# Clarification on log format used by Elastic's NGINX Integration

**URL:** <https://discuss.elastic.co/t/clarification-on-log-format-used-by-elastics-nginx-integration/374586>\
**Category:** Logs\
**Created:** [February 15, 2025, 10:47am UTC](https://discuss.elastic.co/t/clarification-on-log-format-used-by-elastics-nginx-integration/374586 "2025-02-15T10:47:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [February 15, 2025, 10:47am UTC](https://discuss.elastic.co/t/clarification-on-log-format-used-by-elastics-nginx-integration/374586/1 "2025-02-15T10:47:13Z")

</div>

Hi,

I'm currently utilizing Elastic's NGINX integration to collect and analyze my server logs. Could someone clarify which log format this integration expects by default? Is it compatible with NGINX's default "combined" log format, or does it require a specific custom format?

Thank you!

---

<div class="post-metadata">

**Author:** ![ahmed\_charafouddine](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ahmed_charafouddine/32/45129_2.png) [@ahmed\_charafouddine](https://discuss.elastic.co/u/ahmed_charafouddine)\
**Post date:** [February 15, 2025, 12:24pm UTC](https://discuss.elastic.co/t/clarification-on-log-format-used-by-elastics-nginx-integration/374586/2 "2025-02-15T12:24:58Z")

</div>

As mentioned in the Nginx integration overview:

_The Nginx integration allows you to monitor [Nginx](https://nginx.org/) servers. Time series [index mode](https://www.elastic.co/guide/en/elasticsearch/reference/current/tsds.html) enabled for metrics data stream._

_Use the Nginx integration to collect metrics and logs from your server. Then visualize that data in Kibana, use the Machine Learning app to find unusual activity in HTTP access logs, create alerts to notify you if something goes wrong, and reference data when troubleshooting an issue._

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 15, 2025, 3:48pm UTC](https://discuss.elastic.co/t/clarification-on-log-format-used-by-elastics-nginx-integration/374586/3 "2025-02-15T15:48:28Z")

</div>

Hi @yago82

> [@yago82](#):
>
> with NGINX's default "combined" log format

Yes should support standard combined format. Is this not your experience?

Here is detailed information

> **[integrations/packages/nginx at main · elastic/integrations](https://github.com/elastic/integrations/tree/main/packages/nginx)**
>
> Contribute to elastic/integrations development by creating an account on GitHub.

---

<div class="post-metadata">

**Author:** ![yago82](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yago82/32/97755_2.png) [@yago82](https://discuss.elastic.co/u/yago82)\
**Post date:** [February 18, 2025, 10:51am UTC](https://discuss.elastic.co/t/clarification-on-log-format-used-by-elastics-nginx-integration/374586/4 "2025-02-18T10:51:01Z")

</div>

Hi Stephen,

Thank you for the information and documentation. I just need to test it now because, unless I missed it, I don't see a reference to the default or combined log format. Unfortunately, the examples also lack `event.original`, which would have been useful as a reference. It might be helpful to have a clear mention of the tested log format in the documentation—again, unless I overlooked it.

Thanks again!

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 18, 2025, 11:42am UTC](https://discuss.elastic.co/t/clarification-on-log-format-used-by-elastics-nginx-integration/374586/5 "2025-02-18T11:42:44Z")

</div>

The logs useds in the tests for integration are in the Github repository.

For example, the access logs for Ningx will be [here](https://github.com/elastic/integrations/tree/main/packages/nginx/data_stream/access/_dev/test/pipeline).

You have the raw logs examples and the expected output.
