# Issue with logstash configuration

**URL:** <https://discuss.elastic.co/t/issue-with-logstash-configuration/155031>\
**Category:** Logstash\
**Created:** [November 1, 2018, 2:17pm UTC](https://discuss.elastic.co/t/issue-with-logstash-configuration/155031 "2018-11-01T14:17:17Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![jamesp220291](https://avatars.discourse-cdn.com/v4/letter/j/91b2a8/32.png) [@jamesp220291](https://discuss.elastic.co/u/jamesp220291)\
**Post date:** [November 1, 2018, 2:17pm UTC](https://discuss.elastic.co/t/issue-with-logstash-configuration/155031/1 "2018-11-01T14:17:17Z")

</div>

Hi All

New to the ELK Stack, I am wanting to use it to parse my nginx access logs.

Having two issue, removing client ip field breaks geoip  
and overwriting the message..doesnt work.. it just gives the full message.

My config is below, can anyone see where im going wrong?

filter {  
grok {  
match =\> { "message" =\> "%{WORD:method} %{URIPATHPARAM:request}" }  
overwrite =\> ["message"]  
}  
mutate {  
convert =\> ["response", "integer"]  
convert =\> ["bytes", "integer"]  
convert =\> ["responsetime", "float"]  
}  
geoip {  
source =\> "clientip"  
target =\> "geoip"  
add\_tag =\> ["nginx-geoip"]  
remove\_field =\> ["clientip"]  
}  
date {  
match =\> ["timestamp" , "dd/MMM/YYYY:HH:mm:ss Z"]  
remove\_field =\> ["timestamp"]  
}  
useragent {  
source =\> "agent"  
}  
}

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "weblogs-%{+YYYY.MM.dd}"  
document\_type =\> "nginx\_logs"  
}  
stdout { codec =\> rubydebug }

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 29, 2018, 2:17pm UTC](https://discuss.elastic.co/t/issue-with-logstash-configuration/155031/2 "2018-11-29T14:17:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
