# Losgstash error starting with Expected one of #, {, ,, \] at line XX

**URL:** <https://discuss.elastic.co/t/losgstash-error-starting-with-expected-one-of-at-line-xx/179072>\
**Category:** Logstash\
**Created:** [April 30, 2019, 11:25am UTC](https://discuss.elastic.co/t/losgstash-error-starting-with-expected-one-of-at-line-xx/179072 "2019-04-30T11:25:45Z")\
**Posts on this page:** 1\
**Showing post:** 10

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 30, 2019, 10:24pm UTC](https://discuss.elastic.co/t/losgstash-error-starting-with-expected-one-of-at-line-xx/179072/10 "2019-04-30T22:24:52Z")

</div>

> [@franco.federico](#):
>
> Is it possible to delete \_grokparsefailure?

Yes, you can use

```
    mutate { remove_tag => "_grokparsefailure" }

```

If that is the only tag on the event that leaves tags as an empty array. You can remove that using [this](https://discuss.elastic.co/t/how-to-overwrite-message-set-to-minus-if-it-is-not-overwrited-in-grok/138518/8).

I notice that in your original grok filter you tried to do remove\_tag =\> "\_grokparsefailure". That does not work the way you want. "Decoration" of events, which implements the common options like remove\_tag, only occurs if the filter succeeds. So it would only remove the \_grokparsefailure if it had not been added.

---

_[View the full topic](https://discuss.elastic.co/t/losgstash-error-starting-with-expected-one-of-at-line-xx/179072)._
