# Basic Apache Filebeat Log question - missing fields

**URL:** <https://discuss.elastic.co/t/basic-apache-filebeat-log-question-missing-fields/213103>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 26, 2019, 4:31pm UTC](https://discuss.elastic.co/t/basic-apache-filebeat-log-question-missing-fields/213103 "2019-12-26T16:31:35Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shorthills](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shorthills/32/60004_2.png) [@Shorthills](https://discuss.elastic.co/u/Shorthills)\
**Post date:** [December 26, 2019, 4:31pm UTC](https://discuss.elastic.co/t/basic-apache-filebeat-log-question-missing-fields/213103/1 "2019-12-26T16:31:35Z")

</div>

Hi,  
Sorry for the newbie question: I'm able to pull in my apache logs and when I try to filter by `apache2.access.response_code` , I get zilch.

I looked and the response code data is in the message from apache.

Is the problem that I'm having because I'm going directly from the filebeat to elastic? And that I need to use logstash in the middle to expose the apache2.access.response\_code parameter? Just want to make sure I'm on the right path.

Thanks!

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [December 26, 2019, 8:49pm UTC](https://discuss.elastic.co/t/basic-apache-filebeat-log-question-missing-fields/213103/2 "2019-12-26T20:49:10Z")

</div>

Hi @Shorthills, welcome to the Elastic community forums!

You should be able to go directly from Filebeat to Elasticsearch for what you're trying to do — ingest Apache logs. Would you mind sharing a few pieces of information to help figure out what's going on?

1. The output of `filebeat version`

2. The output of `filebeat modules list`

3. Your complete `filebeat.yml` file (but please mask out any sensitive information in it before posting).

4. Any errors or warnings in your Filebeat log after starting it up.

5. The output of `GET _cat/indices/filebeat*`, run against your Elasticsearch cluster.

6. The output of `GET _cat/templates/filebeat*`, run against your Elasticsearch cluster.

Thanks,

Shaunak

---

<div class="post-metadata">

**Author:** ![Shorthills](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shorthills/32/60004_2.png) [@Shorthills](https://discuss.elastic.co/u/Shorthills)\
**Post date:** [December 26, 2019, 9:40pm UTC](https://discuss.elastic.co/t/basic-apache-filebeat-log-question-missing-fields/213103/3 "2019-12-26T21:40:21Z")

</div>

1. ilebeat version 7.5.1 (amd64), libbeat 7.5.1 [60dd883ca29e1fdd5b8b075bd5f3698948b1d44d built 2019-12-16 21:56:14 +0000 UTC]

2. Enabled:  
apache

Disabled:  
apache2  
auditd  
aws  
azure  
cef  
cisco  
coredns  
elasticsearch  
envoyproxy  
googlecloud  
haproxy  
ibmmq  
icinga  
iis  
iptables  
kafka  
kibana  
logstash  
misp  
mongodb  
mssql  
mysql  
nats  
netflow  
nginx  
osquery  
panw  
postgresql  
rabbitmq  
redis  
santa  
suricata  
system  
traefik  
zeek

I'm working on getting you the rest 🙂

Thanks!

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [December 27, 2019, 12:50am UTC](https://discuss.elastic.co/t/basic-apache-filebeat-log-question-missing-fields/213103/4 "2019-12-27T00:50:25Z")

</div>

Hi @Shorthills, thanks for reporting the Filebeat version. You will find the response code in `http.response.status_code`. In general, you can find the fields exported by the Filebeat `apache` module here: [https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields-apache.html](https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields-apache.html).

Shaunak

---

<div class="post-metadata">

**Author:** ![Shorthills](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shorthills/32/60004_2.png) [@Shorthills](https://discuss.elastic.co/u/Shorthills)\
**Post date:** [December 27, 2019, 1:59am UTC](https://discuss.elastic.co/t/basic-apache-filebeat-log-question-missing-fields/213103/5 "2019-12-27T01:59:25Z")

</div>

Thank you. I'm not seeing it on the list of my available fields. Does that matter? The issue is that none of these exported fields have data, unless I'm looking in the wrong place. I figured that I'd be able to see the data in the Discover Module. And the logs are there, they're just coming in as Message and not as parsed data (which is why I asked about logstash).

As for my filebeat.yml, it's default except for this change:

1. I didn't want to pull all of the system logs so I pulled apache only.
2. Also, I added the php error logs b/c I do need that reporting

```auto
    # /var/log/*.log
    - /var/log/apache2/error_log
    #- c:\programdata\elasticsearch\logs\*
    - /home/*/logs/*.php.error.log

```

Will the last ```/home/*/...` line affect the apache log parsing? I didn't edit the apache.yml file at all.

And I'm getting the rest of the data.

---

<div class="post-metadata">

**Author:** ![Shorthills](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shorthills/32/60004_2.png) [@Shorthills](https://discuss.elastic.co/u/Shorthills)\
**Post date:** [December 27, 2019, 2:03am UTC](https://discuss.elastic.co/t/basic-apache-filebeat-log-question-missing-fields/213103/6 "2019-12-27T02:03:59Z")

</div>

And is this the info re: indexes and index templates? I think that I created too many indexes b/c every time I adjusted the .yml config file I regenerated the index which I thought was what I had to do (but now I'm thinking that I didn't need to do that). Thanks for your continued help.

 ![2019-12-26_21-02-20](https://us1.discourse-cdn.com/elastic/original/3X/1/5/15ae243419ff404725261e457bdd9bf447cff820.jpeg)

 ![2019-12-26_21-02-49](https://us1.discourse-cdn.com/elastic/original/3X/3/b/3bf0741be160c97565e3793431fef219a2e684b6.jpeg)

---

<div class="post-metadata">

**Author:** ![Shorthills](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shorthills/32/60004_2.png) [@Shorthills](https://discuss.elastic.co/u/Shorthills)\
**Post date:** [December 27, 2019, 2:11am UTC](https://discuss.elastic.co/t/basic-apache-filebeat-log-question-missing-fields/213103/7 "2019-12-27T02:11:02Z")

</div>

And if it helps, the filebeat 6.8.6 index template has the following:

```auto
        "apache2.access.ssl.protocol",
        "apache2.access.ssl.cipher",
        "apache2.access.user_name",
        "apache2.access.method",
        "apache2.access.url",
        "apache2.access.http_version",
        "apache2.access.referrer",
        "apache2.access.agent",
        "apache2.access.user_agent.device",
        "apache2.access.user_agent.patch",
        "apache2.access.user_agent.name",
        "apache2.access.user_agent.os",
        "apache2.access.user_agent.os_name",
        "apache2.access.geoip.continent_name",
        "apache2.access.geoip.country_iso_code",
        "apache2.access.geoip.region_name",
        "apache2.access.geoip.city_name",
        "apache2.access.geoip.region_iso_code",
        "apache2.error.level",
        "apache2.error.client",
        "apache2.error.message",
        "apache2.error.module",

```

but nothing with the `http.` prefix.

===

And these are the only ones listed in the filebeat-7.5.1 template:

```auto
        "http.request.body.content",
        "http.request.method",
        "http.request.referrer",
        "http.response.body.content",
        "http.version",

```

```auto
        "apache.access.ssl.cipher",
        "apache.error.module",

```

====  
Should I be using the Apache2 or the Apache module? I was reading and it seems that I should use the Apache one?

Thx

---

<div class="post-metadata">

**Author:** ![Shorthills](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shorthills/32/60004_2.png) [@Shorthills](https://discuss.elastic.co/u/Shorthills)\
**Post date:** [December 27, 2019, 2:13am UTC](https://discuss.elastic.co/t/basic-apache-filebeat-log-question-missing-fields/213103/8 "2019-12-27T02:13:23Z")

</div>

And on this box I have

`apache.yml` and `apache2.yml.disabled` if that helps.

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [December 27, 2019, 4:10pm UTC](https://discuss.elastic.co/t/basic-apache-filebeat-log-question-missing-fields/213103/9 "2019-12-27T16:10:02Z")

</div>

Can you share your compete `filebeat.yml` and your complete `modules.d/apache.yml` please?

Also, if possible, could you please share a couple of raw lines from your Apache error log (the one you want to parse)?

Thanks,

Shaunak

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 24, 2020, 4:10pm UTC](https://discuss.elastic.co/t/basic-apache-filebeat-log-question-missing-fields/213103/10 "2020-01-24T16:10:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
