# Logstash grok parse failure

**URL:** <https://discuss.elastic.co/t/logstash-grok-parse-failure/87550>\
**Category:** Logstash\
**Created:** [May 30, 2017, 10:17am UTC](https://discuss.elastic.co/t/logstash-grok-parse-failure/87550 "2017-05-30T10:17:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marcello\_A](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcello_a/32/78018_2.png) [@Marcello\_A](https://discuss.elastic.co/u/Marcello_A)\
**Post date:** [May 30, 2017, 10:17am UTC](https://discuss.elastic.co/t/logstash-grok-parse-failure/87550/1 "2017-05-30T10:17:27Z")

</div>

Hi All,  
I tried to import a modified combined apache logs on a logstash instance and I have this sample row:

`10.10.10.10 54338 - [29/May/2017:16:21:34 +0200] "GET /test.html HTTP/1.1" 200 682 8763 "https://mysite.com/test" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.96 Safari/537.36" "JSESSIONID=1010101; testid=asajdhasd "`

I configured a custom pattern reported like this

```
%{IPORHOST:clientip} (?:%{DATA:ident}|-) (?:%{DATA:auth}|-) \[%{HTTPDATE:timestamp}\] \"%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion}|-)\" %{NUMBER:response} (?:%{NUMBER:bytes}|-) (?:%{NUMBER:timespent}|-) \"%{NOTSPACE:referrer}\" \"%{DATA:agent}\" \"%{DATA:cookies}\"

```

On elasticsearch side all the fields are fine but for all the rows I noticed the tag "\_grokparsefailure".

Does someone notice this error before?

Thanks,  
Marcello

---

<div class="post-metadata">

**Author:** ![sahar\_q](https://avatars.discourse-cdn.com/v4/letter/s/dbc845/32.png) [@sahar\_q](https://discuss.elastic.co/u/sahar_q)\
**Post date:** [May 30, 2017, 10:22am UTC](https://discuss.elastic.co/t/logstash-grok-parse-failure/87550/2 "2017-05-30T10:22:40Z")

</div>

yes, it means grok got an unexpected piece of data that it didnt know what to do with.  
given the data you posted and the grok pattern everything seems fine.  
could it be that not all of the data follow this pattern?

---

<div class="post-metadata">

**Author:** ![Marcello\_A](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcello_a/32/78018_2.png) [@Marcello\_A](https://discuss.elastic.co/u/Marcello_A)\
**Post date:** [June 5, 2017, 8:16am UTC](https://discuss.elastic.co/t/logstash-grok-parse-failure/87550/3 "2017-06-05T08:16:54Z")

</div>

I resolved with a dos2unix command on the parsed file. Actually there aren't entries with "\_grokparsefailure". We would move the entries with "\_grokparsefailure" tag to a dedicated file and not under the elasticsearch index.

Marcello

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 3, 2017, 8:17am UTC](https://discuss.elastic.co/t/logstash-grok-parse-failure/87550/4 "2017-07-03T08:17:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
