# When i add this logstash filter for apache logs get following error

**URL:** <https://discuss.elastic.co/t/when-i-add-this-logstash-filter-for-apache-logs-get-following-error/221679>\
**Category:** Logstash\
**Tags:** elastic-stack-alerting\
**Created:** [March 2, 2020, 12:56pm UTC](https://discuss.elastic.co/t/when-i-add-this-logstash-filter-for-apache-logs-get-following-error/221679 "2020-03-02T12:56:21Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![shahzaib123](https://avatars.discourse-cdn.com/v4/letter/s/eb9ed0/32.png) [@shahzaib123](https://discuss.elastic.co/u/shahzaib123)\
**Post date:** [March 2, 2020, 12:56pm UTC](https://discuss.elastic.co/t/when-i-add-this-logstash-filter-for-apache-logs-get-following-error/221679/1 "2020-03-02T12:56:21Z")

</div>

I am facing a issue in logstash filter with grok filter

my log data is:  
192.168.1.200 - - [02/Mar/2020:12:25:45 +0500] "GET / HTTP/1.1" 200 472 "-" "Mozilla/5.0 (X11; Linux x86\_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.130 Safari/537.36"

grok filter configuration is:  
%{IPORHOST:clientip} - - [%{HTTPDATE:httpdate}] "%{WORD:Method} / HTTP/%{NUMBER:httpversion}" %{NUMBER:response} %{NUMBER:Response\_size} %{QS:referrer} %{QS:agent}

whole configuation of logstash is:  
input {  
beats {  
port =\> 5044  
}  
}  
filter {  
grok {  
match =\> { "message" =\> "%{IPORHOST:clientip} - - [%{HTTPDATE:httpdate}] "%{WORD:Method} / HTTP/%{NUMBER:httpversion}" %{NUMBER:response} %{NUMBER:Response\_size} %{QS:referrer} %{QS:agent}"}  
}  
}  
output {  
elasticsearch {  
hosts =\> ["10.110.2.120:9200"]  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
}  
}

Error:  
logs of logstash:  
[2020-03-02T12:53:00,406][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of [\t\r\n], "#", "{", "}" at line 8, column 81 (byte 140) after filter {\n grok {\n match =\> { "message" =\> "%{IPORHOST:clientip} - - \[%{HTTPDATE:httpdate}\] "", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:47:in `compile_imperative'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:55:in `compile\_graph'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:17:in `block in compile_sources'", "org/jruby/RubyArray.java:2580:in `map'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:14:in `compile_sources'", "org/logstash/execution/AbstractPipelineExt.java:161:in `initialize'", "org/logstash/execution/JavaBasePipelineExt.java:47:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/java_pipeline.rb:27:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline\_action/create.rb:36:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:326:in `block in converge\_state'"]}

[2020-03-02T12:53:00,678][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[2020-03-02T12:53:05,563][INFO][logstash.runner] Logstash shut down.

please give me advice for solution

---

<div class="post-metadata">

**Author:** ![Fabio-sama](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@Fabio-sama](https://discuss.elastic.co/u/Fabio-sama)\
**Post date:** [March 3, 2020, 11:11am UTC](https://discuss.elastic.co/t/when-i-add-this-logstash-filter-for-apache-logs-get-following-error/221679/2 "2020-03-03T11:11:25Z")

</div>

Hi there,

please next time you post something try to properly indent it in a text editor (Atom, Visual Studio Code, Sublime or whatever), paste it here **properly spaced** , highlight it and then click on the **Preformatted text** tool ( ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/8/e8de46f8aa6935eb131978356c2d3c0bb1c66487.png) ), otherwise it'll be unreadable to others.

That said, you didn't escape quotes in your grok before `Method` and after `httpversion`.

Also, you will have a \_grokparsefailure if you don't escape the square brackets around the httpdate, too.

Try with this grok:

```
grok {
  match => { "message" => "%{IPORHOST:clientip} - - \[%{HTTPDATE:httpdate}\] \"%{WORD:Method} / HTTP/%{NUMBER:httpversion}\" %{NUMBER:response} %{NUMBER:Response_size} %{QS:referrer} %{QS:agent}"}
}
```

---

<div class="post-metadata">

**Author:** ![shahzaib123](https://avatars.discourse-cdn.com/v4/letter/s/eb9ed0/32.png) [@shahzaib123](https://discuss.elastic.co/u/shahzaib123)\
**Post date:** [March 6, 2020, 7:32am UTC](https://discuss.elastic.co/t/when-i-add-this-logstash-filter-for-apache-logs-get-following-error/221679/3 "2020-03-06T07:32:46Z")

</div>

Thank you ... 🙂

---

<div class="post-metadata">

**Author:** ![Fabio-sama](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@Fabio-sama](https://discuss.elastic.co/u/Fabio-sama)\
**Post date:** [March 6, 2020, 1:56pm UTC](https://discuss.elastic.co/t/when-i-add-this-logstash-filter-for-apache-logs-get-following-error/221679/4 "2020-03-06T13:56:03Z")

</div>

No problem. If it solved your problem, please set it as `Solution`, this way a future reader will see this problem has been solved.

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 3, 2020, 2:00pm UTC](https://discuss.elastic.co/t/when-i-add-this-logstash-filter-for-apache-logs-get-following-error/221679/5 "2020-04-03T14:00:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
