# Filebeat Apache Module Ingest Pipeline

**URL:** <https://discuss.elastic.co/t/filebeat-apache-module-ingest-pipeline/200493>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [September 20, 2019, 8:45pm UTC](https://discuss.elastic.co/t/filebeat-apache-module-ingest-pipeline/200493 "2019-09-20T20:45:41Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![jvicente](https://avatars.discourse-cdn.com/v4/letter/j/8dc957/32.png) [@jvicente](https://discuss.elastic.co/u/jvicente)\
**Post date:** [September 20, 2019, 8:45pm UTC](https://discuss.elastic.co/t/filebeat-apache-module-ingest-pipeline/200493/1 "2019-09-20T20:45:41Z")

</div>

I am currently working on formatting the @timestamp in access logs for the apache2 module in Filebeat. Currently getting the following error message on kibana: "Provided Grok expressions do not match field value:"

My current ingest pipeline is the following:  
{  
"description": "Pipeline for parsing Apache2 access logs. Requires the geoip and user\_agent plugins.",  
"processors": [{  
"grok": {  
"field": "message",  
"patterns":[  
"%{IPORHOST:apache2.access.remote\_ip} - %{DATA:apache2.access.user\_name} \[%{HTTPDATE:apache2.access.time}\] "(?:%{WORD:apache2.access.method} %{DATA:apache2.access.url} HTTP/%{NUMBER:apache2.access.http\_version}|-)?" %{NUMBER:apache2.access.response\_code} (?:%{NUMBER:apache2.access.body\_sent.bytes}|-)( "%{DATA:apache2.access.referrer}")?( "%{DATA:apache2.access.agent}")?",  
"%{IPORHOST:apache2.access.remote\_ip} - %{DATA:apache2.access.user\_name} \[%{HTTPDATE:apache2.access.time}\] "-" %{NUMBER:apache2.access.response\_code} -",  
"\[%{HTTPDATE:apache2.access.time}\] %{IPORHOST:apache2.access.remote\_ip} %{DATA:apache2.access.ssl.protocol} %{DATA:apache2.access.ssl.cipher} "%{WORD:http.request.method} %{DATA:apache2.access.url} HTTP/%{NUMBER:apache2.access.http\_version}" %{NUMBER:apache2.access.body\_sent.bytes}"  
],  
"ignore\_missing": true  
}  
},{  
"remove":{  
"field": "message"  
}  
}, {  
"rename": {  
"field": "@timestamp",  
"target\_field": "read\_timestamp"  
}  
}, {  
"date": {  
"field": "apache2.access.time",  
"target\_field": "@timestamp",  
"formats": ["yyyy-MM-dd'T'HH:mm:ss.SSS'Z'"],  
"ignore\_failure": false  
}  
}, {  
"remove": {  
"field": "apache2.access.time",  
"ignore\_failure": true  
}  
}, {  
"rename": {  
"field": "apache2.access.agent",  
"target\_field": "apache2.access.user\_agent.original",  
"ignore\_failure": true  
}  
}],  
"on\_failure" : [{  
"set" : {  
"field" : "error.message",  
"value" : "{{ \_ingest.on\_failure\_message }}"  
}  
}]  
}

It was working earlier before i added the milliseconds to the format. I am trying to format the @timestamp to be something like 2019-08-20T00:02:15.000Z. Is there are problem with the time format or something else in the pipeline.

Best Regards,  
Juan Vicente

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 18, 2019, 8:45pm UTC](https://discuss.elastic.co/t/filebeat-apache-module-ingest-pipeline/200493/2 "2019-10-18T20:45:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
