# \#grok

**URL:** https://community.influxdata.com/tag/grok/84.md

[Latest](https://community.influxdata.com/latest.md) · [Categories](https://community.influxdata.com/categories.md) · [Tags](https://community.influxdata.com/tags.md)

---

## [Is there a way to detect/monitor parsing lag in the tail input plugin?](https://community.influxdata.com/t/is-there-a-way-to-detect-monitor-parsing-lag-in-the-tail-input-plugin/58442)

<div class="topic-metadata">

**Author:** [@Mihyun](https://community.influxdata.com/u/Mihyun)\
**Replies:** 1\
**Last updated:** [April 29, 2026, 5:07pm UTC](https://community.influxdata.com/t/is-there-a-way-to-detect-monitor-parsing-lag-in-the-tail-input-plugin/58442 "2026-04-29T17:07:34Z")

</div>

Hi everyone, I’m using the tail input plugin with the grok parser to parse application logs at scale. I’ve confirmed that when log generation exceeds the parsing throughput, Telegraf continues to parse but falls behind…

---

## [Add user-defined tag in Grok input](https://community.influxdata.com/t/add-user-defined-tag-in-grok-input/58156)

<div class="topic-metadata">

**Author:** [@HarimbolaSantatra](https://community.influxdata.com/u/HarimbolaSantatra)\
**Replies:** 1\
**Last updated:** [December 7, 2025, 12:22pm UTC](https://community.influxdata.com/t/add-user-defined-tag-in-grok-input/58156 "2025-12-07T12:22:48Z")

</div>

Is there a way to insert a user-defined tag in a tail input with grok pattern ? For example, I’m parsing the following line (extracted from /var/log/secure): Dec 7 11:52:54 myusername sshd-session\[24595\]: pam\_unix(ssh…

---

## [Add tag if grok pattern matched](https://community.influxdata.com/t/add-tag-if-grok-pattern-matched/32464)

<div class="topic-metadata">

**Author:** [@manoaratefy](https://community.influxdata.com/u/manoaratefy)\
**Replies:** 6\
**Last updated:** [December 15, 2023, 11:09am UTC](https://community.influxdata.com/t/add-tag-if-grok-pattern-matched/32464 "2023-12-15T11:09:25Z")

</div>

Hello, I have logs coming from syslog input, and some of them matches a specific grok pattern. I have to record matched and unmatched log entries to different storage. So I want to add tag if grok match or not. But seem…

---

## [Telegraf Input File Plugin does not support grok and json both logs parsing in single logs](https://community.influxdata.com/t/telegraf-input-file-plugin-does-not-support-grok-and-json-both-logs-parsing-in-single-logs/31857)

<div class="topic-metadata">

**Author:** [@Vivek\_parody](https://community.influxdata.com/u/Vivek_parody)\
**Replies:** 2\
**Last updated:** [October 18, 2023, 10:18am UTC](https://community.influxdata.com/t/telegraf-input-file-plugin-does-not-support-grok-and-json-both-logs-parsing-in-single-logs/31857 "2023-10-18T10:18:47Z")

</div>

Hi, I have an input String in my file 2023-10-17T14:04:51.429439018Z stdout F {"timeMillis":1697551491429,"thread":"http-nio-8081-exec-4","level":"DEBUG","loggerName":"org.apache.tomcat.util.http.Parameters","message"…

---

## [Telegraf grok not parsing with custom patterns which works on grok debug](https://community.influxdata.com/t/telegraf-grok-not-parsing-with-custom-patterns-which-works-on-grok-debug/31470)

<div class="topic-metadata">

**Author:** [@OHO\_OHO](https://community.influxdata.com/u/OHO_OHO)\
**Replies:** 0\
**Last updated:** [September 11, 2023, 6:06pm UTC](https://community.influxdata.com/t/telegraf-grok-not-parsing-with-custom-patterns-which-works-on-grok-debug/31470 "2023-09-11T18:06:22Z")

</div>

I have a pattern basicly copies the grok built-in COMMON\_LOG\_FORMAT pattern. Only difference is the target log I want to match may contain different time formats, so I incorporated two patterns for it. My grok patterns …

---

## [How to parse Snowflake log file?](https://community.influxdata.com/t/how-to-parse-snowflake-log-file/30881)

<div class="topic-metadata">

**Author:** [@pixelcode](https://community.influxdata.com/u/pixelcode)\
**Replies:** 3\
**Last updated:** [July 27, 2023, 8:46am UTC](https://community.influxdata.com/t/how-to-parse-snowflake-log-file/30881 "2023-07-27T08:46:59Z")

</div>

I’m trying to have Telegraf parse the log file of the local Snowflake instance. It usually looks like this: nohup: Input is ignored 2023/07/24 20:09:24 Proxy starting 2023/07/24 20:10:19 NAT type: restricted 2023/07/24 …

---

## [Telegraf is not reading Nginx access log file data on nginx 1.20](https://community.influxdata.com/t/telegraf-is-not-reading-nginx-access-log-file-data-on-nginx-1-20/25752)

<div class="topic-metadata">

**Author:** [@matheus-cfr](https://community.influxdata.com/u/matheus-cfr)\
**Replies:** 6\
**Last updated:** [April 19, 2023, 10:15am UTC](https://community.influxdata.com/t/telegraf-is-not-reading-nginx-access-log-file-data-on-nginx-1-20/25752 "2023-04-19T10:15:35Z")

</div>

Hello guys. I’m studying about telegraf passing the data to prometheus and displaying the data in grafana. The nginx log is not passing through telegraf. My telegraf.conf: \[\[inputs.nginx\]\] urls = \["http://localhost/…

---

## [Capturing entry from /var/log/messages](https://community.influxdata.com/t/capturing-entry-from-var-log-messages/27907)

<div class="topic-metadata">

**Author:** [@rmo](https://community.influxdata.com/u/rmo)\
**Replies:** 4\
**Last updated:** [February 22, 2023, 9:40pm UTC](https://community.influxdata.com/t/capturing-entry-from-var-log-messages/27907 "2023-02-22T21:40:25Z")

</div>

I have a large /var/log/messages file which gets rotated. I would like to get log entries which only have ‘rsyslogd was HUpped’ and put them into telegraf. How would I achieve this?

---

## [Cannot parse multiline exec output using Grok input plugin](https://community.influxdata.com/t/cannot-parse-multiline-exec-output-using-grok-input-plugin/27722)

<div class="topic-metadata">

**Author:** [@cyril.jean](https://community.influxdata.com/u/cyril.jean)\
**Replies:** 2\
**Last updated:** [January 17, 2023, 4:29pm UTC](https://community.influxdata.com/t/cannot-parse-multiline-exec-output-using-grok-input-plugin/27722 "2023-01-17T16:29:02Z")

</div>

Hello, I’m trying to create metrics from the exec output below, where I need to have the client Id and the Connected status. The JORAMMQ\_MQTT\_HOME environment variable is not defined. Use JORAMMQ\_MQTT\_HOME=/usr/share/j…

---

## [Telegraf tail-plugin with grok: no data written to influxdb](https://community.influxdata.com/t/telegraf-tail-plugin-with-grok-no-data-written-to-influxdb/27393)

<div class="topic-metadata">

**Author:** [@astrakid](https://community.influxdata.com/u/astrakid)\
**Replies:** 4\
**Last updated:** [November 17, 2022, 6:47am UTC](https://community.influxdata.com/t/telegraf-tail-plugin-with-grok-no-data-written-to-influxdb/27393 "2022-11-17T06:47:15Z")

</div>

hi, i am parsing an sftp-log for certain requests. if matched an entry should be written in influxdb. this is my telegraf-conf: files = \["/var/log/proftpd/sftp.log"\] watch\_method = "inotify" from\_beginning = tru…

---

## [Inputs.tail grok debugging](https://community.influxdata.com/t/inputs-tail-grok-debugging/26209)

<div class="topic-metadata">

**Author:** [@James\_Coleman](https://community.influxdata.com/u/James_Coleman)\
**Replies:** 3\
**Last updated:** [August 23, 2022, 7:21am UTC](https://community.influxdata.com/t/inputs-tail-grok-debugging/26209 "2022-08-23T07:21:57Z")

</div>

I’ve been trying to get output from inputs.tail for awhile now and I am at the point where I’m hoping the community can help. I reviewed telegraf/plugins/parsers/grok at master · influxdata/telegraf · GitHub to learn abo…

---

## [Telegraf tail input parsing using GROK - Syntax help](https://community.influxdata.com/t/telegraf-tail-input-parsing-using-grok-syntax-help/25076)

<div class="topic-metadata">

**Author:** [@Tom\_Aspland](https://community.influxdata.com/u/Tom_Aspland)\
**Replies:** 5\
**Last updated:** [May 18, 2022, 11:10pm UTC](https://community.influxdata.com/t/telegraf-tail-input-parsing-using-grok-syntax-help/25076 "2022-05-18T23:10:36Z")

</div>

Hi, I am trying to get Telegraf (1.22.3 on Windows) to tail a game server log and extract the timestamp and on the same line entry parse out the tick rate (performance of the game server), example of log below: \[2022.0…

---

## [No data points influxdb \[grok pattern\]](https://community.influxdata.com/t/no-data-points-influxdb-grok-pattern/18686)

<div class="topic-metadata">

**Author:** [@sai\_bug](https://community.influxdata.com/u/sai_bug)\
**Replies:** 18\
**Last updated:** [February 19, 2022, 5:17am UTC](https://community.influxdata.com/t/no-data-points-influxdb-grok-pattern/18686 "2022-02-19T05:17:41Z")

</div>

Hi team i have set telegraf conf to get metrics for python app, see below the telegraf conf . It works fine . \[\[inputs.tail\]\] files = \["probesso.log"\] from\_beginning = false #\[inputs.logparser.grok\] grok\_patter…

---

## [Ignore telegraf logs if it contains a particular data using grok](https://community.influxdata.com/t/ignore-telegraf-logs-if-it-contains-a-particular-data-using-grok/23748)

<div class="topic-metadata">

**Author:** [@jeevan1205](https://community.influxdata.com/u/jeevan1205)\
**Replies:** 2\
**Last updated:** [February 8, 2022, 8:45pm UTC](https://community.influxdata.com/t/ignore-telegraf-logs-if-it-contains-a-particular-data-using-grok/23748 "2022-02-08T20:45:35Z")

</div>

Hi, I have logs like below. I need to ignore the 2nd entry as it has 10.0.0.0 IP address 2022-02-02 14:10:23 299327 10.0.0.28 TCP\_TUNNEL/200 1084 CONNECT test1.com:443 - HIER\_DIRECT/1.1.1.1 - 2022-02-02 14:10:38 981 …

---

## [Grok pattern for telegraf](https://community.influxdata.com/t/grok-pattern-for-telegraf/23681)

<div class="topic-metadata">

**Author:** [@jeevan1205](https://community.influxdata.com/u/jeevan1205)\
**Replies:** 4\
**Last updated:** [February 3, 2022, 6:53pm UTC](https://community.influxdata.com/t/grok-pattern-for-telegraf/23681 "2022-02-03T18:53:23Z")

</div>

I have 2 log entries as below: 2022-02-02 14:09:37 109535 10.0.0.0 TCP\_TUNNEL/200 2428 CONNECT abc.ca:443 - HIER\_DIRECT/45.60.12.23 - 2022-02-02 14:09:57 4200 10.0.0.1 TCP\_TUNNEL/200 1048 CONNECT abc1.com:443 - HI…

---

## [Telegraf is not reading Nginx access log file data](https://community.influxdata.com/t/telegraf-is-not-reading-nginx-access-log-file-data/23079)

<div class="topic-metadata">

**Author:** [@manashwi](https://community.influxdata.com/u/manashwi)\
**Replies:** 5\
**Last updated:** [December 23, 2021, 2:24pm UTC](https://community.influxdata.com/t/telegraf-is-not-reading-nginx-access-log-file-data/23079 "2021-12-23T14:24:10Z")

</div>

Telegraf is not reading Nginx access log file data. Below is the Telegraf plugin configuration. \[\[inputs.tail\]\] files = \["/var/log/nginx/access.log"\] from\_beginning = false grok\_patterns = \["%{IP:client\_ip} .\* %{CUS…

---

## [Apache Log with Tail Plugin and Grok Format](https://community.influxdata.com/t/apache-log-with-tail-plugin-and-grok-format/22528)

<div class="topic-metadata">

**Author:** [@Black\_file](https://community.influxdata.com/u/Black_file)\
**Replies:** 2\
**Last updated:** [November 16, 2021, 11:22am UTC](https://community.influxdata.com/t/apache-log-with-tail-plugin-and-grok-format/22528 "2021-11-16T11:22:45Z")

</div>

Hello, I have a project where I would like to get the latency per page, the number of exceptions and the web traffic. I’ve been stuck on this for 2 weeks already, I installed telegraf on the Apache machine with the Tail…

---

## [Telegraf file-input custom grok pattern timestamp and line breaks](https://community.influxdata.com/t/telegraf-file-input-custom-grok-pattern-timestamp-and-line-breaks/22072)

<div class="topic-metadata">

**Author:** [@astrakid](https://community.influxdata.com/u/astrakid)\
**Replies:** 8\
**Last updated:** [October 29, 2021, 5:49am UTC](https://community.influxdata.com/t/telegraf-file-input-custom-grok-pattern-timestamp-and-line-breaks/22072 "2021-10-29T05:49:57Z")

</div>

hi, i am trying to work with grok, but i am failing. my need: parse frequently a file, which is written newly (so no “tail” needed). within this file i use grok pattern to extract informations. the file is structure…

---

## [Telegraf file plugin with utf-16 le bom and grok not working](https://community.influxdata.com/t/telegraf-file-plugin-with-utf-16-le-bom-and-grok-not-working/21944)

<div class="topic-metadata">

**Author:** [@astrakid](https://community.influxdata.com/u/astrakid)\
**Replies:** 6\
**Last updated:** [October 6, 2021, 5:06pm UTC](https://community.influxdata.com/t/telegraf-file-plugin-with-utf-16-le-bom-and-grok-not-working/21944 "2021-10-06T17:06:53Z")

</div>

hi, i configured telegraf to parse some files with grok. it works fine, but when the files are encoded in utf16-le-bom i am not able to parse them: 2021-10-04T16:10:06Z I! Starting Telegraf 1.19.2 2021-10-04T16:10:06Z …

---

## [Sending data from log file to influx with tail plugin](https://community.influxdata.com/t/sending-data-from-log-file-to-influx-with-tail-plugin/21367)

<div class="topic-metadata">

**Author:** [@Splotsch](https://community.influxdata.com/u/Splotsch)\
**Replies:** 0\
**Last updated:** [August 24, 2021, 4:23pm UTC](https://community.influxdata.com/t/sending-data-from-log-file-to-influx-with-tail-plugin/21367 "2021-08-24T16:23:40Z")

</div>

I’m trying to use the tail-plugin in telegraf to read data from a log file and push it into influxdb. The logfile only contains temperature values that are created by an arduino, and would look like this: 23,4 23,5 2…
