# HTTPD\_COMBINEDLOG not found with docker

**URL:** <https://discuss.elastic.co/t/httpd-combinedlog-not-found-with-docker/63981>\
**Category:** Logstash\
**Created:** [October 26, 2016, 9:48am UTC](https://discuss.elastic.co/t/httpd-combinedlog-not-found-with-docker/63981 "2016-10-26T09:48:21Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![lendoly](https://avatars.discourse-cdn.com/v4/letter/l/439d5e/32.png) [@lendoly](https://discuss.elastic.co/u/lendoly)\
**Post date:** [October 26, 2016, 9:48am UTC](https://discuss.elastic.co/t/httpd-combinedlog-not-found-with-docker/63981/1 "2016-10-26T09:48:21Z")

</div>

Hi all,

I'm using the ELK stack with Docker, for Logstash I'm using Logstash:latest (that is Logstash 2.4 at the moment, [https://hub.docker.com/\_/logstash/](https://hub.docker.com/_/logstash/)), researching a little in Github and code I see that the patterns for this version were moved to logstash-patterns-core (more info [here](https://github.com/elastic/logstash/commit/b5c069aa1e99d9a8fd4b1063df71076abdfad514)). Not problem until here.

The problems comes when I checked the repository for [logstash-patterns-core](https://github.com/logstash-plugins/logstash-patterns-core) and the patterns for httpd I saw that the COMBINEDAPACHELOG is deprecated and now the correct is use the HTTPD\_COMBINEDLOG, so I tried to use it on my Logstash with the next configuration:

```auto
if [type] == "nginx" and [input_type] == "access" {
    grok {
        match => ["message" , "%{HTTPD_COMBINEDLOG}+%{GREEDYDATA:extra_fields}"]   
        overwrite => ["message"]
    }

   mutate {
       convert => ["response", "integer"]
       convert => ["bytes", "integer"]
       convert => ["responsetime", "float"]
    }

   geoip {
       source => "clientip"
       target => "geoip"
       add_tag => ["nginx-geoip"]
    }

   date {
        match => ["timestamp" , "dd/MMM/YYYY:HH:mm:ss Z"]
        remove_field => ["timestamp"]
    }

   useragent {
        source => "agent"
    }
} 

```

But it fails and show me the next error (quite unreadable):

`{:timestamp=>"2016-10-26T09:32:59.288000+0000", :message=>"Pipeline aborted due to error", :exception=>"Grok::PatternError", :backtrace=>["/opt/logstash/vendor/bundle/jruby/1.9/gems/jls-grok-0.11.3/lib/grok-pure.rb:123:in 'compile'", "org/jruby/RubyKernel.java:1479:in 'loop'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/jls-grok-0.11.3/lib/grok-pure.rb:93:in 'compile'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-filter-grok-2.0.5/lib/logstash/filters/grok.rb:264:in 'register'", "org/jruby/RubyArray.java:1613:in 'each'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-filter-grok-2.0.5/lib/logstash/filters/grok.rb:259:in 'register'", "org/jruby/RubyHash.java:1342:in 'each'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-filter-grok-2.0.5/lib/logstash/filters/grok.rb:255:in 'register'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.4.0-java/lib/logstash/pipeline.rb:182:in 'start_workers'", "org/jruby/RubyArray.java:1613:in 'each'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.4.0-java/lib/logstash/pipeline.rb:182:in 'start_workers'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.4.0-java/lib/logstash/pipeline.rb:136:in 'run'", "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.4.0-java/lib/logstash/agent.rb:491:in 'start_pipeline'"], :level=>:error}`

If I try with the COMBINEDAPACHELOG don't show the error but it fails parsing the log (I can put an example if is required, is not the main of the question but it can be a possible workaround)

Any clue about this error? thanks in advance!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 31, 2016, 8:04pm UTC](https://discuss.elastic.co/t/httpd-combinedlog-not-found-with-docker/63981/2 "2016-10-31T20:04:02Z")

</div>

> The problems comes when I checked the repository for logstash-patterns-core and the patterns for httpd I saw that the COMBINEDAPACHELOG is deprecated and now the correct is use the HTTPD\_COMBINEDLOG, so I tried to use it on my Logstash with the next configuration:

The HTTPD\_COMBINEDLOG pattern isn't available in the logstash-patterns-core plugin that ships with Logstash 2.4. You might be able to upgrade the plugin though.

> If I try with the COMBINEDAPACHELOG don't show the error but it fails parsing the log (I can put an example if is required, is not the main of the question but it can be a possible workaround)

If you want help with the parse failure we need to see what the input looks like.

---

<div class="post-metadata">

**Author:** ![lendoly](https://avatars.discourse-cdn.com/v4/letter/l/439d5e/32.png) [@lendoly](https://discuss.elastic.co/u/lendoly)\
**Post date:** [November 2, 2016, 1:25pm UTC](https://discuss.elastic.co/t/httpd-combinedlog-not-found-with-docker/63981/3 "2016-11-02T13:25:21Z")

</div>

Hi,  
I'm moving to 5.0, so this is not a problem now, but thanks for the help 😃

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 2, 2016, 2:09pm UTC](https://discuss.elastic.co/t/httpd-combinedlog-not-found-with-docker/63981/4 "2016-11-02T14:09:21Z")

</div>

I'd expect HTTPD\_COMBINEDLOG and COMBINEDAPACHELOG to be identical, so if you're having parse errors with the last one I'd be surprised if upgrading to Logstash 5 will help.

---

<div class="post-metadata">

**Author:** ![Dacesilian](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dacesilian/32/18614_2.png) [@Dacesilian](https://discuss.elastic.co/u/Dacesilian)\
**Post date:** [May 30, 2017, 8:01am UTC](https://discuss.elastic.co/t/httpd-combinedlog-not-found-with-docker/63981/5 "2017-05-30T08:01:09Z")

</div>

Even with Logstash 5.4 default installation, HTTPD\_COMBINEDLOG is not available. Solution is to update plugin with command `/usr/share/logstash/bin/logstash-plugin update` and restart logstash (`systemctl restart logstash`).

---

<div class="post-metadata">

**Author:** ![srv\_ER](https://avatars.discourse-cdn.com/v4/letter/s/f4b2a3/32.png) [@srv\_ER](https://discuss.elastic.co/u/srv_ER)\
**Post date:** [June 19, 2017, 6:00am UTC](https://discuss.elastic.co/t/httpd-combinedlog-not-found-with-docker/63981/6 "2017-06-19T06:00:01Z")

</div>

Hi,  
I am currently using logstash 5.4, as per documentation I used "COMBINEDAPACHELOG" for parsing my apache logs and it's working fine. When read the file mentioned below \*, I saw "COMBINEDAPACHELOG" stated under "Deprecated" section. I know for sure it's not deprecated yet as it's parsing my logs correctly.

Questions:

1. Is this feature going to be deprecated in the near future?
2. If not the it would be nice if the response time can also be added to this feature's parsing abilities as it's quite common in production logs.

I am new to ELK and would like to head in the right direction keeping in mind future minor and major upgrades.

THANKS!!

\*/usr/share/logstash/vendor/bundle/jruby/1.9/gems/logstash-patterns-core-4.1.0/patterns/httpd

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 19, 2017, 8:19am UTC](https://discuss.elastic.co/t/httpd-combinedlog-not-found-with-docker/63981/7 "2017-06-19T08:19:43Z")

</div>

> Is this feature going to be deprecated in the near future?

Probably not, but if there's a replacement pattern you might as well start using it.

> If not the it would be nice if the response time can also be added to this feature's parsing abilities as it's quite common in production logs.

Sure, but it's not part of the Combined log format. Additionally, different web servers express response time in different units (Apache microseconds, Tomcat milliseconds, Nginx seconds). I suggest you use COMBINEDAPACHELOG (or something equivalent) together with additions that match your particular format.

---

<div class="post-metadata">

**Author:** ![srv\_ER](https://avatars.discourse-cdn.com/v4/letter/s/f4b2a3/32.png) [@srv\_ER](https://discuss.elastic.co/u/srv_ER)\
**Post date:** [June 19, 2017, 9:30am UTC](https://discuss.elastic.co/t/httpd-combinedlog-not-found-with-docker/63981/8 "2017-06-19T09:30:15Z")

</div>

Thanks for the prompt reply.

---

<div class="post-metadata">

**Author:** ![cdalexndr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cdalexndr/32/55274_2.png) [@cdalexndr](https://discuss.elastic.co/u/cdalexndr)\
**Post date:** [September 6, 2019, 2:15pm UTC](https://discuss.elastic.co/t/httpd-combinedlog-not-found-with-docker/63981/9 "2019-09-06T14:15:31Z")

</div>

Using elastic stack 7.3.0 and when trying to use Kibana Grok Debugger with "%{HTTPD\_COMBINEDLOG}" pattern I get the following error:

> [parse\_exception] [patterns] Invalid regex pattern found in: [%{HTTPD\_COMBINEDLOG}]. Unable to find pattern [HTTPD\_COMBINEDLOG] in Grok's pattern dictionary, with { property\_name="patterns" & processor\_type="grok" }

Using %{COMBINEDAPACHELOG} works.  
Shouldn't HTTPD\_COMBINEDLOG be available after more than 2 years of deprecating HTTPD\_COMBINEDLOG?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 6, 2019, 2:31pm UTC](https://discuss.elastic.co/t/httpd-combinedlog-not-found-with-docker/63981/10 "2019-09-06T14:31:03Z")

</div>

In logstash both work, and one is defined in terms of the other

```
patterns/httpd:COMBINEDAPACHELOG %{HTTPD_COMBINEDLOG}

```

Not sure why it is different in kibana.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 4:30am UTC](https://discuss.elastic.co/t/httpd-combinedlog-not-found-with-docker/63981/11 "2022-11-04T04:30:50Z")

</div>


