# Ingest custom nginx log format

**URL:** <https://discuss.elastic.co/t/ingest-custom-nginx-log-format/170005>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 26, 2019, 12:34pm UTC](https://discuss.elastic.co/t/ingest-custom-nginx-log-format/170005 "2019-02-26T12:34:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![tback](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tback/32/41236_2.png) [@tback](https://discuss.elastic.co/u/tback)\
**Post date:** [February 26, 2019, 12:34pm UTC](https://discuss.elastic.co/t/ingest-custom-nginx-log-format/170005/1 "2019-02-26T12:34:53Z")

</div>

I'm using filebeat, my setup is pretty plain: I index nginx log files. Now I wan't to log just one more field (`$http_host`). Let's say I prefix every line with that:

```auto
access_log /var/log/nginx/access.log main

```

becomes

```auto
log_format host_main '$http_host $remote_addr - $remote_user [$time_local] "$request" '
                   '$status $body_bytes_sent "$http_referer" '
                   '"$http_user_agent" "$http_x_forwarded_for"';
...
access_log /var/log/nginx/access.log host_main;

```

I'd assume that I can configure nginx module to interprete log lines using a different pattern. I cannot find anything in the filebeat configuration hinting to that.  
How do I add the host\_name to my log entries?

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [February 27, 2019, 8:59am UTC](https://discuss.elastic.co/t/ingest-custom-nginx-log-format/170005/2 "2019-02-27T08:59:55Z")

</div>

Unfortunately, the nginx module of Filebeat does not support by default to add more patterns.  
But to work around the issue you could install your own nginx pipeline on Elasticsearch.  
The pipeline which is loaded to ES is located under `module/nginx/acces/ingest/default.json`. You could add one more pattern to the first `grok` processor of the pipeline to parse your messages correctly. After you add the extra pattern, you need to upload the pipeline to ES again using `/filebeat setup --pipelines -modules=nginx`.  
Let me know if you need further help with that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 27, 2019, 8:59am UTC](https://discuss.elastic.co/t/ingest-custom-nginx-log-format/170005/3 "2019-03-27T08:59:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
