# Grok Pattern for Apache Error Logs

**URL:** https://discuss.elastic.co/t/grok-pattern-for-apache-error-logs/100582
**Category:** Logstash
**Created:** [September 14, 2017, 5:52pm UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-error-logs/100582 "2017-09-14T17:52:01Z")
**Posts on this page:** 18
**Page:** 1

<div class="post-metadata">

### Author: ![pkshara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pkshara/32/48222_2.png) [@pkshara](https://discuss.elastic.co/u/pkshara)
#### Post date: [September 14, 2017, 5:52pm UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-error-logs/100582/1 "2017-09-14T17:52:01Z")

</div>

Below is the error log:

[Mon Nov 28 04:38:24 2016] [error] [client 10.114.34.43] File does not exist: /fep10/oraapps/appl/fep10comn/portal/FEP10\_j201s648/favicon.ico

I had written grok pattern as  
"message"=\> "[(?%{DAY} %{MONTH} %{MONTHDAY} %{TIME} %{YEAR})] [%{LOGLEVEL:loglevel}] [client %{IP:clientip}:.\*] %{GREEDYDATA:errormsg}"

It gives an grokparsefailure in ES. Please suggest the appropriate and let me know where i am making mistake.

TIA

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [September 14, 2017, 6:04pm UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-error-logs/100582/2 "2017-09-14T18:04:48Z")

</div>

Please edit your post and format the grok expression as preformatted text (e.g. using the toolbar button) so that it doesn't get mangled.

---

<div class="post-metadata">

### Author: ![phegde](https://avatars.discourse-cdn.com/v4/letter/p/e79b87/32.png) [@phegde](https://discuss.elastic.co/u/phegde)
#### Post date: [September 14, 2017, 6:10pm UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-error-logs/100582/3 "2017-09-14T18:10:48Z")

</div>

I'm trying out with nginx and even I get `_grokparsefailure` error along with `_geoip_lookup_failure`.  
Here is my conf.

```
filter
{
    if [type] == "nginx" 
    {
        grok {
            match => {
                "message" => '%{IPORHOST:remote_ip} - %{DATA:user_name} \[%{HTTPDATE:time}\] "%{WORD:request_action} %{DATA:request} HTTP/%{NUMBER:http_version}" %{NUMBER:response} %{NUMBER:bytes} "%{DATA:referrer}" "%{DATA:agent}"'
            }
        }
        date {
            match => ["time", "dd/MMM/YYYY:HH:mm:ss Z"]
            locale => en
        }

        geoip {
            source => "remote_ip"
            target => "geoip"
        }

        useragent {
            source => "agent"
            target => "user_agent"
        }
    }
}
```

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [September 14, 2017, 7:19pm UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-error-logs/100582/4 "2017-09-14T19:19:24Z")

</div>

But that's your access log filters and you wanted help with your error log.

---

<div class="post-metadata">

### Author: ![phegde](https://avatars.discourse-cdn.com/v4/letter/p/e79b87/32.png) [@phegde](https://discuss.elastic.co/u/phegde)
#### Post date: [September 15, 2017, 5:21am UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-error-logs/100582/5 "2017-09-15T05:21:47Z")

</div>

Oh Sorry I forgot to mention were the errors were shown. Actually it shows up in KIBANA.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/b/9b74a3c8add6a139555d007b41bb2d42eba5600e.png)

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [September 15, 2017, 6:06am UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-error-logs/100582/6 "2017-09-15T06:06:31Z")

</div>

- What do you want help with, error logs or access logs?
- For the kind of log you want help with, please show
  - the configuration used (formatted as preformatted text) and
  - an example message processed by Logstash (use a `stdout { codec => rubydebug }` output).

---

<div class="post-metadata">

### Author: ![pkshara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pkshara/32/48222_2.png) [@pkshara](https://discuss.elastic.co/u/pkshara)
#### Post date: [September 15, 2017, 6:08am UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-error-logs/100582/7 "2017-09-15T06:08:32Z")

</div>

Can you be more clear how to do it, As i am very new to this . I dont understand it easily

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [September 15, 2017, 6:12am UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-error-logs/100582/8 "2017-09-15T06:12:53Z")

</div>

How to do **what**?

---

<div class="post-metadata">

### Author: ![pkshara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pkshara/32/48222_2.png) [@pkshara](https://discuss.elastic.co/u/pkshara)
#### Post date: [September 15, 2017, 6:13am UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-error-logs/100582/9 "2017-09-15T06:13:54Z")

</div>

[Mon Nov 28 04:38:24 2016] [error] [client 10.114.34.43] File does not exist: /fep10/oraapps/appl/fep10comn/portal/FEP10\_j201s648/favicon.ico

Grok Pattern for the above error.

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [September 15, 2017, 7:47am UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-error-logs/100582/10 "2017-09-15T07:47:01Z")

</div>

Okay. Then please provide the things I asked for in the bullet list a few posts up.

---

<div class="post-metadata">

### Author: ![pkshara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pkshara/32/48222_2.png) [@pkshara](https://discuss.elastic.co/u/pkshara)
#### Post date: [September 15, 2017, 8:07am UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-error-logs/100582/11 "2017-09-15T08:07:42Z")

</div>

The output which i get,

message:[Mon Nov 28 04:42:21 2016] [error] [client 10.114.34.43] client denied by server configuration: /fep10/oraapps/appl/fep10comn/java/oracle/forms/engine  
@version:1  
@timestamp:14/9/2017 23:02:06 PM  
host:j051s319.jci.com  
path:/data/Ops\_analytics\_EBS/oracle\_ebs\_eu/j201s648/apacheerror.log  
type:logs  
tags:\_grokparsefailure  
\_id:AV6Bcqn7o5C-nkf485it  
\_type:logs  
\_index:logstash\_parsing\_error\_index  
\_score:1

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [September 15, 2017, 10:44am UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-error-logs/100582/12 "2017-09-15T10:44:18Z")

</div>

Sorry, I don't have time for this when you never provide all information I ask for. Maybe someone else has more patience.

---

<div class="post-metadata">

### Author: ![pkshara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pkshara/32/48222_2.png) [@pkshara](https://discuss.elastic.co/u/pkshara)
#### Post date: [September 15, 2017, 1:04pm UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-error-logs/100582/13 "2017-09-15T13:04:41Z")

</div>

Code :

input {  
file {  
path =\> "/data/Ops\_analytics\_EBS/oracle\_ebs\_eu/j201s648/error\_20170913.log"  
start\_position =\> "beginning"  
type =\> "apache\_error"  
}  
}

filter {  
grok {  
match =\>["message","[(?%{DAY} %{MONTH} %{MONTHDAY} %{TIME} %{YEAR})] [%{LOGLEVEL:loglevel}] [client %{IP:clientip}:.\*] %{GREEDYDATA:errormsg}"]

```
add_field => {
	"eventName"=> "grok"
	}
}
geoip {
source => "clientip"
}

```

}

output {  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "logstash\_parsing\_error\_index"  
}  
}

The Error log which i want to push in ES is

[Mon Aug 22 02:41:35 2016] [error] [client 10.96.159.140] File does not exist: /fep10/oraapps/appl/fep10comn/portal/FEP10\_j201s648/favicon.ico

The output which is being indexed in ES or logstash screen is

message:[Mon Nov 28 04:42:21 2016] [error] [client 10.114.34.43] client denied by server configuration: /fep10/oraapps/appl/fep10comn/java/oracle/forms/engine  
@version:1  
@timestamp:14/9/2017 23:02:06 PM  
host:j051s319.jci.com  
path:/data/Ops\_analytics\_EBS/oracle\_ebs\_eu/j201s648/apacheerror.log  
type:logs  
tags:\_grokparsefailure  
\_id:AV6Bcqn7o5C-nkf485it  
\_type:logs  
\_index:logstash\_parsing\_error\_index  
\_score:100:

I want the output in a format where each part of error should be aligned to the data\_name which is mentioned in grok pattern .

n would like to know the cause of \_grokparsefailure as well.

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [September 15, 2017, 1:11pm UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-error-logs/100582/14 "2017-09-15T13:11:45Z")

</div>

> [@pkshara](#):
>
> [client %{IP:clientip}:.\*]

You have a `:` after the `client` pattern which does not seem to match the entry. What happens if you remove this?

---

<div class="post-metadata">

### Author: ![pkshara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pkshara/32/48222_2.png) [@pkshara](https://discuss.elastic.co/u/pkshara)
#### Post date: [September 15, 2017, 1:23pm UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-error-logs/100582/15 "2017-09-15T13:23:10Z")

</div>

It does cleared grokparsefailure error. tnx for that .

I want my error-time to converted in time format. It is getting stored as string. Can you plz guide me where i am going wrong.

Is there any regex pattern where i can convert string into timestamp format?

---

<div class="post-metadata">

### Author: ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)
#### Post date: [September 15, 2017, 1:29pm UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-error-logs/100582/16 "2017-09-15T13:29:44Z")

</div>

You should use a `date` filter to process the date and get it into the right format.

---

<div class="post-metadata">

### Author: ![pkshara](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pkshara/32/48222_2.png) [@pkshara](https://discuss.elastic.co/u/pkshara)
#### Post date: [September 15, 2017, 1:31pm UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-error-logs/100582/17 "2017-09-15T13:31:00Z")

</div>

Thanks for the suggestion , I used date filter before only , now added target in date filter and it works fine 🙂

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [October 13, 2017, 1:31pm UTC](https://discuss.elastic.co/t/grok-pattern-for-apache-error-logs/100582/18 "2017-10-13T13:31:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
