# Filebeat HAProxy module does not parse tcplog format

**URL:** <https://discuss.elastic.co/t/filebeat-haproxy-module-does-not-parse-tcplog-format/303422>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 27, 2022, 2:55pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-module-does-not-parse-tcplog-format/303422 "2022-04-27T14:55:18Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![CaptAintHere](https://avatars.discourse-cdn.com/v4/letter/c/46a35a/32.png) [@CaptAintHere](https://discuss.elastic.co/u/CaptAintHere)\
**Post date:** [April 27, 2022, 2:55pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-module-does-not-parse-tcplog-format/303422/1 "2022-04-27T14:55:18Z")

</div>

Hi,

I'm trying to use the HAProxy module of Filebeat with a TCP frontend in HAProxy but the grok does not seem to work with the log lines generated by the `option tcplog` of HAProxy.

[This GitHub issue](https://github.com/elastic/beats/issues/8311) mentions that the `option tcplog` should be supported by Filebeat.

Here is an example of a log line generated by HAProxy :

```auto
haproxy[105122]: 1.1.1.1:16625 [27/Apr/2022:16:08:23.339] v4-https v4-server-pool/server01 1/0/1043 28944 CD 2/2/1/0/0 0/0

```

Regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 25, 2022, 4:55pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-module-does-not-parse-tcplog-format/303422/2 "2022-05-25T16:55:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
