
}

but the pattern  
{  
match=\>{"message",(?[0-9]\*)} // did not give me any error  
}

but in either case, I was unable to see fields tag in the stdout (Is the fields tag updated only if the grok parsing succeeds?)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 20, 2017, 6:34am UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-error/89989/19 "2017-06-20T06:34:11Z")

</div>

> I performed this test on Windows 10 with "File input plugin". Are there any chances that there can be any problems with EOL characters or with File opening or closing?

Unlikely.

> match=\>{"message",%{NUMBER}} // This gave me \_grokparefailure

Always surround strings with double quotes.

> but in either case, I was unable to see fields tag in the stdout (Is the fields tag updated only if the grok parsing succeeds?)

What output plugin are you using?

---

<div class="post-metadata">

**Author:** ![sslv](https://avatars.discourse-cdn.com/v4/letter/s/c2a13f/32.png) [@sslv](https://discuss.elastic.co/u/sslv)\
**Post date:** [June 20, 2017, 4:29pm UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-error/89989/20 "2017-06-20T16:29:59Z")

</div>

For debugging I am using stdout.Please see the following configurations and results:

**1)**  
**file content** : 123

**config** :  
input {  
file {

# path =\> ["C:\Users\xyz\Downloads\abc-20170523192613978.log"]

path =\> "C:\Users\xyz\Desktop\Demo\WriteText.txt"  
start\_position =\> "beginning"  
}  
}

filter {  
grok {  
match =\> { "@message" =\> "%{GREEDYDATA:data}"}  
}  
}  
output {  
stdout { codec =\> rubydebug }  
}

My commandline shows following **output** :  
{  
"path" =\> "C:\Users\xyz\Desktop\Demo\WriteText.txt",  
"@timestamp" =\> 2017-06-20T16:18:33.956Z,  
"@version" =\> "1",  
"host" =\> "ABC",  
"message" =\> "123"  
}

// no data tag.

**2)**  
contents of **input** text:  
123  
789

**config2** :  
grok {  
match =\> { "@message" =\> "%{NUMBER:data}"}  
}

**output**  
{  
"path" =\> "C:\Users\xyz\Desktop\Demo\WriteText.txt",  
"@timestamp" =\> 2017-06-20T16:22:56.167Z,  
"@version" =\> "1",  
"host" =\> "ABC",  
"message" =\> "789",  
"tags" =\> [  
[0] "\_grokparsefailure"  
]  
}  
// I am getting parse error for simple number input. So I am wondering If the problem is with windows **.txt file** and **encoding** or something because grok is able to parse as GREEDYDATA but not as NUMBER. and there are no field tags in both the outputs.

Upon using --debug flag I found this I donot know if it is useful or not:

\_globbed\_files: C:\Users\xyz\Desktop\Demo\WriteText.txt: glob is: []

\_globbed\_files: C:\Users\xyz\Desktop\Demo\WriteText.txt: glob is: ["C:\Users\xyz\Desktop\Demo\WriteText.txt"] because glob did not work

[Next page](https://discuss.elastic.co/t/logstash--grokparsefailure-error/89989.md?page=2)
