# Need help with logparser

**URL:** <https://community.influxdata.com/t/need-help-with-logparser/12907>\
**Category:** Telegraf\
**Tags:** telegraf\
**Created:** [February 5, 2020, 7:34am UTC](https://community.influxdata.com/t/need-help-with-logparser/12907 "2020-02-05T07:34:22Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![hsafe](https://avatars.discourse-cdn.com/v4/letter/h/e9c0ed/32.png) [@hsafe](https://community.influxdata.com/u/hsafe)\
**Post date:** [February 5, 2020, 7:34am UTC](https://community.influxdata.com/t/need-help-with-logparser/12907/1 "2020-02-05T07:34:22Z")

</div>

Hi  
I tried to set up a log parser on nginx response code and while first initial tries failed, I now receive an error incomprehensible to me. Here are some details:  
Influx Version: influxdb-1.7.9-1.x86\_64  
Teelgraf Version: Telegraf 1.13.1 (git: HEAD 0c175724)

The config gist:

> Blockquote  
> [[inputs.logparser]]  
> files = [“/var/log/nginx/access.log”]  
> from\_beginning = true  
> watch\_method = “inotify”  
> [inputs.logparser.grok]  
> patterns = [“%{METRICS\_INCLUDE\_RESPONSE}”]  
> measurement = “nginx\_access\_log”  
> custom\_patterns = ‘’’  
> METRICS\_INCLUDE\_RESPONSE [%{NUMBER:response}]  
> ‘’’

The error I receive is:  
2020-02-05T07:33:42Z E! [inputs.logparser] Error parsing log line: error parsing regexp: unexpected ): `([(?P<response>(?:(([+-]?(?:[0-9]+(?:\.[0-9]+)?)|\.[0-9]+))))])`

Appreciate to let me know what part needs change or modification…I am a newbie in the world of log parsing really Thank you again

---

<div class="post-metadata">

**Author:** ![daniel](https://sea1.discourse-cdn.com/flex023/user_avatar/community.influxdata.com/daniel/32/142_2.png) [@daniel](https://community.influxdata.com/u/daniel)\
**Post date:** [February 5, 2020, 6:35pm UTC](https://community.influxdata.com/t/need-help-with-logparser/12907/2 "2020-02-05T18:35:25Z")

</div>

I think you need to escape the brackets in your custom pattern, since brackets are special characters for the regular expressions.

```auto
METRICS_INCLUDE_RESPONSE \[%{NUMBER:response}\]

```

To explain the error message a bit, each pattern such as `%{NUMBER:response}`, is just a placeholder for a regular expression. In this case it is replaced with `(?P<response>(?:(([+-]?(?:[0-9]+(?:\.[0-9]+)?)|\.[0-9]+))))`. If you add the brackets around this regular expression then it is no longer valid.
