# Haproxy.source not being logged

**URL:** <https://discuss.elastic.co/t/haproxy-source-not-being-logged/175670>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 6, 2019, 9:55am UTC](https://discuss.elastic.co/t/haproxy-source-not-being-logged/175670 "2019-04-06T09:55:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [April 6, 2019, 9:55am UTC](https://discuss.elastic.co/t/haproxy-source-not-being-logged/175670/1 "2019-04-06T09:55:58Z")

</div>

I am using latest (6.7) ES, Kibana, and Filebeat.

The grok patterns in pipeline.json for http log format contain

%{IPORHOST:haproxy.source}

and my log files seem to match OK, but this field is not being logged into my ES? is this intended? I see the field as searchable string field in filebeat-\* index-patterns.

I am running filebeat on saved log files piping straight into ES, no logstash.

I have many haproxy instances and it's important to be able to distinguish them somehow in visualisations.

Ideas?

---

<div class="post-metadata">

**Author:** ![RainTown](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raintown/32/140206_2.png) [@RainTown](https://discuss.elastic.co/u/RainTown)\
**Post date:** [April 10, 2019, 6:16am UTC](https://discuss.elastic.co/t/haproxy-source-not-being-logged/175670/2 "2019-04-10T06:16:33Z")

</div>

So, using the 7.0.0rc2 version of filebeat and elasticsearch I got it to work with my files using this grok:

```auto
"(%{IPORHOST:haproxy.source} %{NOTSPACE:process.name}\\[%{NUMBER:process.pid:long}\\]: )?%{IP:source.address}:%{NUMBER:source.port:long} \\[%{NOTSPACE:haproxy.request_date}\\] %{NOTSPACE:haproxy.frontend_name} %{NOTSPACE:haproxy.backend_name}/%{NOTSPACE:haproxy.server_name} %{NUMBER:haproxy.http.request.time_wait_ms:long}/%{NUMBER:haproxy.total_waiting_time_ms:long}/%{NUMBER:haproxy.connection_wait_time_ms:long}/%{NUMBER:haproxy.http.request.time_wait_without_data_ms:long}/%{NUMBER:temp.duration:long} %{NUMBER:haproxy.http.response.status_code:long} %{NUMBER:haproxy.bytes_read:long} %{NOTSPACE:haproxy.http.request.captured_cookie} %{NOTSPACE:haproxy.http.response.captured_cookie} %{NOTSPACE:haproxy.termination_state} %{NUMBER:haproxy.connections.active:long}/%{NUMBER:haproxy.connections.frontend:long}/%{NUMBER:haproxy.connections.backend:long}/%{NUMBER:haproxy.connections.server:long}/%{NUMBER:haproxy.connections.retries:long} %{NUMBER:haproxy.server_queue:long}/%{NUMBER:haproxy.backend_queue:long} (\\{%{DATA:haproxy.http.request.captured_headers}\\} \\{%{DATA:haproxy.http.response.captured_headers}\\} |\\{%{DATA}\\} )?\"%{GREEDYDATA:haproxy.http.request.raw_request_line}\""

```

Might help someone else down the line ...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 8, 2019, 6:19am UTC](https://discuss.elastic.co/t/haproxy-source-not-being-logged/175670/3 "2019-05-08T06:19:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
