Hello,
Sorry for bothering. I'm a new user for ELK. I have managed to enable Apache module for Filebeat and I'm seeing the Apache logs coming in Discover Section in Kibana. However the remote_ip and other fields from Apache are being containted in the message field. How can I get the remote_ip and other fields mapped correctly? Mainly remote_ip, User, URL (GET /mail) ...
Thank you in advance!
==============================
Example of a Log in Discover in Kibana
@timestamp
Feb 9, 2021 @ 16:46:36.153
_id
Xhx5h3cB1OZ-J5vvq_rA
_index
filebeat-7.10.2-2021.02.09-000001
_score
_type
_doc
agent.ephemeral_id
c75f9d91-47af-49eb-8797-79920a1308a7
agent.hostname
Server
agent.id
77a89e44-7cec-4d01-8b8f-8195dd8c3679
agent.name
Server
agent.type
filebeat
agent.version
7.10.2
ecs.version
1.5.0
error.message
Provided Grok expressions do not match field value: [85.85.85.85 webmail.company.com "CN=User/O=Company/C=CZ" [14/Dec/2020:05:58:18 +0100] "GET /mail/User.nsf/iNotes/Proxy/?OpenDocument&Form=s_ReadViewEntries&PresetFields=DBQuotaInfo;1,FolderName;($Inbox),UnreadCountInfo;1,SearchSort;DateD,s_UsingHttps;1,noPI;1&TZType=UTC&Start=1&Count=23&resortdescending=6 HTTP/1.1" 200 2054 "https://webmail.company.com/mail/User.nsf/iNotes/Proxy/?OpenDocument&Form=l_ScriptFrame&l=en&gz&CR&MX&TSF=20170318T181650,92Z&TSX=20180206T185427,18Z&EFF=%2FiNotes%2FForms9_x&charset=UTF-8&charset=UTF-8&KIC&ua=safari&pt" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36" 31
event.dataset
apache.access
event.ingested
Feb 9, 2021 @ 16:47:13.932
event.module
apache
fileset.name
access
host.architecture
x86_64
host.hostname
Server
host.id
fec37629-61fa-466c-b662-9537045df62a
host.ip
fe80::c573:3ba4:33e1:4ede, 192.168.1.13, fe80::5efe:c0a8:10d, fe80:7f:fffe
host.mac
00:15:5d:01:19:1c, 00:00:00:00:00:00:00:e0, 00:00:00:00:00:00:00:e0
host.name
Server
host.os.build
7601.24546
host.os.family
windows
host.os.kernel
6.1.7601.24545 (win7sp1_ldr_escrow.200102-1707)
host.os.name
Windows Server 2008 R2 Enterprise
host.os.platform
windows
host.os.version
6.1
input.type
log
log.file.path
D:\Lotus\Domino\data\weblogs\access12142020.log
log.offset
8,054,853
message
85.85.85.85 webmail.company.com "CN=User/O=Company/C=CZ" [14/Dec/2020:05:58:18 +0100] "GET /mail/User.nsf/iNotes/Proxy/?OpenDocument&Form=s_ReadViewEntries&PresetFields=DBQuotaInfo;1,FolderName;($Inbox),UnreadCountInfo;1,SearchSort;DateD,s_UsingHttps;1,noPI;1&TZType=UTC&Start=1&Count=23&resortdescending=6 HTTP/1.1" 200 2054 "https://webmail.company.com/mail/User.nsf/iNotes/Proxy/?OpenDocument&Form=l_ScriptFrame&l=en&gz&CR&MX&TSF=20170318T181650,92Z&TSX=20180206T185427,18Z&EFF=%2FiNotes%2FForms9_x&charset=UTF-8&charset=UTF-8&KIC&ua=safari&pt" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.88 Safari/537.36" 31
service.type
apache
suricata.eve.timestamp
Feb 9, 2021 @ 16:46:36.153