# Erros Logstash fields Kibana

**URL:** <https://discuss.elastic.co/t/erros-logstash-fields-kibana/146907>\
**Category:** Logstash\
**Created:** [August 31, 2018, 7:05pm UTC](https://discuss.elastic.co/t/erros-logstash-fields-kibana/146907 "2018-08-31T19:05:25Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![marcos.vbp](https://avatars.discourse-cdn.com/v4/letter/m/c5a1d2/32.png) [@marcos.vbp](https://discuss.elastic.co/u/marcos.vbp)\
**Post date:** [August 31, 2018, 7:05pm UTC](https://discuss.elastic.co/t/erros-logstash-fields-kibana/146907/1 "2018-08-31T19:05:25Z")

</div>

Hello,

I'm try start with ELK, but very dificult for me.

I try read log access.log for weblogic , output exemple is :

172.16.27.211 - - [30/Ago/2018:10:05:41 -0300] "GET /teste/rest/currentUser?noCache=1535634341625 HTTP/1.1" 200 211

in my filter. i try any option ,  
COMMONAPACHELOG, COMBINEDAPACHELOG,HTTPD\_COMBINEDLOG and specific message

match =\> { "message" =\> "%{IP:client} %{USERNAME} %{USERNAME} [%{HTTPDATE:timestamp}] %{WORD:request} %{URIPATHPARAM:path} HTTP/%{NUMBER:version} %{NUMBER:response} %{GREEDYDATA:responseMessage}" }  
}

both always failure in my output

{  
"tags" =\> [  
[0] "\_grokparsefailure"  
],  
"@timestamp" =\> 2018-08-31T18:56:52.725Z,  
"message" =\> "172.16.27.211 - - [31/Ago/2018:15:56:51 -0300] "POST /lmsa/swtbrokerziped HTTP/1.1" 200 312 ",  
"path" =\> "/var/log/weblogic/producao/lms01/access.log",  
"host" =\> "brpoaelk01.mercurio.local",  
"@version" =\> "1",  
"type" =\> "weblogic-access-lms01"  
}

I do not know what to do anymore, none of the alternatives work. with this I can not create the index with the fields that I need

```auto

```

---

<div class="post-metadata">

**Author:** ![Harshad\_Velapure](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harshad_velapure/32/33684_2.png) [@Harshad\_Velapure](https://discuss.elastic.co/u/Harshad_Velapure)\
**Post date:** [August 31, 2018, 10:06pm UTC](https://discuss.elastic.co/t/erros-logstash-fields-kibana/146907/2 "2018-08-31T22:06:29Z")

</div>

Hello,

try below changes

> filter {
> 
> grok {  
> match =\> { message =\> "%{IP:client} %{DATA:USERNAME} %{DATA:USERNAME} \[%{DATA:logtime}\] "%{WORD:request} %{URIPATHPARAM:path} HTTP/%{NUMBER:version}" %{NUMBER:response} %{GREEDYDATA:responseMessage}" }  
> }  
> mutate{  
> gsub =\> ["logtime"," -0300",""]  
> }
> 
> date{  
> match =\> ["logtime","dd/MMM/yyy:HH:mm:ss"]  
> }
> 
> }

in this case logtime is time field

---

<div class="post-metadata">

**Author:** ![marcos.vbp](https://avatars.discourse-cdn.com/v4/letter/m/c5a1d2/32.png) [@marcos.vbp](https://discuss.elastic.co/u/marcos.vbp)\
**Post date:** [September 3, 2018, 7:04pm UTC](https://discuss.elastic.co/t/erros-logstash-fields-kibana/146907/3 "2018-09-03T19:04:49Z")

</div>

> [@Harshad\_Velapure](#):
>
> filter {
> 
> grok {  
> match =\> { message =\> "%{IP:client} %{DATA:USERNAME} %{DATA:USERNAME} [%{DATA:logtime}] "%{WORD:request} %{URIPATHPARAM:path} HTTP/%{NUMBER:version}" %{NUMBER:response} %{GREEDYDATA:responseMessage}" }  
> }  
> mutate{  
> gsub =\> ["logtime"," -0300",""]  
> }
> 
> date{  
> match =\> ["logtime","dd/MMM/yyy:HH:mm:ss"]  
> }
> 
> }

Hello Harshad

I try test y script . but I receive this error:

[2018-09-03T16:03:28,842][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2018-09-03T16:03:29,469][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.3.2"}  
[2018-09-03T16:03:30,221][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, {, } at line 14, column 91 (byte 262) after filter {\n\ngrok {\nmatch =\> { message =\> "%{IP:client} %{DATA:USERNAME} %{DATA:USERNAME} \[%{DATA:logtime}\]"", :backtrace=\>["/app/elk/logstash-6.3.2/logstash-core/lib/logstash/compiler.rb:42:in `compile_imperative'", "/app/elk/logstash-6.3.2/logstash-core/lib/logstash/compiler.rb:50:in `compile\_graph'", "/app/elk/logstash-6.3.2/logstash-core/lib/logstash/compiler.rb:12:in `block in compile_sources'", "org/jruby/RubyArray.java:2486:in `map'", "/app/elk/logstash-6.3.2/logstash-core/lib/logstash/compiler.rb:11:in `compile_sources'", "/app/elk/logstash-6.3.2/logstash-core/lib/logstash/pipeline.rb:49:in `initialize'", "/app/elk/logstash-6.3.2/logstash-core/lib/logstash/pipeline.rb:167:in `initialize'", "/app/elk/logstash-6.3.2/logstash-core/lib/logstash/pipeline_action/create.rb:40:in `execute'", "/app/elk/logstash-6.3.2/logstash-core/lib/logstash/agent.rb:305:in `block in converge\_state'"]}

---

<div class="post-metadata">

**Author:** ![marcos.vbp](https://avatars.discourse-cdn.com/v4/letter/m/c5a1d2/32.png) [@marcos.vbp](https://discuss.elastic.co/u/marcos.vbp)\
**Post date:** [September 3, 2018, 7:49pm UTC](https://discuss.elastic.co/t/erros-logstash-fields-kibana/146907/4 "2018-09-03T19:49:07Z")

</div>

> [@marcos.vbp](#):
>
> match =\> { "message" =\> "%{IP:client} %{USERNAME} %{USERNAME} [%{HTTPDATE:timestamp}] %{WORD:request} %{URIPATHPARAM:path} HTTP/%{NUMBER:version} %{NUMBER:response} %{GREEDYDATA:responseMessage}" }  
> }

I found error , and the same error occur.

{  
"tags" =\> [  
[0] "\_grokparsefailure"  
],  
"message" =\> "172.16.2.211 - - [03/Set/2018:16:31:53 -0300] "POST /lmsa/swtbrokerziped HTTP/1.1" 200 475 ",  
"@version" =\> "1",  
"host" =\> "brpoaelk01.mercurio.local",  
"type" =\> "weblogic-access-lms01",  
"path" =\> "/var/log/weblogic/producao/lms01/access.log",  
"@timestamp" =\> 2018-09-03T19:48:20.647Z  
}

match =\> { message =\> "%{IP:client} %{DATA:USERNAME} %{DATA:USERNAME} [%{DATA:logtime}] %{WORD:request} %{URIPATHPARAM:path} HTTP/%{NUMBER:version} %{NUMBER:response} %{GREEDYDATA:responseMessage}" }  
}

---

<div class="post-metadata">

**Author:** ![marcos.vbp](https://avatars.discourse-cdn.com/v4/letter/m/c5a1d2/32.png) [@marcos.vbp](https://discuss.elastic.co/u/marcos.vbp)\
**Post date:** [September 3, 2018, 8:17pm UTC](https://discuss.elastic.co/t/erros-logstash-fields-kibana/146907/5 "2018-09-03T20:17:39Z")

</div>

Harshad\_Velapure,

I Change code y send me :  
match =\> { message =\> "%{IP:client} %{DATA:USERNAME} %{DATA:USERNAME} [%{DATA:logtime}] **"** %{WORD:request} %{URIPATHPARAM:path} HTTP/%{NUMBER:versioni} **"** %{NUMBER:response} %{GREEDYDATA:responseMessage}" }

And before error change too.

{  
"host" =\> "brpoaelk01.mercurio.local",  
"path" =\> [  
[0] "/var/log/weblogic/producao/lms01/access.log",  
[1] "/lmsa/jsonbroker"  
],  
"versioni" =\> "1.1",  
"USERNAME" =\> [  
[0] "-",  
[1] "-"  
],  
"client" =\> "172.16.2.211",  
"@timestamp" =\> 2018-09-03T20:14:33.209Z,  
"@version" =\> "1",  
"request" =\> "POST",  
"response" =\> "200",  
"tags" =\> [  
[0] "\_dateparsefailure"  
],  
"message" =\> "172.16.2.211 - - [03/Set/2018:16:57:30 -0300] "POST /lmsa/jsonbroker HTTP/1.1" 200 958 ",  
"type" =\> "weblogic-access-lms01",  
"responseMessage" =\> "958 ",  
"logtime" =\> "03/Set/2018:16:57:30"  
}

Now , y help me again ?

---

<div class="post-metadata">

**Author:** ![Harshad\_Velapure](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harshad_velapure/32/33684_2.png) [@Harshad\_Velapure](https://discuss.elastic.co/u/Harshad_Velapure)\
**Post date:** [September 12, 2018, 8:00pm UTC](https://discuss.elastic.co/t/erros-logstash-fields-kibana/146907/6 "2018-09-12T20:00:54Z")

</div>

what's the error now ?  
can you share full updated configuration along with sample log?

---

<div class="post-metadata">

**Author:** ![marcos.vbp](https://avatars.discourse-cdn.com/v4/letter/m/c5a1d2/32.png) [@marcos.vbp](https://discuss.elastic.co/u/marcos.vbp)\
**Post date:** [September 14, 2018, 3:10pm UTC](https://discuss.elastic.co/t/erros-logstash-fields-kibana/146907/7 "2018-09-14T15:10:16Z")

</div>

Hi,

input {  
file {  
path =\> "/var/log/weblogic/producao/lms01/access.log"  
type =\> "weblogic-access-lms01"  
start\_position =\> "beginning"  
}

}

filter {

grok {  
match =\> { message =\> "%{IP:client} %{DATA:USERNAME} %{DATA:USERNAME} [%{DATA:logtime}] "%{WORD:request} %{NOTSPACE:path} HTTP/%{NUMBER:versioni}" %{NUMBER:response} %{GREEDYDATA:responseMessage}" }

}  
mutate{  
remove\_field =\> ["message"]  
}

date{  
match =\> ["logtime","dd/MMM/yyy:HH:mm:ss Z"]  
}

}  
output {  
elasticsearch { hosts =\> "lx-swelk01:9800"  
index =\> "access\_weblogic\_index"

}

stdout { codec =\> rubydebug }

}

Error:

{  
"logtime" =\> "14/Set/2018:12:08:35 -0300",  
"client" =\> "172.16.2.211",  
"tags" =\> [  
[0] "\_dateparsefailure"  
],  
"USERNAME" =\> [  
[0] "-",  
[1] "-"  
],  
"versioni" =\> "1.1",  
"responseMessage" =\> "83 ",  
"host" =\> "brpoaelk01.mercurio.local",  
"request" =\> "POST",  
"@version" =\> "1",  
"type" =\> "weblogic-access-lms01",  
"@timestamp" =\> 2018-09-14T15:08:41.563Z,  
"response" =\> "200",  
"path" =\> [  
[0] "/var/log/weblogic/producao/lms01/access.log",  
[1] "/lmsa/rest/coleta/programacaoColetasVeiculos/findColetasRealizadas"  
]  
}

Line log :  
172.16.27.211 - - [14/Set/2018:12:08:35 -0300] "GET /lmsa/rest/coleta/programacaoColetasVeiculos/findColetasRealizadas HTTP/1.1" 200 211

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 12, 2018, 3:10pm UTC](https://discuss.elastic.co/t/erros-logstash-fields-kibana/146907/8 "2018-10-12T15:10:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
