# Apache log to logstash and consume content

**URL:** <https://discuss.elastic.co/t/apache-log-to-logstash-and-consume-content/33110>\
**Category:** Logstash\
**Created:** [October 27, 2015, 8:54pm UTC](https://discuss.elastic.co/t/apache-log-to-logstash-and-consume-content/33110 "2015-10-27T20:54:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![steven\_vogogo](https://avatars.discourse-cdn.com/v4/letter/s/cdc98d/32.png) [@steven\_vogogo](https://discuss.elastic.co/u/steven_vogogo)\
**Post date:** [October 27, 2015, 8:54pm UTC](https://discuss.elastic.co/t/apache-log-to-logstash-and-consume-content/33110/1 "2015-10-27T20:54:29Z")

</div>

Hello,

We are using logstash to parse sensitive data from our logs and as a result we need the original logfile (that contains the sensitive data) to not retain any content.

I have tried using a mkfifo and have logstash watch the named pipe file and have apache log to it. This does not work as logstash does not hold the pipe file open, as a result apache fails to start as it cannot log to the file if its not being held open.

I also considered using a syslog input but we have multiple configs for multiple vhosts and as result using a single facility could get complex.

Ideally we want this configuration  
Apache -\> logstash -\> output.log

Can anyone recommend a configuration or logstash input that would allow us to not retain the original unprocessed log data.

Thank you

---

<div class="post-metadata">

**Author:** ![renevdm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/renevdm/32/5730_2.png) [@renevdm](https://discuss.elastic.co/u/renevdm)\
**Post date:** [October 27, 2015, 9:18pm UTC](https://discuss.elastic.co/t/apache-log-to-logstash-and-consume-content/33110/2 "2015-10-27T21:18:04Z")

</div>

I don't really get what you exactly want, but as long as the vhosts are concerned, I wrote a article on my own blog about getting logs from multiple vhosts into Logstash

> **[Apache access logs in Kibana](http://ict.renevdmark.nl/2015/10/20/apache-access-logs-in-kibana/)**
>
> I needed a more convenient way to view my Apache access logs, other than tailing the access logs files on my webserver. Why not use Kibana for this? It not only shows you the access log lines, it a…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:25am UTC](https://discuss.elastic.co/t/apache-log-to-logstash-and-consume-content/33110/3 "2017-07-06T05:25:09Z")

</div>


