# Elastic Common Schema for website domain

**URL:** <https://discuss.elastic.co/t/elastic-common-schema-for-website-domain/199383>\
**Category:** Logstash\
**Tags:** ecs-elastic-common-schema\
**Created:** [September 13, 2019, 7:58am UTC](https://discuss.elastic.co/t/elastic-common-schema-for-website-domain/199383 "2019-09-13T07:58:21Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![webmat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/webmat/32/46191_2.png) [@webmat](https://discuss.elastic.co/u/webmat)\
**Post date:** [November 29, 2019, 3:37pm UTC](https://discuss.elastic.co/t/elastic-common-schema-for-website-domain/199383/3 "2019-11-29T15:37:38Z")

</div>

By default, web server logs don't include the vhost. But yes, if you want to distinguish traffic from different vhosts, make sure to add it to your logs (or produce distinct logs per vhost).

Next I assume you're already breaking down your http traffic between the [http](https://www.elastic.co/guide/en/ecs/current/ecs-http.html) and [url](https://www.elastic.co/guide/en/ecs/current/ecs-url.html) field sets.

Trivial (and incomplete) example document:

```auto
{ "http": { "method": "get", "status_code": 200, ...}
  "url": { "path": "/assets/stylesheet.css", "domain": "www.example.com", ...}
}

```

So `url.domain` would be my recommendation 🙂

Check this out as well [Parsing URL with Logstash (using ECS fields) nested!](https://discuss.elastic.co/t/parsing-url-with-logstash-using-ecs-fields-nested/209953)

---

_[View the full topic](https://discuss.elastic.co/t/elastic-common-schema-for-website-domain/199383)._
