# How to parse Apache log : Logstash plugin or Filebeat module?

**URL:** <https://discuss.elastic.co/t/how-to-parse-apache-log-logstash-plugin-or-filebeat-module/191212>\
**Category:** Logstash\
**Tags:** beats-module\
**Created:** [July 18, 2019, 1:47pm UTC](https://discuss.elastic.co/t/how-to-parse-apache-log-logstash-plugin-or-filebeat-module/191212 "2019-07-18T13:47:38Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Paul\_ALTEN](https://avatars.discourse-cdn.com/v4/letter/p/bcef8e/32.png) [@Paul\_ALTEN](https://discuss.elastic.co/u/Paul_ALTEN)\
**Post date:** [July 18, 2019, 1:47pm UTC](https://discuss.elastic.co/t/how-to-parse-apache-log-logstash-plugin-or-filebeat-module/191212/1 "2019-07-18T13:47:38Z")

</div>

I'm in troubles using ELK stack for analysing my Apache's logs.

Is it better to parse them with Filebeat using the Apache's module directly shipping to Elasticsearch ?  
Or it's better to use grok plugin from Logstash for the Apache's log ?  
Which way is the best and why ?

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [July 26, 2019, 4:01pm UTC](https://discuss.elastic.co/t/how-to-parse-apache-log-logstash-plugin-or-filebeat-module/191212/2 "2019-07-26T16:01:26Z")

</div>

Hi @Paul_ALTEN and welcome 🙂

I'd recommend you to use Filebeat module for Apache, shipping directly to Elasticsearch. The filebeat module includes an ingest pipeline with everything needed to parse Apache logs, this pipeline makes use of the [grok ingest processor](https://www.elastic.co/guide/en/elasticsearch/reference/7.2/grok-processor.html) in Elasticsearch, that is very similar to the Logstash one you mention.

Why is it better? With this option you don't need to maintain Logstash as an additional piece in your infrastructure, and you don't need to implement your own pipeline to parse logs, because it is already provided by the Filebeat module.

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [July 26, 2019, 6:06pm UTC](https://discuss.elastic.co/t/how-to-parse-apache-log-logstash-plugin-or-filebeat-module/191212/3 "2019-07-26T18:06:09Z")

</div>

You can convert the elasticsearch ingest pipelines to logstash format: [https://www.elastic.co/guide/en/logstash/7.2/ingest-converter.html](https://www.elastic.co/guide/en/logstash/7.2/ingest-converter.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2019, 6:07pm UTC](https://discuss.elastic.co/t/how-to-parse-apache-log-logstash-plugin-or-filebeat-module/191212/4 "2019-08-23T18:07:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
