# Filebeat Configuration for Apache Logs

**URL:** <https://discuss.elastic.co/t/filebeat-configuration-for-apache-logs/81085>\
**Category:** Beats\
**Created:** [April 4, 2017, 6:29am UTC](https://discuss.elastic.co/t/filebeat-configuration-for-apache-logs/81085 "2017-04-04T06:29:53Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![vortex](https://avatars.discourse-cdn.com/v4/letter/v/fbc32d/32.png) [@vortex](https://discuss.elastic.co/u/vortex)\
**Post date:** [April 4, 2017, 6:29am UTC](https://discuss.elastic.co/t/filebeat-configuration-for-apache-logs/81085/1 "2017-04-04T06:29:53Z")

</div>

Hi all,

I'am trying to configure filebeat to send apache logs to ELK ,but  
something goes wrong.

My set up is the following :

Server : Centos7  
Elasticsearch : 2.4.4  
Logstash : 2.3.4  
Kibana : 4.5.4

# Client : Centos7 Filebeat : 1.3.1 Apache : 2.4.6

On Client the filebeat.yml has the following:

- 

```
paths:
  - /var/log/messages
input_type: syslog
document_type: syslog
fields_under_root: true

```

- 

```
paths:
  - /var/log/httpd/access.log
input_type: log
document_type: apache-access
fields_under_root: true

```

On Server ,under /etc/logstash/conf.d i have :

01-apache.conf :

input {  
beats {  
port =\> "5043"  
}  
}  
filter {  
if [type] == "apache-access" {  
grok {  
match =\> { "message" =\> "%{COMBINEDAPACHELOG}" }  
}  
}  
}  
output {  
stdout { codec =\> rubydebug }  
}

and

logstash.conf :

input {  
beats {  
port =\> 5044  
ssl =\> true  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/certs/logstash-forwarder.key"  
congestion\_threshold =\> "40"  
}  
}  
filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGLINE}" }  
}

```
date {

```

match =\> ["timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}

}  
output {  
elasticsearch {  
hosts =\> localhost  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
}  
stdout {  
codec =\> rubydebug  
}  
}

When im running : filebeat -e -c filebeat.yml -d "publish" on Client in order to check messages,it seems that only harvests /var/log/messages :

2017/04/04 09:24:17.718663 publish.go:109: DBG Publish: {  
"@timestamp": "2017-04-04T09:24:15.215Z",  
"beat": {  
"hostname": "client",  
"name": "client"  
},  
"count": 1,  
"input\_type": "log",  
"message": "Apr 4 09:20:02 elkclient systemd[1]: Starting Session 668 of user root.",  
"offset": 714805,  
"source": "/var/log/messages",  
"type": "syslog"

It doesn't even read the apache prospector ,what i'am doing wrong ?

Thank you  
George

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 4, 2017, 7:05am UTC](https://discuss.elastic.co/t/filebeat-configuration-for-apache-logs/81085/2 "2017-04-04T07:05:25Z")

</div>

Why not upgrade and use [https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-apache2.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-apache2.html)

---

<div class="post-metadata">

**Author:** ![vortex](https://avatars.discourse-cdn.com/v4/letter/v/fbc32d/32.png) [@vortex](https://discuss.elastic.co/u/vortex)\
**Post date:** [April 4, 2017, 11:53am UTC](https://discuss.elastic.co/t/filebeat-configuration-for-apache-logs/81085/3 "2017-04-04T11:53:33Z")

</div>

thanks.  
Any comment regarding the given setup ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 25, 2017, 6:30am UTC](https://discuss.elastic.co/t/filebeat-configuration-for-apache-logs/81085/4 "2017-04-25T06:30:14Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
