# My grok fikter dont work

**URL:** <https://discuss.elastic.co/t/my-grok-fikter-dont-work/137795>\
**Category:** Logstash\
**Created:** [June 28, 2018, 1:51pm UTC](https://discuss.elastic.co/t/my-grok-fikter-dont-work/137795 "2018-06-28T13:51:58Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![DmitryLysenko](https://avatars.discourse-cdn.com/v4/letter/d/e56c9b/32.png) [@DmitryLysenko](https://discuss.elastic.co/u/DmitryLysenko)\
**Post date:** [June 28, 2018, 1:51pm UTC](https://discuss.elastic.co/t/my-grok-fikter-dont-work/137795/1 "2018-06-28T13:51:58Z")

</div>

Hi, I want the logs of my service to be processed using the filter grok. But instead I get \_grokparsefailure.  
Could you tell me what the problem is?

My logstash configuration:

```
input {
        file {
                path => ["/path/to/log/*.log"]
                exclude => ["*.gz", "*.zip", "*.rar","*.xlog"]
                start_position => "end"
                discover_interval => 1
        }
}
filter {
        grok{
                match => {"message" => "%{INT:count}[T]%{YEAR:year}-%{MONTHNUM:month}-%{MONTHDAY:day}[T]%{HOUR:hour}:?%{MINUTE:min}(?::?%{SECOND:sec})?[T]\(?%{BASE10NUM}\:?%{BASE16NUM}\)[T]\[?%{LOGLEVEL:exception_level}\s*][T]\:[T]\<?%{USERNAME:user}\>[T](%{GREEDYDATA:message})?"}
        }
}
output {
        elasticsearch {
                hosts => "http://IP_ADDR:9200"
                index => "logs-%{+YYYY.MM.dd}"
        }
}

```

My logs example:

`1 2018-05-04 12:02:47.852003 (3476:0x00007f466d7fb700) [WARNING] : <Root> Failed to close session to service`

My index:  
{  
"\_index": "logs-2018.06.28",  
"\_type": "logs",  
"\_id": "AWRGVgCw5z-x38VXIohu",  
"\_score": 1,  
"\_source": {  
"path": "/path/to/log/\*\*\*.log",  
"@timestamp": "2018-06-28T12:19:58.752Z",  
"@version": "1",  
"host": "RHEL6.local",  
"message": "1 2018-05-04 12:02:47.852003 (3476:0x00007f466d7fb700) [WARNING] : Failed to close session to service ",  
"tags": [  
"\_grokparsefailure"  
]  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 29, 2018, 10:02am UTC](https://discuss.elastic.co/t/my-grok-fikter-dont-work/137795/2 "2018-06-29T10:02:41Z")

</div>

I can't spot anything off the top of my head, but just build the expression gradually and you'll find the problem. Start with `^%{INT:count}[T]` and build from there.

---

<div class="post-metadata">

**Author:** ![DmitryLysenko](https://avatars.discourse-cdn.com/v4/letter/d/e56c9b/32.png) [@DmitryLysenko](https://discuss.elastic.co/u/DmitryLysenko)\
**Post date:** [June 29, 2018, 12:10pm UTC](https://discuss.elastic.co/t/my-grok-fikter-dont-work/137795/3 "2018-06-29T12:10:27Z")

</div>

I tried this method, nothing has changed.  
But I did not try to put the symbol "^" at the beginning

---

<div class="post-metadata">

**Author:** ![DmitryLysenko](https://avatars.discourse-cdn.com/v4/letter/d/e56c9b/32.png) [@DmitryLysenko](https://discuss.elastic.co/u/DmitryLysenko)\
**Post date:** [July 4, 2018, 6:47am UTC](https://discuss.elastic.co/t/my-grok-fikter-dont-work/137795/4 "2018-07-04T06:47:49Z")

</div>

Hello!  
I try your method, I dont see anymore "\_grokparsefailure" tag.  
But, my message dont cut

```
> {
> "_index": "logs-2018.07.04",
> "_type": "logs",
> "_id": "AWRkABAAMgfICQ_NuSAY",
> "_score": 1,
> "_source": {
> "path": "/path/to/log/***.log",
> "@timestamp": "2018-07-04T06:34:43.056Z",
> "@version": "1",
> "host": "RHEL6.local",
> "count": "2",
> "message": "2 2018-07-04 09:34:42.980795 (52245:0x00007f1087fff700) [WARNING] : <Iscp> Failed to connect to sniffer. Error: connect: Connection refused"
> }

```

Maybe, I make some mistake, because "count" field is determined.

New grok:

`> ^%{INT:count}[T]^%{YEAR:year}-^%{MONTHNUM:month}-^%{MONTHDAY:day}[T]^%{HOUR:hour}:?^%{MINUTE:min}(?::?^%{SECOND:sec})?[T]\(?^%{BASE10NUM}\:?^%{BASE16NUM}\)[T]\[?^%{LOGLEVEL:exception_level}\s*][T]\:[T]\<?^%{USERNAME:user}\>[T](^%{GREEDYDATA:message})?`

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 4, 2018, 9:51am UTC](https://discuss.elastic.co/t/my-grok-fikter-dont-work/137795/5 "2018-07-04T09:51:05Z")

</div>

Remove all `^` except the first one. That character means "beginning of the line", which obviously only should occur prior to `%{INT:count}`:

---

<div class="post-metadata">

**Author:** ![DmitryLysenko](https://avatars.discourse-cdn.com/v4/letter/d/e56c9b/32.png) [@DmitryLysenko](https://discuss.elastic.co/u/DmitryLysenko)\
**Post date:** [July 13, 2018, 8:33am UTC](https://discuss.elastic.co/t/my-grok-fikter-dont-work/137795/6 "2018-07-13T08:33:37Z")

</div>

Thank you so much!  
It works!  
If I still have a question, should I open a new topic, or continue communication in this?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 13, 2018, 11:35am UTC](https://discuss.elastic.co/t/my-grok-fikter-dont-work/137795/7 "2018-07-13T11:35:07Z")

</div>

Unless it's directly related to the existing topic please start a new one.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2018, 11:35am UTC](https://discuss.elastic.co/t/my-grok-fikter-dont-work/137795/8 "2018-08-10T11:35:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
