# Filebeat apache module not collecting any logs

**URL:** <https://discuss.elastic.co/t/filebeat-apache-module-not-collecting-any-logs/319832>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 25, 2022, 3:04pm UTC](https://discuss.elastic.co/t/filebeat-apache-module-not-collecting-any-logs/319832 "2022-11-25T15:04:19Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![cesq](https://avatars.discourse-cdn.com/v4/letter/c/f0a364/32.png) [@cesq](https://discuss.elastic.co/u/cesq)\
**Post date:** [November 25, 2022, 3:04pm UTC](https://discuss.elastic.co/t/filebeat-apache-module-not-collecting-any-logs/319832/1 "2022-11-25T15:04:19Z")

</div>

So I have been playing around with collecting data using filebeat and sending it via sidecar to my graylog server. I wanted to try out the apache module, so I wrote the configuration for this (following the docs of course), however no acceess or error logs are showing up. Now it probably isn't an issue regarding Graylog, which is why I ask this question here and not on the graylog forum.  
Here's the configuration file:

```auto
# Needed for Graylog
fields_under_root: true
fields.collector_node_id: ${sidecar.nodeName}
fields.gl2_source_collector: ${sidecar.nodeId}

# Where to look for logs
filebeat.inputs:
- input_type: log
  paths:
    - /var/log/*.log
  type: log

# Where to send the logs 
output.logstash:
   hosts: ["x.x.x.x:5044"]

# Where to store the logs (locally)
path:
  data: /var/lib/graylog-sidecar/collectors/filebeat/data
  logs: /var/lib/graylog-sidecar/collectors/filebeat/log

# Optional modules
filebeat.modules:
- module: apache
  access:
    enabled: true
    var.paths: ["/var/log/httpd/*access.log"]
  error:
    enabled: true
    var.paths: ["/var/log/httpd/*error.log"]

```

I have checked this configuration file multiple times and there's nothing wrong with it (syntax wise), I have also checked the logs and there are no errors as well. I've made sure that the access and error logs are being filled up with new traffic so that it doesn't try to read empty files. So I really don't know what else it could be.  
Aside from the module, everything seems to be logging just fine.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 25, 2022, 4:24pm UTC](https://discuss.elastic.co/t/filebeat-apache-module-not-collecting-any-logs/319832/2 "2022-11-25T16:24:21Z")

</div>

Hi @cesq Welcome to the community!

You are sending the data through logstash did you also follow these documents

You did not share your log stash configuration.

> **[Use ingest pipelines for parsing | Logstash Reference \[8.11\] | Elastic](https://www.elastic.co/guide/en/logstash/current/use-ingest-pipelines.html)**

Pro tip always send data first directly from filebeat to elasticsearch first and make sure all the data is correct and then put logstash in the middle if you want to.

Follow the [filebeat quickstart](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-installation-configuration.html) module first.

Then reconfigure file beat to point to logstash.

Also run full setup not just the dashboards

`filebeat setup -e`

You do not need logstash, but it's a perfectly valid architecture.

There are lots of topics on this form about the subject.

I think this is one

> [@Apache Access Logs with Filebeats-\>Logstash-\>EL\<-Kibana: Throws errors at default dashboard](https://discuss.elastic.co/t/apache-access-logs-with-filebeats-logstash-el-kibana-throws-errors-at-default-dashboard/313585/7):
>
> @SirStephanikus Nope that is not your issue in 8.3.3 I just ran setup with setup.ilm.check\_exists: false ./filebeat setup -e and the mappings are correct GET \_cat/indices?v health status index uuid pri rep docs.count docs.deleted store.size pri.store.size yellow open .ds-filebeat-8.3.3-2022.09.06-000001 u3YyG9i\_Sh2XduYtAaVloQ 1 1 0 0 225b 225b GET .ds-filebeat-8.3.3-2022.09.06-000001/ { ".ds-fileb…

---

<div class="post-metadata">

**Author:** ![cesq](https://avatars.discourse-cdn.com/v4/letter/c/f0a364/32.png) [@cesq](https://discuss.elastic.co/u/cesq)\
**Post date:** [November 26, 2022, 10:15am UTC](https://discuss.elastic.co/t/filebeat-apache-module-not-collecting-any-logs/319832/3 "2022-11-26T10:15:34Z")

</div>

Hi @stephenb, thank you for replying.

I am using Graylog Sidecar feature to run the configs, meaning there's no fixed configuration on the host that the logs are being retrieved from.

Filebeat is installed on the host, but the configs there are irrelevant.  
I don't know if you're familiar with how Sidecars work in Graylog, but basically it's a feature that allows me to push one configuration to _n_ hosts. So there's only one config file in play, and that's the one I posted.

I know nothing about this logstash you're referring to, I've gotten filebeat and auditbeat working, only by using the Sidecar feature (and a Beats input). In both examples, nothing is being sent to elasticsearch. Also I want to emphasise that filebeat **is working** , it's only the **apache module** that I've tried to get running and failed, no errors in the logs and everything else works fine.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 26, 2022, 3:40pm UTC](https://discuss.elastic.co/t/filebeat-apache-module-not-collecting-any-logs/319832/4 "2022-11-26T15:40:47Z")

</div>

> [@cesq](#):
>
> ```auto
> output.logstash:
> hosts: ["x.x.x.x:5044"]
> 
> ```

This is why I assumed logstash that the [logstash](https://www.elastic.co/guide/en/logstash/current/index.html) output it appears that is what greylog uses as an endpoint

I did a quick search...

`greylog filebeat modules`

Looks like filebeat modules are not supported... that is unfortunate as they are quite powerful

> **[Filebeat module juniper SRX](https://community.graylog.org/t/filebeat-module-juniper-srx/21301/3)**
>
> Hi tmacgbay thank you for your help Right now I am sending all the logs through Syslog to Graylog Server and it works fine, But, I want to use the (Filbeat Moudule Juniper) but I have NOT idea how to do it?

I suspect the reason they do not work greylog actual workings / requirements of modules. Filebeat modules load / use specific ingest pipelines (parsers) to parse the data that are loaded into elasticsearch and used. Those are loaded into elasticsearch.. I'm pretty certain they are not loaded into greylog.

Why greylog is failing with no errors? I think you're going to need to go to the greylog community and ask them.

I suspect you could just load them as regular logs but I don't know what that looks like on greylog side

---

<div class="post-metadata">

**Author:** ![cesq](https://avatars.discourse-cdn.com/v4/letter/c/f0a364/32.png) [@cesq](https://discuss.elastic.co/u/cesq)\
**Post date:** [November 26, 2022, 4:55pm UTC](https://discuss.elastic.co/t/filebeat-apache-module-not-collecting-any-logs/319832/5 "2022-11-26T16:55:52Z")

</div>

Ah, that's a shame, thank you for helping me out!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 24, 2022, 6:56pm UTC](https://discuss.elastic.co/t/filebeat-apache-module-not-collecting-any-logs/319832/6 "2022-12-24T18:56:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
