# Apache logs missing SSL Protocol

**URL:** <https://discuss.elastic.co/t/apache-logs-missing-ssl-protocol/248070>\
**Category:** Beats\
**Tags:** beats-module, filebeat\
**Created:** [September 9, 2020, 8:45pm UTC](https://discuss.elastic.co/t/apache-logs-missing-ssl-protocol/248070 "2020-09-09T20:45:15Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![prophoto](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Post date:** [September 9, 2020, 8:45pm UTC](https://discuss.elastic.co/t/apache-logs-missing-ssl-protocol/248070/1 "2020-09-09T20:45:15Z")

</div>

Despite SSL Protocol and request time showing in my logformat directive in Apache 2.4 I am not seeing either of them in ES/Kibana. How is this fixed? I am using filebeat and shipping logs directly to ES.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 9, 2020, 11:33pm UTC](https://discuss.elastic.co/t/apache-logs-missing-ssl-protocol/248070/2 "2020-09-09T23:33:26Z")

</div>

Are you using the Filebeat module for this?

---

<div class="post-metadata">

**Author:** ![prophoto](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Post date:** [September 10, 2020, 6:16pm UTC](https://discuss.elastic.co/t/apache-logs-missing-ssl-protocol/248070/3 "2020-09-10T18:16:54Z")

</div>

> [@warkolm](#):
>
> Are you using the Filebeat module for this?

Yess

---

<div class="post-metadata">

**Author:** ![prophoto](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Post date:** [September 14, 2020, 3:11pm UTC](https://discuss.elastic.co/t/apache-logs-missing-ssl-protocol/248070/4 "2020-09-14T15:11:25Z")

</div>

Bump.

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [September 14, 2020, 8:55pm UTC](https://discuss.elastic.co/t/apache-logs-missing-ssl-protocol/248070/5 "2020-09-14T20:55:52Z")

</div>

Hi @prophoto,

Could you please post the following here?

1. A sample log line from your Apache log that's not getting ingested into Elasticsearch as you expect.

2. Your Filebeat `apache` module configuration.

3. Which version of Filebeat you're using.

Thanks,

Shaunak

---

<div class="post-metadata">

**Author:** ![prophoto](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Post date:** [September 16, 2020, 3:36pm UTC](https://discuss.elastic.co/t/apache-logs-missing-ssl-protocol/248070/6 "2020-09-16T15:36:38Z")

</div>

```auto
[centos@server9 ~]$ sudo filebeat version
filebeat version 7.8.0 (amd64), libbeat 7.8.0 [f79387d32717d79f689d94fda1ec80b2cf285d30 built 2020-06-14 18:15:37 +0000 UTC]

```

```auto
www.website.com 114.119.154.211 - - [16/Sep/2020:15:30:10 +0000] "GET /user-profile/jprofilename.html HTTP/1.1" 503 1898 "-" "Mozilla/5.0 (Linux; Android 7.0;) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; PetalBot;+http://aspiegel.com/petalbot)" TLSv1.2 ECDHE-RSA-AES256-GCM-SHA384 9758883 9

```

```auto
[centos@server9 ~]$ sudo cat /etc/filebeat/filebeat.yml
logging.level: info
logging.to_files: true
logging.files:
  path: /var/log/filebeat
  name: filebeat
  keepfiles: 7
  permissions: 0644

filebeat.config.modules:
  enabled: true
  path: /etc/filebeat/modules.d/*.yml

setup.kibana.host: "https://studio.mydomain.com:5601"
setup.kibana.ssl.enabled: true
setup.kibana.ssl.certificate: "studio.crt.pem"
setup.kibana.ssl.key: "studio.key.pem"
setup.kibana.ssl.certificate_authorities: ["studio.crt.pem"]

output.elasticsearch:
  # Array of hosts to connect to.
  hosts: ["studio.mydomain.com:9200"]

  protocol: "https"
  username: "elastic"
  password: "----------------------"
  ssl.certificate: "studio.crt.pem"
  ssl.key: "studio.key.pem"
  ssl.certificate_authorities: ["studio.crt.pem"]

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 14, 2020, 3:36pm UTC](https://discuss.elastic.co/t/apache-logs-missing-ssl-protocol/248070/7 "2020-10-14T15:36:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
