# Logstash reports \[0\] \_grokparsefailure

**URL:** <https://discuss.elastic.co/t/logstash-reports-0--grokparsefailure/49245>\
**Category:** Logstash\
**Created:** [May 5, 2016, 2:20am UTC](https://discuss.elastic.co/t/logstash-reports-0--grokparsefailure/49245 "2016-05-05T02:20:11Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kennedy\_Kan1](https://avatars.discourse-cdn.com/v4/letter/k/cc9497/32.png) [@Kennedy\_Kan1](https://discuss.elastic.co/u/Kennedy_Kan1)\
**Post date:** [May 5, 2016, 2:20am UTC](https://discuss.elastic.co/t/logstash-reports-0--grokparsefailure/49245/1 "2016-05-05T02:20:11Z")

</div>

I am using Logstash 2.3 and I have the following conf file.

I would expect to see in Kibana in the "Fields" section on the left the options for "JobID" displaying my job codebut I don't.

I see

@timestamp  
@version  
\_id  
\_index  
\_type host path  
I do see in the \_source section on the right side the following...

This is the message I received when I run the .conf file  
[![enter image description here](http://i.stack.imgur.com/fBio4.png)](http://i.stack.imgur.com/fBio4.png)

```
input{
	file{
		path => "C:/Job/Code.txt"
		start_position => "beginning"
	}
}
filter{
	json{source => "message"}
	grok{
	match => ["@message","%{WORD:job_id}"]
	add_tag => "grokked"
    	}
mutate {
        add_field => ['JobID', "%{job_id}"]
    }
}
output{
  	elasticsearch { hosts => ["localhost:9200"] }
  	stdout { codec => rubydebug }	
}

```

My txt file only contains 4 roles

```
0001
0002
0003
0004

```

Thanks

---

<div class="post-metadata">

**Author:** ![fbaligand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fbaligand/32/5657_2.png) [@fbaligand](https://discuss.elastic.co/u/fbaligand)\
**Post date:** [May 5, 2016, 8:49pm UTC](https://discuss.elastic.co/t/logstash-reports-0--grokparsefailure/49245/2 "2016-05-05T20:49:37Z")

</div>

I invite you to replace `@message` by `message` in your grok filter.

Thus, in mutate filter, the good syntax is :  
`add_field => { "JobID" => "%{job_id}" }`

If your file is a flat file (not containing json lines), I invite you to not use json filter.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:59am UTC](https://discuss.elastic.co/t/logstash-reports-0--grokparsefailure/49245/3 "2017-07-06T04:59:10Z")

</div>


