# Configuration if \[path\] =~ "access" not working

**URL:** <https://discuss.elastic.co/t/configuration-if-path-access-not-working/197570>\
**Category:** Logstash\
**Created:** [August 30, 2019, 6:51pm UTC](https://discuss.elastic.co/t/configuration-if-path-access-not-working/197570 "2019-08-30T18:51:41Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Senthil\_ak](https://avatars.discourse-cdn.com/v4/letter/s/eb9ed0/32.png) [@Senthil\_ak](https://discuss.elastic.co/u/Senthil_ak)\
**Post date:** [August 30, 2019, 6:51pm UTC](https://discuss.elastic.co/t/configuration-if-path-access-not-working/197570/1 "2019-08-30T18:51:41Z")

</div>

Hi Team,  
I am trying to filter apache logs messages, but its always goes to random\_logs than the apache\_access or apache\_error. When i tried to run as adhoc its parsing properly.

```
# Logstash configuration
# Beats -> Logstash -> Elasticsearch pipeline.

input {
  beats {
    port => 5044
  }
}
#-------------------------------------------------------------------------------
# Apache log filter
#-------------------------------------------------------------------------------
filter {
  if [path] =~ "access" {
    mutate { replace => { type => "apache_access" } }
    grok {
      match => { "message" => "%{COMBINEDAPACHELOG}" }
    }
    date {
      match => ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]
    }
  } else if [path] =~ "error" {
    mutate { replace => { type => "apache_error" } }
  } else {
    mutate { replace => { type => "random_logs" } }
  }
}
#-------------------------------------------------------------------------------
# Sys log filter
#-------------------------------------------------------------------------------
filter {
  if [type] == "syslog" {
    grok {
      match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
      add_field => ["received_at", "%{@timestamp}"]
      add_field => ["received_from", "%{host}"]
    }
    date {
      match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
    }
  }
}
#-------------------------------------------------------------------------------
output {
  if [@metadata][pipeline] {
    elasticsearch {
      hosts => ["http://xxx.xxx.xxx.xx:9200","http://xxx.xxx.xxx.xx:9200","http://xxx.xxx.xxx.xx:9200"]
      manage_template => false
      index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
      pipeline => "%{[@metadata][pipeline]}"
    }
  } else {
    elasticsearch {
      hosts => ["http://xxx.xxx.xxx.xx:9200","http://xxx.xxx.xxx.xx:9200","http://xxx.xxx.xxx.xx:9200"]
      manage_template => false
      index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
    }
  }
}
#-------------------------------------------------------------------------------

```

My log file path is having log path like below.  
/apps/nginx/logs/access.log  
/apps/\*/access\_ssl.log

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 30, 2019, 7:11pm UTC](https://discuss.elastic.co/t/configuration-if-path-access-not-working/197570/2 "2019-08-30T19:11:26Z")

</div>

If you are using filebeat I would expect the filename to be in [log][file][path] rather than [path]

---

<div class="post-metadata">

**Author:** ![Senthil\_ak](https://avatars.discourse-cdn.com/v4/letter/s/eb9ed0/32.png) [@Senthil\_ak](https://discuss.elastic.co/u/Senthil_ak)\
**Post date:** [September 4, 2019, 5:01pm UTC](https://discuss.elastic.co/t/configuration-if-path-access-not-working/197570/3 "2019-09-04T17:01:26Z")

</div>

sorry for the late response, its working perfectly now. But the only issue i have is nginx access.logs also moved as apache\_access type. Is there any way to separate that ? nginx path will be /apps/logs/nginx/access.logs

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 4, 2019, 6:16pm UTC](https://discuss.elastic.co/t/configuration-if-path-access-not-working/197570/4 "2019-09-04T18:16:41Z")

</div>

> [@Senthil\_ak](#):
>
> if [path] =~ "access" { mutate { replace =\> { type =\> "apache\_access" } }

Something like

```
if [path] =~ "nginx/access" {
    mutate { replace => { type => "nginx_access" } }
 } else if [path] =~ "access" {
    mutate { replace => { type => "apache_access" } }
 [...]

```

---

<div class="post-metadata">

**Author:** ![Senthil\_ak](https://avatars.discourse-cdn.com/v4/letter/s/eb9ed0/32.png) [@Senthil\_ak](https://discuss.elastic.co/u/Senthil_ak)\
**Post date:** [September 4, 2019, 7:53pm UTC](https://discuss.elastic.co/t/configuration-if-path-access-not-working/197570/5 "2019-09-04T19:53:28Z")

</div>

I gave like below and its putting the nginx logs properly under nginx\_access

```
filter {
  if [log][file][path] =~ "nginx/logs/access" {
    mutate { replace => { type => "nginx_access" } }
  } else if [log][file][path] =~ "access" {
    mutate { replace => { type => "apache_access" } }
    grok {
      match => { "message" => "%{COMBINEDAPACHELOG}" }
    }
    date {
      match => ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]
    }
  } else if [log][file][path] =~ "error" {
    mutate { replace => { type => "apache_error" } }
  } else {
    mutate { replace => { type => "random_logs" } }
  }
}

```

Is it \* will be acceptable in the path check ?

`else if [log][file][path] =~ "/apps/*/logs/*/access"`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 4, 2019, 8:22pm UTC](https://discuss.elastic.co/t/configuration-if-path-access-not-working/197570/6 "2019-09-04T20:22:46Z")

</div>

It's doing a regexp match, so \* means zero or more of the preceding character or class. So `"/apps/*/logs/*/access"` would match `"/apps///logs/access"`.

You want `"/apps/.*/logs/.*/access"`

---

<div class="post-metadata">

**Author:** ![Senthil\_ak](https://avatars.discourse-cdn.com/v4/letter/s/eb9ed0/32.png) [@Senthil\_ak](https://discuss.elastic.co/u/Senthil_ak)\
**Post date:** [September 5, 2019, 12:59pm UTC](https://discuss.elastic.co/t/configuration-if-path-access-not-working/197570/7 "2019-09-05T12:59:44Z")

</div>

Thanks we can close the topic now.

I am using below config which works perfectly.

```auto
filter {
  if [log][file][path] =~ "nginx/logs/access" {
    mutate { replace => { type => "nginx_access" } }
  } else if [log][file][path] =~ "nginx/logs/error" {
    mutate { replace => { type => "nginx_error" } }
  } else if [log][file][path] =~ "apps/.*/logs/.*/access" {
    mutate { replace => { type => "apache_access" } }
    grok {
      match => { "message" => "%{COMBINEDAPACHELOG}" }
    }
    date {
      match => ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]
    }
  } else if [log][file][path] =~ "apps/.*/logs/.*/error" {
    mutate { replace => { type => "apache_error" } }
  } else {
    mutate { replace => { type => "random_logs" } }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 3, 2019, 12:59pm UTC](https://discuss.elastic.co/t/configuration-if-path-access-not-working/197570/8 "2019-10-03T12:59:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
