# Access custom fields on nginx from logstash

**URL:** <https://discuss.elastic.co/t/access-custom-fields-on-nginx-from-logstash/139119>\
**Category:** Logstash\
**Created:** [July 9, 2018, 9:20am UTC](https://discuss.elastic.co/t/access-custom-fields-on-nginx-from-logstash/139119 "2018-07-09T09:20:02Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jonghun\_Park1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jonghun_park1/32/20893_2.png) [@Jonghun\_Park1](https://discuss.elastic.co/u/Jonghun_Park1)\
**Post date:** [July 9, 2018, 9:20am UTC](https://discuss.elastic.co/t/access-custom-fields-on-nginx-from-logstash/139119/1 "2018-07-09T09:20:03Z")

</div>

I've wrote a nginx log\_format as below.

**log\_format main '$http\_host $remote\_addr - $remote\_user [$time\_local] "$request" $status $body\_bytes\_sent "$http\_referer" "$http\_user\_agent" "$http\_x\_forwarded\_for" "$http\_user\_browser\_language" $sent\_http\_sv\_il $sent\_http\_sv\_cid $sent\_http\_sv\_uid "User-Time-Zone=$http\_User\_Time\_Zone"';**

And I want to filter message for $sent\_http\_sv\_il and $sent\_http\_sv\_cid, $sent\_http\_sv\_uid from Logstash for getting informations more details.

I tried to grok filter as below.

**add\_field =\> { "sv\_cid" =\> "%{sent\_http\_sv\_cid}" "sv\_uid" =\> "%{sent\_http\_sv\_uid}"}**

the result of them as below

**"sv\_uid": "%{sent\_http\_sv\_uid}"**

what's the missing?  
anyone who answer me the way?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 9, 2018, 11:55am UTC](https://discuss.elastic.co/t/access-custom-fields-on-nginx-from-logstash/139119/2 "2018-07-09T11:55:19Z")

</div>

You need to adjust the grok expression you use to also extract the new fields. If you show us your current grok expression we can give more specific advice.

---

<div class="post-metadata">

**Author:** ![Jonghun\_Park1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jonghun_park1/32/20893_2.png) [@Jonghun\_Park1](https://discuss.elastic.co/u/Jonghun_Park1)\
**Post date:** [July 10, 2018, 1:06am UTC](https://discuss.elastic.co/t/access-custom-fields-on-nginx-from-logstash/139119/3 "2018-07-10T01:06:01Z")

</div>

I'm very appreciate for your reply.

it is our current grok expression shown below.

grok {  
match =\> { "message" =\> ["%{IPORHOST:[nginx][access][remote\_ip]} - %{DATA:[nginx][access][user\_name]} [%{HTTPDATE:[nginx][access][time]}] "%{WORD:[nginx][access][method]} %{DATA:[nginx][access][url]} HTTP/%{NUMBER:[nginx][access][http\_version]}" %{NUMBER:[nginx][access][response\_code]} %{NUMBER:[nginx][access][body\_sent][bytes]} "%{DATA:[nginx][access][agent]}" "%{IPORHOST:[nginx][access][remote\_ip\_list]}""] }  
remove\_field =\> "message"  
add\_field =\> { "sv\_cid" =\> "%{NUMBER:[nginx][access][sent\_http\_sv\_uid]}" "sv\_uid" =\> "%{sent\_http\_sv\_uid}" }  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 10, 2018, 1:34pm UTC](https://discuss.elastic.co/t/access-custom-fields-on-nginx-from-logstash/139119/4 "2018-07-10T13:34:05Z")

</div>

Okay, so your current grok expression only covers up to and including `"$http_x_forwarded_for"`. After that you have `"$http_user_browser_language" $sent_http_sv_il $sent_http_sv_cid $sent_http_sv_uid` so you need to append something like

```
%{QS} %{NOTSPACE} %{NOTSPACE} %{NOTSPACE:sv_cid} %{NOTSPACE:sv_uid}

```

to capture the additional fields you're interested in.

---

<div class="post-metadata">

**Author:** ![Jonghun\_Park1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jonghun_park1/32/20893_2.png) [@Jonghun\_Park1](https://discuss.elastic.co/u/Jonghun_Park1)\
**Post date:** [July 11, 2018, 2:30am UTC](https://discuss.elastic.co/t/access-custom-fields-on-nginx-from-logstash/139119/5 "2018-07-11T02:30:44Z")

</div>

awesome!

it works as intended.  
And I'm very appreciate for your help!!

best regards.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 8, 2018, 2:37am UTC](https://discuss.elastic.co/t/access-custom-fields-on-nginx-from-logstash/139119/6 "2018-08-08T02:37:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
