# Logstash grok \_grokparsefailure tag

**URL:** <https://discuss.elastic.co/t/logstash-grok-grokparsefailure-tag/226123>\
**Category:** Logstash\
**Created:** [April 1, 2020, 8:43pm UTC](https://discuss.elastic.co/t/logstash-grok-grokparsefailure-tag/226123 "2020-04-01T20:43:13Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sepideh\_Bayati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sepideh_bayati/32/65520_2.png) [@Sepideh\_Bayati](https://discuss.elastic.co/u/Sepideh_Bayati)\
**Post date:** [April 1, 2020, 8:43pm UTC](https://discuss.elastic.co/t/logstash-grok-grokparsefailure-tag/226123/1 "2020-04-01T20:43:13Z")

</div>

hi. im using syslog-ng and loggen to generate my logs and this is the one for example:

```auto
<38>2020-04-01T23:30:02 localhost prg00000[1234]: seq: 0000000096, thread: 0000, runid: 1585767601, stamp: 2020-04-01T23:30:02 PADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADDPADD

```

and this is my logstash configuration file:

```auto
input {
  tcp {
    port => 9000
  }
  udp {
    port => 9000
  }
}

filter {

grok {

match => { "message" => "%{GREEDYDATA:nonsense}: {NUMBER:seq}, %{NUMBER:thread}, %{NUMBER:runid}, %{TIMESTAMP_ISO8601:stamp} %{GREEDYDATA:message}" }

}

}

output {

elasticsearch {

hosts => ["localhost:9200"]

}

}

```

although i can see the logs in kibana, but all of them have the same tag "\_grokparsefailure" . can someone please help me ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 1, 2020, 9:01pm UTC](https://discuss.elastic.co/t/logstash-grok-grokparsefailure-tag/226123/2 "2020-04-01T21:01:36Z")

</div>

> [@Sepideh\_Bayati](#):
>
> {NUMBER:seq}, %{NUMBER:thread}, %{NUMBER:runid},

That is not going to match

```
0000000096, thread: 0000, runid: 1585767601,

```

You could try

```
{NUMBER:seq}, thread: %{NUMBER:thread}, runid: %{NUMBER:runid},

```

Also, get rid of the leading '%{GREEDYDATA:nonsense}', it will make the pattern much more expensive if a line does not match. Starting the pattern with the : that follows that limits the number of places in the log line where it has to starting trying to match.

I would actually dissect that instead of using grok

```
dissect { mapping => { "message" => "<%{pri}>%{ts} %{host} %{program}[%{pid}]: seq: %{seq}, thread: %{thread}, runid: %{runid}, stamp: %{stamp} %{restOfLine}" }

```

If you do not want some fields you can replace %{pri} with %{} etc. -- it will still consume the text between the delimiters but not store it as a field.

---

<div class="post-metadata">

**Author:** ![Sepideh\_Bayati](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sepideh_bayati/32/65520_2.png) [@Sepideh\_Bayati](https://discuss.elastic.co/u/Sepideh_Bayati)\
**Post date:** [April 1, 2020, 9:20pm UTC](https://discuss.elastic.co/t/logstash-grok-grokparsefailure-tag/226123/3 "2020-04-01T21:20:40Z")

</div>

thanks it worked perfectly and now i got what i exactly want 🥳

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 29, 2020, 9:28pm UTC](https://discuss.elastic.co/t/logstash-grok-grokparsefailure-tag/226123/4 "2020-04-29T21:28:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
