# Logstash grokparsefailure

**URL:** <https://discuss.elastic.co/t/logstash-grokparsefailure/250598>\
**Category:** Logstash\
**Created:** [October 1, 2020, 6:02am UTC](https://discuss.elastic.co/t/logstash-grokparsefailure/250598 "2020-10-01T06:02:57Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![sandikata](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandikata/32/73421_2.png) [@sandikata](https://discuss.elastic.co/u/sandikata)\
**Post date:** [October 1, 2020, 6:02am UTC](https://discuss.elastic.co/t/logstash-grokparsefailure/250598/1 "2020-10-01T06:02:57Z")

</div>

Hello!  
Is it there any way (human readable) to debug what is causing grokparsefailure?  
There's my nginx filter conf

```auto
filter { if "nginx_access" in [tags] {
  grok {
    patterns_dir => ["/etc/logstash/patterns"]
    match => { "message" => "%{NGINXACCESS}" }
	}

#grok { match => { "request" => "%{NOTSPACE:request_file}\?" } }
grok { match => { "request" => "%{URIPATH:request_file}%{URIPARAM:request_params}" } }

mutate { 
	remove_field => ["bytes", "httpversion", "agent.ephemeral_id", "agent.id", "agent.name", "agent.hostname", "agent.type", "agent.version"] 
	}
}

	 if ![x_first_ip] {
   geoip {
    source => "clientip"
       target => "geoip"
    database => "/usr/share/GeoIP/GeoIP2-City.mmdb"
    fields => ["continent_code", "country_name", "country_code3", "region_name", "city_name", "postal_code", "region_code", "location"]
   }
   ip2proxy {
    source => "clientip"
	database => "/usr/share/IP2Proxy/IP2PROXY-IP-PROXYTYPE-COUNTRY.BIN"
   }
  } else {
   ip2proxy {
    source => "x_first_ip"
	database => "/usr/share/IP2Proxy/IP2PROXY-IP-PROXYTYPE-COUNTRY.BIN"
   }
   geoip {
    source => "x_first_ip"
    database => "/usr/share/GeoIP/GeoIP2-City.mmdb"
    fields => ["continent_code", "country_name", "country_code3", "region_name", "city_name", "postal_code", "region_code", "location"]
   }
  }
#}
# useragent {
# source => "user_agent"
#	}
}

filter { if "nginx_errors" in [tags] {
  grok {
	add_tag => ["nginx_errors"]
}
}
}

And the pattern which i use.

```

```auto
NGINXACCESS %{IPORHOST:http_host} %{IPORHOST:clientip} \[%{HTTPDATE:timestamp}\] \"(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})\" %{NUMBER:response_code} (?:%{NUMBER:bytes}|-) \"%{DATA:referrer}\" \"%{DATA:useragent}\" \"%{DATA:request_body}\" \"(-|(?<x_forwarded_for>%{IP:x_first_ip}(?:, [^\s,]+)*)?)\" \"%{DATA:x_server}\" \"(-|%{DATA:api_key})\" %{NUMBER:request_time}

```

I am trying add some more thinks, and cannot find which is the problem.

---

<div class="post-metadata">

**Author:** ![sandikata](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandikata/32/73421_2.png) [@sandikata](https://discuss.elastic.co/u/sandikata)\
**Post date:** [October 1, 2020, 6:59am UTC](https://discuss.elastic.co/t/logstash-grokparsefailure/250598/2 "2020-10-01T06:59:16Z")

</div>

Also another think.  
Is it there any difference between built-in grok debugger and [https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/)  
Because some logs are not parsed properly, if i check them on debugger from the link everything is parsed properly, but in kibana built-in debugger just says grokparsefailure

First example have been taken from built-in

 ![Screenshot_2020-10-01 Dev Tools - Elastic-grok debugger](https://us1.discourse-cdn.com/elastic/original/3X/d/f/dfce529fe5ed7dd115187d1119dd151ce2f39840.png)

Second example have been taken from the link.

 ![Screenshot_2020-10-01 Grok Debugger](https://us1.discourse-cdn.com/elastic/original/3X/b/d/bd99280a5f8f40d94f08bebbf2a9f89acc0866a5.png)

What's could be the difference, because in kibana it won't parse anyway.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 1, 2020, 2:43pm UTC](https://discuss.elastic.co/t/logstash-grokparsefailure/250598/3 "2020-10-01T14:43:30Z")

</div>

> [@sandikata](#):
>
> Is it there any way (human readable) to debug what is causing grokparsefailure?

My suggestion for building complex grok patterns is [here](https://discuss.elastic.co/t/help-needed-in-grok/213827/2).

Note that grok debuggers (including kibana) and grok itself [sometimes](https://discuss.elastic.co/t/logstash-grok-not-parsing-multiline-pattern-properly/235033/4) interpret ambiguous patterns differently (and almost every pattern that uses DATA, or especially GREEDYDATA, is ambiguous).

---

<div class="post-metadata">

**Author:** ![sandikata](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sandikata/32/73421_2.png) [@sandikata](https://discuss.elastic.co/u/sandikata)\
**Post date:** [October 14, 2020, 11:22am UTC](https://discuss.elastic.co/t/logstash-grokparsefailure/250598/4 "2020-10-14T11:22:53Z")

</div>

Thank You for tips.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 11, 2020, 11:22am UTC](https://discuss.elastic.co/t/logstash-grokparsefailure/250598/5 "2020-11-11T11:22:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
