# Logstash \_grokparsefailure issues?

**URL:** <https://discuss.elastic.co/t/logstash--grokparsefailure-issues/46645>\
**Category:** Logstash\
**Created:** [April 7, 2016, 9:03am UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-issues/46645 "2016-04-07T09:03:03Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![stefansaye](https://avatars.discourse-cdn.com/v4/letter/s/df788c/32.png) [@stefansaye](https://discuss.elastic.co/u/stefansaye)\
**Post date:** [April 7, 2016, 9:03am UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-issues/46645/1 "2016-04-07T09:03:03Z")

</div>

hi all ,  
I'm having issues with grok parsing. In ElasticSearch/Kibana the lines I match come up with the tag \_grokparsefailure.

Here is my logstash config :  
input {  
snmptrap {  
yamlmibdir =\> "/opt/logstash/vendor/bundle/jruby/1.9/gems/snmp- 1.2.0/data/ruby/snmp/mibs"  
codec =\> plain {  
charset =\> "BINARY"  
}  
type =\> "snmptrap"  
}  
}

filter {  
de\_dot {}  
if [type] == "snmptrap"  
{  
grok {  
match =\> { "message" =\> "%{IP:@source\_ip=\""}" }  
add\_field =\> { "source\_ip" =\>"%{@source\_ip="}" }  
}

}

}

output {  
elasticsearch { hosts =\> localhost }  
stdout {  
codec =\> rubydebug  
}  
file {  
codec =\> rubydebug  
flush\_interval =\> 1  
path =\> "/tmp/logstash-snmptrap.log"  
}  
}

my input look like this below.

"message" =\> "#\<SNMP::SNMPv1\_Trap:0x1c6c6492 @enterprise=[1.3.6.1.3.92.1.1.7], @timestamp=#\<SNMP::TimeTicks:0x680d5191 @value=802993822\>, @varbind\_list=[#\<SNMP::VarBind:0x3deb19e5 @name=[1.3.6.1.3.92.1.1.5.1.3.202.169.174.90], @value=#\<SNMP::Integer:0x42dcb23e @value=1\>\>], @specific\_trap=2, @source\_ip="10.10.10.12", @agent\_addr=#\<SNMP::IpAddress:0x405ff22d @value="\xC0\xA8\a\f"\>, @generic\_trap=6\>",  
"host" =\> "10.10.10.12",  
"@version" =\> "1",  
"@timestamp" =\> "2016-04-07T08:31:03.697Z",  
"type" =\> "snmptrap",  
"MSDP-MIB::msdpPeerState\_10\_10\_14\_20" =\> "1"

Can somebody give me a hint how I can fix the problem?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 8, 2016, 6:26am UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-issues/46645/2 "2016-04-08T06:26:49Z")

</div>

> match =\> { "message" =\> "%{IP:@source\_ip=\""}" }

I think you're misunderstanding the grok syntax. You probably mean this:

```
@source_ip=\"%{IP:source_ip}\"

```

I suggest you look into the kv filter, especially if you want to parse more than the source IP field.

> add\_field =\> { "source\_ip" =\>"%{@source\_ip="}" }

Remove this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:03am UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-issues/46645/3 "2017-07-06T05:03:10Z")

</div>


