# Apache2 SSL log Parsing Issue

**URL:** <https://discuss.elastic.co/t/apache2-ssl-log-parsing-issue/144588>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 15, 2018, 9:47pm UTC](https://discuss.elastic.co/t/apache2-ssl-log-parsing-issue/144588 "2018-08-15T21:47:24Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![AlexB](https://avatars.discourse-cdn.com/v4/letter/a/ecc23a/32.png) [@AlexB](https://discuss.elastic.co/u/AlexB)\
**Post date:** [August 15, 2018, 9:47pm UTC](https://discuss.elastic.co/t/apache2-ssl-log-parsing-issue/144588/1 "2018-08-15T21:47:24Z")

</div>

I'm using Filebeat to push Apache2 logs directly to Elasticsearch but I'm getting an error "Provided Grok expressions do not match field value:" when I try to add ssl\_request\_log file with two newly defined fields.

I've added the Grok pattern to the default.json injest in the apache2 module. I've added the two new SSL fields that didn't exist to the index. The expression works inside the Grok Debugger.

The json pattern is:

```
%{IPORHOST:apache2.access.remote_ip} \\[%{HTTPDATE:apache2.access.time}\\] %{DATA:apache2.access.ssl_protocol} %{DATA:apache2.access.ssl_cipher} %{WORD:apache2.access.method} %{DATA:apache2.access.url} HTTP/%{NUMBER:apache2.access.http_version} (?:%{NUMBER:apache2.access.body_sent.bytes}|-)

```

The sample data is:

```
10.10.75.120 [15/Aug/2018:16:16:06 -0400] TLSv1.2 ECDHE-RSA-AES128-GCM-SHA256 GET /wp-content/plugins/awesome-weather/awesome-weather.css?ver=4.9.8 HTTP/1.1 -

```

 ![33%20PM](https://us1.discourse-cdn.com/elastic/original/3X/6/b/6be358e69e8576d5ed5a756e2803030a994821a7.png)

But it's not parsing the message. The only difference between the \[\] in the json and single backslash in the Grok Pattern. The default Apache2 json patterns are almost identical except for the two new fields I added to the index apache2.access.ssl\_cipher and apache2.access.ssl\_protocol.

I'm guessing I didn't add the fields properly to the index?

Edit: I tried removing the two custom ssl fields from the log and still get the same error.

Thanks for any suggestions!

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [August 16, 2018, 6:49am UTC](https://discuss.elastic.co/t/apache2-ssl-log-parsing-issue/144588/2 "2018-08-16T06:49:03Z")

</div>

Are you sure Apache pipeline is updated on Elasticsearch? By default Filebeat does not update Ingest pipelines if they already exist. You can force reloading the pipeline by running `./filebeat setup --pipelines -modules=apache2`.

---

<div class="post-metadata">

**Author:** ![AlexB](https://avatars.discourse-cdn.com/v4/letter/a/ecc23a/32.png) [@AlexB](https://discuss.elastic.co/u/AlexB)\
**Post date:** [August 16, 2018, 11:55am UTC](https://discuss.elastic.co/t/apache2-ssl-log-parsing-issue/144588/3 "2018-08-16T11:55:31Z")

</div>

Thank you!! That solved it. Once the pipeline was updated it parsed on the first try.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 13, 2018, 11:55am UTC](https://discuss.elastic.co/t/apache2-ssl-log-parsing-issue/144588/4 "2018-09-13T11:55:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
