# Grok pattern for Apache customized log

**URL:** <https://discuss.elastic.co/t/grok-pattern-for-apache-customized-log/177270>\
**Category:** Logstash\
**Created:** [April 17, 2019, 10:29am UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-customized-log/177270 "2019-04-17T10:29:42Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![srinivasas](https://avatars.discourse-cdn.com/v4/letter/s/b487fb/32.png) [@srinivasas](https://discuss.elastic.co/u/srinivasas)\
**Post date:** [April 17, 2019, 10:29am UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-customized-log/177270/1 "2019-04-17T10:29:42Z")

</div>

Hello,

we are using a filebeat Apahce module to parse apache access logs and customized the default log format. Logs are sent to Logstash there we want to use the grok filter to catch few events through alerts.

We tried with different grok patterns, but failed to get actual results. Apache logs are showing as single message and with \_grokparsefailur, \_geoip\_lookup\_failure in tags.

## Our logs in apache access log:

## CustomLog logs/19Httpd\_access\_log "%{%a %m/%d/%Y @ %I:%M:%S.}t%{msec\_frac}t %{%p %Z}t %h (%{X-Forwarded-For}i) \> %v:%p "%r" %I %D %\>s %O %k %L "%{Referer}i" "%{User-Agent}i" %u %{User}C %{SessionTracker}C"

## Wed 04/17/2019 @ 02:40:16.348 PM IST 192.168.0.58 (-) \> 192.168.10.115:80 "POST /rR\_Performance/super\_updateDescription.action HTTP/1.1" 8054 53804 200 260 0 - "[http://192.168.0.19/RR\_Performance/reviewForm\_editReviewForm.action](http://192.168.0.19/RR_Performance/reviewForm_editReviewForm.action)" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683.103 Safari/537.36" - - -

Please help us to create a Grok pattern for above example log.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 17, 2019, 2:24pm UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-customized-log/177270/2 "2019-04-17T14:24:47Z")

</div>

What have you tried and what don't you like about the results?

---

<div class="post-metadata">

**Author:** ![srinivasas](https://avatars.discourse-cdn.com/v4/letter/s/b487fb/32.png) [@srinivasas](https://discuss.elastic.co/u/srinivasas)\
**Post date:** [April 17, 2019, 2:56pm UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-customized-log/177270/3 "2019-04-17T14:56:33Z")

</div>

Tried with Logstash pipeline Apache2 logs configuration.

 ![Apache02](https://us1.discourse-cdn.com/elastic/original/3X/a/0/a01144e70fba34672a0d3ad092797b90def09b09.jpeg)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 17, 2019, 3:17pm UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-customized-log/177270/4 "2019-04-17T15:17:15Z")

</div>

What grok pattern have you tried.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 15, 2019, 3:30pm UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-customized-log/177270/5 "2019-05-15T15:30:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
