# Debug code of file config to get log

**URL:** <https://discuss.elastic.co/t/debug-code-of-file-config-to-get-log/45573>\
**Category:** Logstash\
**Created:** [March 28, 2016, 9:46am UTC](https://discuss.elastic.co/t/debug-code-of-file-config-to-get-log/45573 "2016-03-28T09:46:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Inbeo\_Beo](https://avatars.discourse-cdn.com/v4/letter/i/d78d45/32.png) [@Inbeo\_Beo](https://discuss.elastic.co/u/Inbeo_Beo)\
**Post date:** [March 28, 2016, 9:46am UTC](https://discuss.elastic.co/t/debug-code-of-file-config-to-get-log/45573/1 "2016-03-28T09:46:15Z")

</div>

Hi all

I make a file config to get log from apache.

input {  
file{  
type =\> "apache-access"  
path =\> " /var/log/logstash/apache.log"  
start\_position =\> "beginning"  
}  
}

filter {

```
if "% Apache-" in [message]{
    mutate {
    add_tag => ["apache"]
    }

grok {

    match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program} (?\[POSINT:syslog_pid}\]?: %{GREEDYDATA:syslog_message}"]
    add_field => ["received_at","%{@timestamp}"]

    add_field => ["received_from", "%{host}"]

```

}

}

date {

```
    match => ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]

```

}  
}

output {  
elasticsearch { hosts =\> localhost}  
}  
stdout { codec =\> rubydebug }  
}

After that, i check it though command below:

/opt/logstash/bin/logstash –configtest -f /etc/logstash/conf.d/logstash\_getlog\_config.conf

It recomment me some error in there, however i can't fix them..

Could you check and show me what is my mistake and how can i fix it?

Regds

---

<div class="post-metadata">

**Author:** ![kirill\_polishchuk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kirill_polishchuk/32/6489_2.png) [@kirill\_polishchuk](https://discuss.elastic.co/u/kirill_polishchuk)\
**Post date:** [March 28, 2016, 5:04pm UTC](https://discuss.elastic.co/t/debug-code-of-file-config-to-get-log/45573/2 "2016-03-28T17:04:20Z")

</div>

hello

There were 2 mistakes in your config:

1. in filter =\> grok =\> match
2. in the output

Check out a correct config below:

```
input {
	file{
		type => "apache-access"
		path => " /var/log/logstash/apache.log"
		start_position => "beginning"
	}
}

filter {

	if "% Apache-" in [message]{
    	mutate {
    		add_tag => ["apache"]
    	}

		grok {

    		match =>["message", "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program} (?\[%{POSINT:syslog_pid}\]?: %{GREEDYDATA:syslog_message}"]
    		add_field => ["received_at","%{@timestamp}"]
    		add_field => ["received_from", "%{host}"]
		}

	}

	date {

    	match => ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]
	}	
}

output {
	elasticsearch { host => localhost}
	stdout { codec => rubydebug }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:05am UTC](https://discuss.elastic.co/t/debug-code-of-file-config-to-get-log/45573/3 "2017-07-06T05:05:09Z")

</div>


