# COMBINEDAPACHELOG did not add any matched fileds?

**URL:** <https://discuss.elastic.co/t/combinedapachelog-did-not-add-any-matched-fileds/66791>\
**Category:** Logstash\
**Created:** [November 21, 2016, 10:06pm UTC](https://discuss.elastic.co/t/combinedapachelog-did-not-add-any-matched-fileds/66791 "2016-11-21T22:06:48Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![robertchen117](https://avatars.discourse-cdn.com/v4/letter/r/edb3f5/32.png) [@robertchen117](https://discuss.elastic.co/u/robertchen117)\
**Post date:** [November 21, 2016, 10:06pm UTC](https://discuss.elastic.co/t/combinedapachelog-did-not-add-any-matched-fileds/66791/1 "2016-11-21T22:06:48Z")

</div>

my logstash filter rule is like:

if [type] == "apache" {  
grok {  
match =\> ["message", "%{COMBINEDAPACHELOG}"]  
match =\> ["message", "%{HTTPD20\_ERRORLOG}"]  
}  
}

COMBINEDAPACHELOG did not add any matched fileds, or it did not get \_grokparsefailure.  
Please see the captured screen:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/1/153368b8caf533bbd6d3210fb8df8b178b651dc2.PNG)

---

<div class="post-metadata">

**Author:** ![robertchen117](https://avatars.discourse-cdn.com/v4/letter/r/edb3f5/32.png) [@robertchen117](https://discuss.elastic.co/u/robertchen117)\
**Post date:** [November 21, 2016, 10:23pm UTC](https://discuss.elastic.co/t/combinedapachelog-did-not-add-any-matched-fileds/66791/2 "2016-11-21T22:23:21Z")

</div>

if I replace COMBINEDAPACHELOG with the below it works, why?:

if [type] == "apache" {  
grok {  
match =\> ["message", "%{IPORHOST:clientip} %{HTTPDUSER:ident} %{USER:auth} [%{HTTPDATE:timestamp}] "(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})" %{NUMBER:response} (?:%{NUMBER:bytes}|-)"]  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 22, 2016, 6:45am UTC](https://discuss.elastic.co/t/combinedapachelog-did-not-add-any-matched-fileds/66791/3 "2016-11-22T06:45:21Z")

</div>

Please do not post Kibana screenshots. Copy/paste from the JSON tab in Kibana instead, or use a `stdout { codec => rubydebug }` output in Logstash.

Your log isn't a combined log so COMBINEDAPACHELOG doesn't match and you're getting a `_grokparsefailure` tag as a result. The grok expression you replaced COMBINEDAPACHELOG with matches common log files which is the format of your log.

---

<div class="post-metadata">

**Author:** ![robertchen117](https://avatars.discourse-cdn.com/v4/letter/r/edb3f5/32.png) [@robertchen117](https://discuss.elastic.co/u/robertchen117)\
**Post date:** [November 22, 2016, 2:41pm UTC](https://discuss.elastic.co/t/combinedapachelog-did-not-add-any-matched-fileds/66791/4 "2016-11-22T14:41:24Z")

</div>

> [@robertchen117](#):
>
> "%{IPORHOST:clientip} %{HTTPDUSER:ident} %{USER:auth} [%{HTTPDATE:timestamp}] "(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})" %{NUMBER:response} (?:%{NUMBER:bytes}|-)"]

This are copied from COMBINEDAPACHELOG, this matches, but not the COMBINEDAPACHELOG

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 22, 2016, 2:52pm UTC](https://discuss.elastic.co/t/combinedapachelog-did-not-add-any-matched-fileds/66791/5 "2016-11-22T14:52:07Z")

</div>

You have match specified twice in the same grok block for the same field. I believe the correct way to match multiple patterns against the same field is to [configure an array](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html#plugins-filters-grok-match). Try something like this:

```
grok {
  match => { "message" => ["%{COMBINEDAPACHELOG}", "%{HTTPD20_ERRORLOG}"] }
}
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 22, 2016, 8:37pm UTC](https://discuss.elastic.co/t/combinedapachelog-did-not-add-any-matched-fileds/66791/6 "2016-11-22T20:37:00Z")

</div>

> This are copied from COMBINEDAPACHELOG, this matches, but not the COMBINEDAPACHELOG

Please look more carefully. Your expression is copied from COMMONAPACHELOG:

> <https://github.com/logstash-plugins/logstash-patterns-core/blob/v2.0.5/patterns/grok-patterns#L93>

Here's the definition of COMBINEDAPACHELOG:

> <https://github.com/logstash-plugins/logstash-patterns-core/blob/v2.0.5/patterns/grok-patterns#L94>

Your HTTP log is not in combined format. Over and out.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 20, 2016, 8:37pm UTC](https://discuss.elastic.co/t/combinedapachelog-did-not-add-any-matched-fileds/66791/7 "2016-12-20T20:37:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
