# Yet another funky grokparsefailure

**URL:** <https://discuss.elastic.co/t/yet-another-funky-grokparsefailure/124322>\
**Category:** Logstash\
**Created:** [March 16, 2018, 3:52pm UTC](https://discuss.elastic.co/t/yet-another-funky-grokparsefailure/124322 "2018-03-16T15:52:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Fred1](https://avatars.discourse-cdn.com/v4/letter/f/e99b99/32.png) [@Fred1](https://discuss.elastic.co/u/Fred1)\
**Post date:** [March 16, 2018, 3:52pm UTC](https://discuss.elastic.co/t/yet-another-funky-grokparsefailure/124322/1 "2018-03-16T15:52:03Z")

</div>

Hi gang,

Completely out of my wits on this one...

Here's a log line (NGINX custom format):

13.88.158.6 - - [14/Mar/2018:00:02:03 +0000] "GET /issue/wsfed?wa=wsignout1.0 HTTP/1.0" 499 0 "[https://msft2017r2-wus2-prd.whatever.com/app.aspx](https://msft2017r2-wus2-prd.whatever.com/app.aspx)" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36 Edge/16.16299" "-" "[pass.whatever.com](http://pass.whatever.com)" sn="[passproxy-prod.whatever.com](http://passproxy-prod.whatever.com)" rt=49.171 ua="13.88.158.6:443" us="-" ut="-" ul="0" cs=-Netherlands NL NH

It can be parsed this way with grok:

filter {  
grok {  
match =\> ["message","%{COMBINEDAPACHELOG}+%{GREEDYDATA:extra\_fields}"]  
overwrite =\> ["message"]  
}

but the result is not accurate.

Here's an expression that will fly in [https://grokdebug.herokuapp.com](https://grokdebug.herokuapp.com) and other grok debuggers:

%{IPORHOST:remote\_addr} %{USER:ident} %{USER:auth} [%{HTTPDATE:timestamp}] \"%{WORD:verb} %{NOTSPACE:request} HTTP/%{NUMBER:httpversion}\" %{INT:status} %{NUMBER:bytes\_sent} \"%{DATA:http\_referer}" \"%{DATA:http\_user\_agent}" \"%{DATA:http\_x\_forwarded\_for}\" \"%{DATA:host}\" sn=\"%{DATA:server\_name}\" rt=%{DATA:request\_time} ua=\"%{DATA:upstream\_addr}\" us=\"%{DATA:upstream\_status}\" ut=\"%{DATA:upstream\_response\_time}\" ul=\"%{DATA:upstream\_response\_length}\" %{GREEDYDATA:extra\_fields}

... but that gets me a \_grokparsefailure in logstash.

Any idea how I shall build the "match" statement in logstash.conf so that my (legal) expression does not result in a \_grokparsefailure ?

I've tried everything, working my way up from what is working. Every time I try to add something here I get this dreaded grokparsefailure:

match =\> ["message","%{COMBINEDAPACHELOG}[ADD-SOMETHING-HERE]+%{GREEDYDATA:extra\_fields}"]

Thanks much,

Fred

---

<div class="post-metadata">

**Author:** ![atira](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/atira/32/28699_2.png) [@atira](https://discuss.elastic.co/u/atira)\
**Post date:** [March 31, 2018, 10:26pm UTC](https://discuss.elastic.co/t/yet-another-funky-grokparsefailure/124322/2 "2018-03-31T22:26:05Z")

</div>

You need to escape brackets in the Logstash config.  
eg.  
[%{HTTPDATE:timestamp}] --\> \[%{HTTPDATE:timestamp}\]

---

<div class="post-metadata">

**Author:** ![Fred1](https://avatars.discourse-cdn.com/v4/letter/f/e99b99/32.png) [@Fred1](https://discuss.elastic.co/u/Fred1)\
**Post date:** [April 16, 2018, 8:53am UTC](https://discuss.elastic.co/t/yet-another-funky-grokparsefailure/124322/3 "2018-04-16T08:53:37Z")

</div>

Thanks atira !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 14, 2018, 8:54am UTC](https://discuss.elastic.co/t/yet-another-funky-grokparsefailure/124322/4 "2018-05-14T08:54:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
