# Grok to parse SAP NetWeaver access logs

**URL:** <https://discuss.elastic.co/t/grok-to-parse-sap-netweaver-access-logs/79664>\
**Category:** Logstash\
**Created:** [March 23, 2017, 1:27am UTC](https://discuss.elastic.co/t/grok-to-parse-sap-netweaver-access-logs/79664 "2017-03-23T01:27:25Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![zhmq0124v](https://avatars.discourse-cdn.com/v4/letter/z/f08c70/32.png) [@zhmq0124v](https://discuss.elastic.co/u/zhmq0124v)\
**Post date:** [March 23, 2017, 1:27am UTC](https://discuss.elastic.co/t/grok-to-parse-sap-netweaver-access-logs/79664/1 "2017-03-23T01:27:25Z")

</div>

Hi,

I am trying to parse the following log but failed, as you can see first 12 lines are not needed and from line 12 it's CATALINA\_DATESTAMP, client ip, http verb, URL, http version, http code, data size and response time.  
How to parse this log file? I am stuck at grok match, thanks.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/a/8/a8756a93da3211103a8fa61060bdd08153a86436.jpg)

Best regards,  
Mike

---

<div class="post-metadata">

**Author:** ![zhmq0124v](https://avatars.discourse-cdn.com/v4/letter/z/f08c70/32.png) [@zhmq0124v](https://discuss.elastic.co/u/zhmq0124v)\
**Post date:** [March 23, 2017, 2:02am UTC](https://discuss.elastic.co/t/grok-to-parse-sap-netweaver-access-logs/79664/2 "2017-03-23T02:02:06Z")

</div>

After browsing this forum, I found the pattern, thank you all.

filter {  
if [path] =~ "access" {  
mutate { replace =\> { "type" =\> "pqm\_access" } }  
grok {  
match =\> { "message" =\> "[%{CATALINA\_DATESTAMP:timestamp}] - %{IPV4:clientip} : %{WORD:verb} %{NOTSPACE:rawrequest} %{NOTSPACE:httpversion} %{NUMBER:httpcode} %{NUMBER:respbytes} [%{NUMBER:resptime}]" }  
}  
}  
date {  
match =\> ["timestamp" , "MMM dd, YYYY hh:mm:ss a"]  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 20, 2017, 2:02am UTC](https://discuss.elastic.co/t/grok-to-parse-sap-netweaver-access-logs/79664/3 "2017-04-20T02:02:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
