# How to grok catalina log file

**URL:** <https://discuss.elastic.co/t/how-to-grok-catalina-log-file/328895>\
**Category:** Logstash\
**Created:** [March 30, 2023, 7:24am UTC](https://discuss.elastic.co/t/how-to-grok-catalina-log-file/328895 "2023-03-30T07:24:33Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![vanhaiit90](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vanhaiit90/32/119189_2.png) [@vanhaiit90](https://discuss.elastic.co/u/vanhaiit90)\
**Post date:** [March 30, 2023, 7:24am UTC](https://discuss.elastic.co/t/how-to-grok-catalina-log-file/328895/1 "2023-03-30T07:24:33Z")

</div>

I have context my config logstash for tomcat

- filtertomcat

> filter {  
> if [fileset][module] == "tomcat" {  
> if [fileset][name] == "tomcatcatalina" {  
> grok {  
> match =\> ["message", "(?m)%{TOMCAT\_DATESTAMP:timestamp} %{LOGLEVEL:severity} %{GREEDYDATA:message}"]  
> overwrite =\> ["message"]  
> }
> 
> mutate {  
> add\_field =\> { "[@metadata][target\_index]" =\> "tomcatcatalina-%{[host][hostname]}-%{+YYYY.MM.dd}" }
> 
> ```
> }
> 
> ```
> 
> mutate {  
> lowercase =\> ["[@metadata][target\_index]" ]  
> }
> 
> date {  
> match =\> ["timestamp", "yyyy-MM-dd HH:mm:ss"]  
> }  
> }  
> }  
> }

- Output

> output {  
> if [service][type] == "system" {  
> if [fileset][name] == "syslog" {  
> elasticsearch {  
> hosts =\> ["localhost:9200"]  
> sniffing =\> true  
> manage\_template =\> false  
> index =\> "%{[@metadata][target\_index]}"  
> document\_type =\> "%{[@metadata][type]}"  
> }  
> }  
> else if [fileset][name] == "auth" {  
> elasticsearch {  
> hosts =\> ["localhost:9200"]  
> sniffing =\> true  
> manage\_template =\> false  
> index =\> "%{[@metadata][target\_index]}"  
> document\_type =\> "%{[@metadata][type]}"  
> }  
> }  
> }
> 
> if [service][module] == "tomcat" {  
> if [fileset][name] == "tomcatcatalina" {  
> elasticsearch {  
> hosts =\> ["localhost:9200"]  
> sniffing =\> true  
> manage\_template =\> false  
> index =\> "%{[@metadata][target\_index]}"  
> document\_type =\> "%{[@metadata][type]}"  
> }  
> }  
> }
> 
> else  
> {  
> file {  
> path =\> "/var/log/logstash/unknown\_messages.log"  
> }  
> }  
> }

- tomcat modules:

> # Module: tomcat
> 
> # Docs: [Tomcat module | Filebeat Reference [8.6] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/8.6/filebeat-module-tomcat.html)
> 
> - module: tomcat  
> access:  
> enabled: true

But is is seem is wrong context in the file configure. Please help me configure it completely and push it to the kibana index

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 27, 2023, 7:24am UTC](https://discuss.elastic.co/t/how-to-grok-catalina-log-file/328895/2 "2023-04-27T07:24:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
