# Apache.log example

**URL:** <https://discuss.elastic.co/t/apache-log-example/41960>\
**Category:** Logstash\
**Created:** [February 17, 2016, 2:29am UTC](https://discuss.elastic.co/t/apache-log-example/41960 "2016-02-17T02:29:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![w0lverine](https://avatars.discourse-cdn.com/v4/letter/w/90db22/32.png) [@w0lverine](https://discuss.elastic.co/u/w0lverine)\
**Post date:** [February 17, 2016, 2:29am UTC](https://discuss.elastic.co/t/apache-log-example/41960/1 "2016-02-17T02:29:16Z")

</div>

I am trying to have logstash parse through the apache log example. I have randomly succeeded in creating a logstash-$DATE stamp with the example "here and there" and when I do get the logstash-$DATE index it says “no such index” in debug node.

The step are:

Apache log is downloaded to the following folder:` /home/suricata/logs`  
My first-pipeline.conf is:

> input {  
> file {  
> path =\> "/home/suricata/logs/logstash-tutorial.log"  
> start\_position =\> beginning  
> }  
> }

> filter {  
> grok {  
> match =\> { "message" =\> "%{COMBINEDAPACHELOG}"}  
> }   
> }   
> output {  
> elasticsearch {}  
> stdout {}  
> }

I run the following command:

> root@elk:/etc/logstash/conf.d# /opt/logstash/bin/logstash -f first-pipeline.conf  
> Settings: Default pipeline workers: 2  
> Logstash startup completed  
> ^CSIGINT received. Shutting down the pipeline. {:level=\>:warn}  
> Logstash shutdown completed

In debug mode: I get a bunch of "adding patterns" and "replacement\_patterns" short example:

> Grok compiled OK {:pattern=\>"%{COMBINEDAPACHELOG}", :expanded\_pattern=\>"(?:(?:(?IPORHOST:clientip(?:(?:(?:(?:((([0-9A-Fa-f]{1,4}:

And before this example I get the following:  
Indices status:

> root@elk:/etc/logstash/conf.d# curl -XGET 'localhost:9200/\_cat/indices?v'  
> health status index pri rep docs.count docs.deleted store.size pri.store.size  
> yellow open alerts 5 1 0 0 795b 795b  
> yellow open logstash-2016.02.17 5 1 2 0 8.4kb 8.4kb  
> yellow open logstash-2016.02.15 5 1 1 0 4.7kb 4.7kb  
> yellow open .kibana 1 1 2 0 8.2kb 8.2kb

The two logstash index are not from this output.  
When I run the:

> curl -XGET 'localhost:9200/logstash-2016.02.17/\_search?q=response=200'  
> {"took":1,"timed\_out":false,"\_shards":{"total":5,"successful":5,"failed":0},"hits":{"total":0,"max\_score":null,"hits":}}

But I do have a losgstash-2016.02.17 index...  
Any suggestions on what I am doing wrong? I pretty much tore this problem apart and I hit a dead end.

Troubleshooting:  
-No extra .since238402394830989 file is located in the home directory.  
-ES & logstash services is up and running  
-Configuration file is right  
-I have been able to do a stdin and stdout logstash example  
-Nodes are yellow but are running(probably because I have one node)  
Errors:  
-Index logstash does not exist even though the indices says they do.  
-I do not get a "pretty font" when I have an output.  
-reponse=200 is wrong

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 17, 2016, 4:45am UTC](https://discuss.elastic.co/t/apache-log-example/41960/2 "2016-02-17T04:45:55Z")

</div>

Logstash is probably tailing your file and waiting for more data. Delete the sincedb file that's used (see the log for its exact location) or set `sincedb_path => "/dev/null"` for the file input.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:11am UTC](https://discuss.elastic.co/t/apache-log-example/41960/3 "2017-07-06T05:11:06Z")

</div>


