# Filebeat + Apache2 Module + add field

**URL:** <https://discuss.elastic.co/t/filebeat-apache2-module-add-field/96747>\
**Category:** Beats\
**Created:** [August 11, 2017, 10:18am UTC](https://discuss.elastic.co/t/filebeat-apache2-module-add-field/96747 "2017-08-11T10:18:55Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Globule](https://avatars.discourse-cdn.com/v4/letter/g/8491ac/32.png) [@Globule](https://discuss.elastic.co/u/Globule)\
**Post date:** [August 11, 2017, 10:18am UTC](https://discuss.elastic.co/t/filebeat-apache2-module-add-field/96747/1 "2017-08-11T10:18:55Z")

</div>

Hello,

I try to add a field with vhost name. Actually, the filebeat module apache2 work but it dosen't show the vhost name.

My apache log looks like this:  
[www.foo.com:443](http://www.foo.com:443) 37.34.55.121 - - [11/Aug/2017:12:07:53 +0200] "GET /sites/default/files/pdf/tauxphnl.pdf HTTP/1.1" 304 5163 "-" "Mozilla/5.0 (compatible; MSIE 9.11; Windows NT 6.1; Trident/5.0)"

and the result in kibana:

{  
"\_index": "filebeat-2017.08.11",  
"\_type": "doc",  
"\_id": "AV3QvyqOs-yNO51h3JDi",  
"\_version": 1,  
"\_score": null,  
"\_source": {  
"@timestamp": "2017-08-11T10:02:29.000Z",  
"offset": 4641569,  
"apache2": {  
"access": {  
"referrer": "[https://xxx.xxxxxxxx.xxx/xx/xxxxxxxxxxxxx](https://xxx.xxxxxxxx.xxx/xx/xxxxxxxxxxxxx)",  
"response\_code": "304",  
"remote\_ip": "[XXX.XXX.XXX.XXX](http://XXX.XXX.XXX.XXX)",  
"geoip": {  
"continent\_name": "Europe",  
"country\_iso\_code": "BE",  
"location": {  
"lon": 4.35,  
"lat": 50.85  
}  
},  
"method": "GET",  
"user\_name": "-",  
"http\_version": "1.1",  
"body\_sent": {  
"bytes": "5162"  
},  
"url": "/sites/default/files/xxxxx-xxxxx-xxx.png",  
"user\_agent": {  
"patch": "2171",  
"major": "39",  
"minor": "0",  
"os": "Windows 8.1",  
"name": "Chrome",  
"os\_name": "Windows 8.1",  
"device": "Other"  
}  
}  
},  
"beat": {  
"hostname": "xxxxx01",  
"name": "xxxxx01",  
"version": "5.5.1"  
},  
"input\_type": "log",  
"read\_timestamp": "2017-08-11T10:02:35.602Z",  
"source": "/var/log/apache2/access.log",  
"type": "log"  
},  
"fields": {  
"@timestamp": [  
1502445749000  
]

I need to see in kibana the vhost name (first field in log) where 's the info before the remote\_ip?

I try to update the /usr/share/filebeat/modules/apache2/access/ingest/defult.json like this:

{  
"description": "Pipeline for parsing Apache2 access logs. Requires the geoip and user\_agent plugins.",  
"processors": [{  
"grok": {  
"field": "message",  
"patterns":[  
"%{HOSTPORT:vhost} %{IPORHOST:apache2.access.remote\_ip} - %{DATA:apache2.access.user\_name} \[%{HTTPDATE:apache2.access.time}\] "%{WORD:apache2.access.method} %{DATA:apache2.access.url} HTTP/%{NUMBER:apache2.access.http\_version}" %{NUMBER:apache2.access.response\_code} (?:%{NUMBER:apache2.access.body\_sent.bytes}|-)( "%{DATA:apache2.access.referrer}")?( "%{DATA:apache2.access.agent}")?",  
"%{HOSTPORT:vhost} %{IPORHOST:apache2.access.remote\_ip} - %{DATA:apache2.access.user\_name} \[%{HTTPDATE:apache2.access.time}\] "-" %{NUMBER:apache2.access.response\_code} -"  
],  
"ignore\_missing": true  
}  
},{  
"remove":{  
"field": "message"  
}  
}, {  
"rename": {  
"field": "@timestamp",  
"target\_field": "read\_timestamp"  
}  
}, {  
"date": {  
"field": "apache2.access.time",  
"target\_field": "@timestamp",  
"formats": ["dd/MMM/YYYY:H:m:s Z"]  
}  
}, {  
"remove": {  
"field": "apache2.access.time"  
}  
}, {  
"user\_agent": {  
"field": "apache2.access.agent",  
"target\_field": "apache2.access.user\_agent",  
"ignore\_failure": true  
}  
}, {  
"remove": {  
"field": "apache2.access.agent",  
"ignore\_failure": true  
}  
}, {  
"geoip": {  
"field": "apache2.access.remote\_ip",  
"target\_field": "apache2.access.geoip"  
}  
}],  
"on\_failure" : [{  
"set" : {  
"field" : "error",  
"value" : "{{ \_ingest.on\_failure\_message }}"  
}  
}]  
}

I have added the field: %{HOSTPORT:vhost} %{IPORHOST:apache2.access.remote\_ip} to match the vhostname and in /etc/filebeat/filebeat.template.json I add this:

{  
"mappings": {  
"_default_": {  
"\_all": {  
"norms": false  
},  
"\_meta": {  
"version": "5.5.1"  
},  
"date\_detection": false,  
"dynamic\_templates": [  
{  
"strings\_as\_keyword": {  
"mapping": {  
"ignore\_above": 1024,  
"type": "keyword"  
},  
"match\_mapping\_type": "string"  
}  
}  
],  
"properties": {  
"@timestamp": {  
"type": "date"  
},  
"vhost": {  
"type": "keyword"  
},  
"apache2": {  
"properties": {  
"access": {  
"properties": {  
"message": {  
"type": "text"  
},  
"vhost\_name": {  
"type": "text"  
},  
"agent": {  
"norms": false,  
"type": "text"  
},  
"body\_sent": {  
"properties": {  
"bytes": {  
"type": "long"  
}  
}  
},  
"geoip": {  
"properties": {  
"continent\_name": {  
"ignore\_above": 1024,  
"type": "keyword"  
},  
"country\_iso\_code": {  
"ignore\_above": 1024,  
"type": "keyword"  
},  
"location": {  
"type": "geo\_point"  
}  
}  
},.......

How do this? Anyone can help me please?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [August 15, 2017, 8:38pm UTC](https://discuss.elastic.co/t/filebeat-apache2-module-add-field/96747/2 "2017-08-15T20:38:44Z")

</div>

After modifying the pipeline JSON file on the Filebeat host you need to [delete the pipeline](https://www.elastic.co/guide/en/elasticsearch/reference/5.5/delete-pipeline-api.html) from Elasticsearch. If you don't delete the pipeline from Elasticsearch, then Filebeat will not update the pipeline config with the new settings.

Additionally when changing the filebeat index template file you need to [delete the template](https://www.elastic.co/guide/en/elasticsearch/reference/5.5/indices-templates.html#delete) from Elasticsearch too. Or you can tell Filebeat to [overwrite](https://www.elastic.co/guide/en/beats/filebeat/current/elasticsearch-output.html#_template) the template.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 1, 2017, 10:19am UTC](https://discuss.elastic.co/t/filebeat-apache2-module-add-field/96747/3 "2017-09-01T10:19:00Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
