# \[logstash\] Cannot find the logs that donot match the grok filter

**URL:** <https://discuss.elastic.co/t/logstash-cannot-find-the-logs-that-donot-match-the-grok-filter/147510>\
**Category:** Logstash\
**Created:** [September 6, 2018, 7:19am UTC](https://discuss.elastic.co/t/logstash-cannot-find-the-logs-that-donot-match-the-grok-filter/147510 "2018-09-06T07:19:23Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Zhao](https://avatars.discourse-cdn.com/v4/letter/z/3da27b/32.png) [@Zhao](https://discuss.elastic.co/u/Zhao)\
**Post date:** [September 6, 2018, 7:19am UTC](https://discuss.elastic.co/t/logstash-cannot-find-the-logs-that-donot-match-the-grok-filter/147510/1 "2018-09-06T07:19:23Z")

</div>

Hello, dear all,

I updated the logstash from vesrion 2.1 to 6.4, and I find there are some differences between them which caused my problem.

1. I cannot find any logs that don't match my grok filters in the kibana for version 6.4, but for the older logstash, I can find them with the tags: "\_grokparsefailure ".

2. I also can't see any error in the /var/log/logstash/logstash-plain.log for the new version logstash.  
And I can find it many \_grokparsefailure in the /var/log/logstash/logstatsh.log for the old version logstash.

And for me, I need to save all the logs in the elasticsearch, include the parse error log.

How can I do my job for losgtash v6.4?

Any advice is very appreciated, thanks in advance.

Lyndon

---

<div class="post-metadata">

**Author:** ![Zhao](https://avatars.discourse-cdn.com/v4/letter/z/3da27b/32.png) [@Zhao](https://discuss.elastic.co/u/Zhao)\
**Post date:** [September 6, 2018, 11:20am UTC](https://discuss.elastic.co/t/logstash-cannot-find-the-logs-that-donot-match-the-grok-filter/147510/2 "2018-09-06T11:20:00Z")

</div>

I had found a way to resolve this issue -- add a filter that can match each log.  
But it still cannot be seen in the elasticsearch.

And in the end, I found that, I need to extract a field with the type date, or it cann't be indexed to "logstash-YY-MM-DD.log", that's why the log cannot be see in the kibana.

---

<div class="post-metadata">

**Author:** ![Zhao](https://avatars.discourse-cdn.com/v4/letter/z/3da27b/32.png) [@Zhao](https://discuss.elastic.co/u/Zhao)\
**Post date:** [September 6, 2018, 11:22am UTC](https://discuss.elastic.co/t/logstash-cannot-find-the-logs-that-donot-match-the-grok-filter/147510/3 "2018-09-06T11:22:37Z")

</div>

And I am wondering why in the logstash of 2.1 , it can use the default field @timestamp as the elasticsearch index but logstash v6.4 cannot do it as this way.

If anybody knows why, please let me know.

Thanks very much.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 4, 2018, 11:22am UTC](https://discuss.elastic.co/t/logstash-cannot-find-the-logs-that-donot-match-the-grok-filter/147510/4 "2018-10-04T11:22:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
