# How to parse nginx error\_log in Kibana from file?

**URL:** <https://discuss.elastic.co/t/how-to-parse-nginx-error-log-in-kibana-from-file/279460>\
**Category:** Kibana\
**Created:** [July 23, 2021, 8:50am UTC](https://discuss.elastic.co/t/how-to-parse-nginx-error-log-in-kibana-from-file/279460 "2021-07-23T08:50:12Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![station72](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/station72/32/92032_2.png) [@station72](https://discuss.elastic.co/u/station72)\
**Post date:** [July 23, 2021, 8:50am UTC](https://discuss.elastic.co/t/how-to-parse-nginx-error-log-in-kibana-from-file/279460/1 "2021-07-23T08:50:12Z")

</div>

Hello!  
I have an error log file from nginx.  
I am trying to upload and parse my file with Data Visualizer in Kibana v 7.10.1

Example of my error log

```auto
2021/07/21 04:44:36 [error] 7#7: *24864573 foo could not be resolved (110: Operation timed out), client: 10.1.1.2, server: , request: "GET /foo/api/info HTTP/1.1", host: "foo.bar.local"
2021/07/21 04:44:38 [error] 7#7: *24864628 favicon could not be resolved (110: Operation timed out), client: 10.1.1.2, server: , request: "GET /favicon.ico HTTP/1.1", host: "foo.bar.cloud"

```

grok pattern

```auto
(?<timestamp>%{YEAR}[./]%{MONTHNUM}[./]%{MONTHDAY} %{TIME}) \[%{LOGLEVEL:severity}\] %{POSINT:pid}#%{NUMBER:threadid}\: \*%{NUMBER:connectionid} %{GREEDYDATA:message}, client: %{IP:client}, server: %{GREEDYDATA:server}, request: "(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion}))", host: %{GREEDYDATA:host}

```

When i am trying this log and grok pattern in Dev Tools - everything is all right, but when i am tryin to upload my file i have an issue.  
My settings in Kibata upload settings

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/a/7adcd1177bb582352efdf138eee8229aaf62e35a.png)

Answer is

```auto
File structure cannot be determined
If you know something about this data, such as the file format or timestamp format, adding initial overrides may help us to infer the rest of the structure.

```

I have tried various time formats in settings, but without seccess.

Can you help me with understanding of this error?

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [July 24, 2021, 12:53am UTC](https://discuss.elastic.co/t/how-to-parse-nginx-error-log-in-kibana-from-file/279460/2 "2021-07-24T00:53:39Z")

</div>

Hi, you'll need to set a custom timestamp format of: `yyyy/MM/dd HH:mm:ss`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 21, 2021, 12:54am UTC](https://discuss.elastic.co/t/how-to-parse-nginx-error-log-in-kibana-from-file/279460/3 "2021-08-21T00:54:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
