# Issue with parsing nginx log

**URL:** <https://discuss.elastic.co/t/issue-with-parsing-nginx-log/229967>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 27, 2020, 1:50pm UTC](https://discuss.elastic.co/t/issue-with-parsing-nginx-log/229967 "2020-04-27T13:50:06Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Samuel\_Stanislav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/samuel_stanislav/32/67194_2.png) [@Samuel\_Stanislav](https://discuss.elastic.co/u/Samuel_Stanislav)\
**Post date:** [April 27, 2020, 1:50pm UTC](https://discuss.elastic.co/t/issue-with-parsing-nginx-log/229967/1 "2020-04-27T13:50:07Z")

</div>

Hello ,

I m sending Nginx logs via filebeat -\> elastic search -\> Kibana . But already have issue with some logs .

It s look like this type of log is parsing without any problem :

66.249.76.123 - - [24/Apr/2020:17:24:51 +0200] "GET / HTTP/1.1" 200 5249 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/41.0.2272.96 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"

but on the other hand similar log :

62.197.243.55 - - [24/Apr/2020:17:29:22 +0200] "GET / HTTP/1.1" 200 5252 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10\_15\_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.163 Safari/537.36"

throwing error to syslog -

Apr 24 17:29:31 prodserver filebeat[12562]: 2020-04-24T17:29:31.497+0200#011WARN#011elasticsearch/client.go:517#011Cannot index event publisher.Event{Content:beat.Event{Timestamp:time.Time{wall:0xbfa0df569acc421c, ext:321343689727, loc:(\*time.Location)(0x5003080)}, Meta:{"pipeline":"filebeat-7.6.2-nginx-access-default"}, Fields:{"agent":{"ephemeral\_id":"3d9ae7ae-c460-4e7b-b994-f10a681cc10b","hostname":"prodserver","id":"58d1eb1d-9c09-485d-ad7f-28b0066a0054","type":"filebeat","version":"7.6.2"},"ecs":{"version":"1.4.0"},"event":{"dataset":"nginx.access","module":"nginx","timezone":"+02:00"},"fileset":{"name":"access"},"host":{"name":"prodserver"},"input":{"type":"log"},"log":{"file":{"path":"/var/log/nginx/denevy.access.log"},"offset":483636},"message":"62.197.243.55 - - [24/Apr/2020:17:29:22 +0200] "GET / HTTP/1.1" 200 5252 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10\_15\_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.163 Safari/537.36"","service":{"type":"nginx"}}, Private:file.State{Id:"", Finished:false, Fileinfo:(\*os.fileStat)(0xc0008c4d00), Source:"/var/log/nginx/denevy.access.log", Offset:483837, Timestamp:time.Time{wall:0xbfa0df0e51ae7c7f, ext:32190743674, loc:(\*time.Location)(0x5003080)}, TTL:-1, Type:"log", Meta:map[string]string(nil), FileStateOS:file.StateOS{Inode:0x2466a, Device:0xfc00}}, TimeSeries:false}, Flags:0x1, Cache:publisher.EventCache{m:common.MapStr(nil)}} (status=400): {"type":"mapper\_parsing\_exception","reason":"failed to parse field [user\_agent.version] of type [date] in document with id 'ZJ\_OrHEBZWkJKYxN4WlY'. Preview of field's value: '80.0.3987.163'","caused\_by":{"type":"illegal\_argument\_exception","reason":"failed to parse date field [80.0.3987.163] with format [strict\_date\_optional\_time||epoch\_millis]","caused\_by":{"type":"date\_time\_parse\_exception","reason":"Failed to parse with all enclosed parsers"}}}

problem starts :

{"type":"mapper\_parsing\_exception","reason":"failed to parse field [user\_agent.version] of type [date] in document with id 'ZJ\_OrHEBZWkJKYxN4WlY'. Preview of field's value: '80.0.3987.163'","caused\_by":{"type":"illegal\_argument\_exception","reason":"failed to parse date field [80.0.3987.163] with format [strict\_date\_optional\_time||epoch\_millis]","caused\_by":{"type":"date\_time\_parse\_exception","reason":"Failed to parse with all enclosed parsers"}}}

any idea why 99% of my logs doing well , but type with chrome : "(KHTML, like Gecko) Chrome/" - have issue with parse failed to parse field [user\_agent.version]

Using Filebeat/Elasticsearch/Kibana - version 7.6.2

Thanks in advice

---

<div class="post-metadata">

**Author:** ![Luca\_Belluccini](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/luca_belluccini/32/33239_2.png) [@Luca\_Belluccini](https://discuss.elastic.co/u/Luca_Belluccini)\
**Post date:** [April 27, 2020, 2:23pm UTC](https://discuss.elastic.co/t/issue-with-parsing-nginx-log/229967/2 "2020-04-27T14:23:13Z")

</div>

Hello!

Would it be possible to share your `filebeat.yml` and tell us if you're using the Nginx module?

Are you sending events directly to Elasticsearch or via Logstash?

Did you install the Filebeat index template?

---

<div class="post-metadata">

**Author:** ![Samuel\_Stanislav](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/samuel_stanislav/32/67194_2.png) [@Samuel\_Stanislav](https://discuss.elastic.co/u/Samuel_Stanislav)\
**Post date:** [April 27, 2020, 3:36pm UTC](https://discuss.elastic.co/t/issue-with-parsing-nginx-log/229967/4 "2020-04-27T15:36:59Z")

</div>

Hello , issue was with elasticsearch mapping.  
where template have trouble when bacis mapper filebeat-7.6.2 was there .  
After remove filebeat-7.6.2 mapper , and start : filebeat setup --index-management .  
Everything working perfectly .

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 25, 2020, 3:37pm UTC](https://discuss.elastic.co/t/issue-with-parsing-nginx-log/229967/5 "2020-05-25T15:37:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
