# Filebeat Nginx Module + ModSecurity Audit Log to Same ELK Stack

**URL:** <https://discuss.elastic.co/t/filebeat-nginx-module-modsecurity-audit-log-to-same-elk-stack/232018>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 11, 2020, 1:11pm UTC](https://discuss.elastic.co/t/filebeat-nginx-module-modsecurity-audit-log-to-same-elk-stack/232018 "2020-05-11T13:11:23Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [May 11, 2020, 2:24pm UTC](https://discuss.elastic.co/t/filebeat-nginx-module-modsecurity-audit-log-to-same-elk-stack/232018/2 "2020-05-11T14:24:15Z")

</div>

Hey @adlp, welcome to discuss 🙂

You would need to add an input with the path of the ModSecurity logs, look for example to the configuration in [Filebeat to parse modsecurity json logs](https://discuss.elastic.co/t/filebeat-to-parse-modsecurity-json-logs/134662)

In the same link you can see that parsing its contents can be a more complicated task.

---

_[View the full topic](https://discuss.elastic.co/t/filebeat-nginx-module-modsecurity-audit-log-to-same-elk-stack/232018)._
