# Error parsing logs Filebeat - APACHE module

**URL:** <https://discuss.elastic.co/t/error-parsing-logs-filebeat-apache-module/272889>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 13, 2021, 7:58am UTC](https://discuss.elastic.co/t/error-parsing-logs-filebeat-apache-module/272889 "2021-05-13T07:58:35Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![marti1](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@marti1](https://discuss.elastic.co/u/marti1)\
**Post date:** [May 13, 2021, 7:58am UTC](https://discuss.elastic.co/t/error-parsing-logs-filebeat-apache-module/272889/1 "2021-05-13T07:58:35Z")

</div>

Hi everyone,

I have configured my Apache server with Filebeat apache module to load ACCESS and ERROR logs to Elasticsearch but is not working properly, all the logs are not parsed (are raw). This is my configuration:

`Apache Server Logs -> Filebeat -> Kafka -> Logstash -> Elasticsearch`

When I connect my Filebeat directly to Elasticsearch that problem disappears and all the logs are parsed correctly.

`Apache Server Logs -> Elasticsearch`

Why? How can I configure my Filebeat to work well with Kafka?

Thanks

---

<div class="post-metadata">

**Author:** ![marti1](https://avatars.discourse-cdn.com/v4/letter/m/6bbea6/32.png) [@marti1](https://discuss.elastic.co/u/marti1)\
**Post date:** [May 13, 2021, 10:44am UTC](https://discuss.elastic.co/t/error-parsing-logs-filebeat-apache-module/272889/2 "2021-05-13T10:44:10Z")

</div>

SOLUTION:

To load pipelines to elasticsearch you must add this **[pipline]** option into the logstash output:

```auto
output {
  if [@metadata][pipeline] {
    elasticsearch {
      hosts => "https://myEShost:9200"
      manage_template => false
      index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
      pipeline => "%{[@metadata][pipeline]}" 
      user => "elastic"
      password => "secret"
    }
  } else {
    elasticsearch {
      hosts => "https://myEShost:9200"
      manage_template => false
      index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
      user => "elastic"
      password => "secret"
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 10, 2021, 12:45pm UTC](https://discuss.elastic.co/t/error-parsing-logs-filebeat-apache-module/272889/3 "2021-06-10T12:45:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
