# Getting sample apache logs into Kibana

**URL:** <https://discuss.elastic.co/t/getting-sample-apache-logs-into-kibana/45264>\
**Category:** Kibana\
**Created:** [March 23, 2016, 5:29pm UTC](https://discuss.elastic.co/t/getting-sample-apache-logs-into-kibana/45264 "2016-03-23T17:29:58Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![dickepa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dickepa/32/8069_2.png) [@dickepa](https://discuss.elastic.co/u/dickepa)\
**Post date:** [March 23, 2016, 5:29pm UTC](https://discuss.elastic.co/t/getting-sample-apache-logs-into-kibana/45264/1 "2016-03-23T17:29:58Z")

</div>

Hello everyone

I'm currently building an ELK stack and what I want to do is use a previous Apache log file to ingest into the ELK server for demo purposes.

One idea I had was to make the log locally available and then parse through Logstash by adding an apache conf file in the Logstash conf.d directory and restart Logstash.

In short I'm trying to find a quick way to add some "known" data to be able to demo to my colleagues the benefits of using Kibana dashboards for identifing security events.

Thanks

Paul

---

<div class="post-metadata">

**Author:** ![Khalah\_Jones\_Golden](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khalah_jones_golden/32/7169_2.png) [@Khalah\_Jones\_Golden](https://discuss.elastic.co/u/Khalah_Jones_Golden)\
**Post date:** [March 23, 2016, 5:52pm UTC](https://discuss.elastic.co/t/getting-sample-apache-logs-into-kibana/45264/2 "2016-03-23T17:52:55Z")

</div>

The kibana team, and i think a good portion of elastic uses this awesome tool called makelogs here [http://github.com/spalger/makelogs](http://github.com/spalger/makelogs), it's a great way to just pop in some really generic data into a cluster to analyze and show off what you can do.

Peace,  
Khalah

---

<div class="post-metadata">

**Author:** ![dickepa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dickepa/32/8069_2.png) [@dickepa](https://discuss.elastic.co/u/dickepa)\
**Post date:** [March 24, 2016, 4:18pm UTC](https://discuss.elastic.co/t/getting-sample-apache-logs-into-kibana/45264/3 "2016-03-24T16:18:03Z")

</div>

Thanks for the info Khalah, I could find a use case for that however what I'm trying to do is use an existing log that contains, let's say "activities of interest" to view in Kibana. So it would be champion if I could use that.

Paul

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [March 24, 2016, 6:21pm UTC](https://discuss.elastic.co/t/getting-sample-apache-logs-into-kibana/45264/4 "2016-03-24T18:21:02Z")

</div>

I think you're idea is fine. I found this pretty detailed step-by-step guide that gets Apache logs into Logstash and into Elasticsearch;

> **[404 Page not found](https://www.linode.com/docs/databases/elasticsearch/visualizing-apache-webserver-logs-in-the-elk-stack-on-debian-8)**
>
> Guides and tutorials on the Linode platform, Linux basics, and software installation and configuration.

Let us know if you get stuck on some part of that.

Regards,  
Lee

---

<div class="post-metadata">

**Author:** ![dickepa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dickepa/32/8069_2.png) [@dickepa](https://discuss.elastic.co/u/dickepa)\
**Post date:** [April 13, 2016, 3:18pm UTC](https://discuss.elastic.co/t/getting-sample-apache-logs-into-kibana/45264/5 "2016-04-13T15:18:10Z")

</div>

Thank you Lee, i did give that a go but fell at the logstash apache config

```
3output {
    elasticsearch { protocol => "http" }
}

```

with this inplace logstash fails reporting a protocol error! Can you please advise?

UPDATE: As David Bowie sung "Ch Ch Ch Changes" new format config noted in dropping the use of protocol within the conf file. [https://www.elastic.co/guide/en/logstash/2.0/advanced-pipeline.html](https://www.elastic.co/guide/en/logstash/2.0/advanced-pipeline.html)

UPDATE UPDATE: Data still absent from ELK!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:55pm UTC](https://discuss.elastic.co/t/getting-sample-apache-logs-into-kibana/45264/6 "2017-07-06T13:55:37Z")

</div>


