# Filebeat.template.json

**URL:** <https://discuss.elastic.co/t/filebeat-template-json/70902>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 8, 2017, 10:26pm UTC](https://discuss.elastic.co/t/filebeat-template-json/70902 "2017-01-08T22:26:28Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Arnaud\_Domard](https://avatars.discourse-cdn.com/v4/letter/a/278dde/32.png) [@Arnaud\_Domard](https://discuss.elastic.co/u/Arnaud_Domard)\
**Post date:** [January 8, 2017, 10:26pm UTC](https://discuss.elastic.co/t/filebeat-template-json/70902/1 "2017-01-08T22:26:28Z")

</div>

Hi

I am looking for a template matching access .log file (apache log file).  
I need to parse the message which is the raw apache log in kibana.  
Where can i find the documentation to build my own filebeat template ?  
Fields type accepted...

Thanks for your help

arnaud

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [January 9, 2017, 1:59pm UTC](https://discuss.elastic.co/t/filebeat-template-json/70902/2 "2017-01-09T13:59:00Z")

</div>

For the moment I would recommend using Logstash to parse the access logs, see an example here: [https://www.elastic.co/guide/en/logstash/current/config-examples.html#\_processing\_apache\_logs](https://www.elastic.co/guide/en/logstash/current/config-examples.html#_processing_apache_logs)

This parsing can also be done with the Elasticsearch [Ingest Node](https://www.elastic.co/guide/en/elasticsearch/reference/master/ingest.html), and in the future we plan to make it possible for Filebeat to upload Ingest Node configurations. That part is not yet ready, though.

---

<div class="post-metadata">

**Author:** ![nono1974](https://avatars.discourse-cdn.com/v4/letter/n/d9b06d/32.png) [@nono1974](https://discuss.elastic.co/u/nono1974)\
**Post date:** [January 9, 2017, 11:55pm UTC](https://discuss.elastic.co/t/filebeat-template-json/70902/3 "2017-01-09T23:55:40Z")

</div>

Hi thank you for the reply.

I switch my apache log to json encoding.

I put this in my custom apache acces log 🙂

LogFormat "{ "index" : { "\_index" : "Apachebeat-%{%Y.%m.%d}t", "\_type" : "ApacheHttpRequestEvent" }}\n { "timestamp": "%{%Y-%m-%dT%H:%M:%S%z}t", "type": "ApacheHttpRequestEvent", "version": "2.4.25", "origin":{"host":{"name":"%h"},"software":{"name":"httpd","instance":"0","processId":"%{pid}P","threadId":"%{tid}P"},"module":{"executionId":"","name":"%U"}},"tags":["domain:technical","tier:software","severity:info"],"remoteAddr":"%a","forwardedFor":"%{X-Forwarded-For}i","referer":"%{Referer}i","method":"%m","protocol":"%H","parameters":"%q","contentType":"%{Content-Type}o","correlationId":"%{HTTP\_CORRELATION\_ID}e","transactionId":"%{X-TRANSACTIONID}i","userIdTech":"%{X-USERID-TECH}i","userIdTarget":"%{X-USERID-TARGET}i","status":%\>s,"latency":%D,"size":%O}" combined\_json

I don't see clearly what i should change in the filebeat.yml to digest this json nativaly to ES.

Could you please give some clues ?

regards

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [January 10, 2017, 9:09am UTC](https://discuss.elastic.co/t/filebeat-template-json/70902/4 "2017-01-10T09:09:47Z")

</div>

Have a look at the filebeat json docs: [https://www.elastic.co/guide/en/beats/filebeat/master/configuration-filebeat-options.html#config-json](https://www.elastic.co/guide/en/beats/filebeat/master/configuration-filebeat-options.html#config-json)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 7, 2017, 9:10am UTC](https://discuss.elastic.co/t/filebeat-template-json/70902/5 "2017-02-07T09:10:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
