# Logstash | Apache Acces log | Parsing

**URL:** <https://discuss.elastic.co/t/logstash-apache-acces-log-parsing/75822>\
**Category:** Logstash\
**Created:** [February 21, 2017, 6:06am UTC](https://discuss.elastic.co/t/logstash-apache-acces-log-parsing/75822 "2017-02-21T06:06:21Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![aliahsan81](https://avatars.discourse-cdn.com/v4/letter/a/cab0a1/32.png) [@aliahsan81](https://discuss.elastic.co/u/aliahsan81)\
**Post date:** [February 21, 2017, 6:06am UTC](https://discuss.elastic.co/t/logstash-apache-acces-log-parsing/75822/1 "2017-02-21T06:06:21Z")

</div>

Hi All,

I have custom apache log format, I am struggling to make it parse using logstash. Can any one help me.

LogFormat "%{X-Forwarded-For}i %h %l %u %t "%r" %\>s %b "%{Referer}i" "%{User-Agent}i" "%{True-Client-IP}i" %q"

Sample Log output;

Actual Client = 2.50.172.5  
2.20.249.8, 2.20.133.107 = distil IP  
172.31.24.155 = Load Blancer IP

Feb 21 05:24:43 ip-172-31-24-246 apache[29290]: 2.50.172.5 , 2.20.249.8, 2.20.133.107 172.31.24.155 - - [21/Feb/2017:05:24:39 +0000] "GET /ar/property/get\_category\_trends/?property\_id=2439117 HTTP/1.1" 200 401 "[https://www.example.com/ar/to-rent/apartments/abu-dhabi/corniche-area/saraya/live-your-way-2-b-r-apartment-w-city-view-2439117.html](https://www.example.com/ar/to-rent/apartments/abu-dhabi/corniche-area/saraya/live-your-way-2-b-r-apartment-w-city-view-2439117.html)" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.2924.87 Safari/537.36" "2.50.172.5" ?property\_id=2439117

---

<div class="post-metadata">

**Author:** ![lueneburger](https://avatars.discourse-cdn.com/v4/letter/l/f475e1/32.png) [@lueneburger](https://discuss.elastic.co/u/lueneburger)\
**Post date:** [February 21, 2017, 11:26am UTC](https://discuss.elastic.co/t/logstash-apache-acces-log-parsing/75822/2 "2017-02-21T11:26:20Z")

</div>

HI @aliahsan81 ,

did you try %{COMBINEDAPACHELOG:log} ?

and take a look at:

[grok debugger](http://grokdebug.herokuapp.com/)  
[grok patterns](http://grokdebug.herokuapp.com/patterns#)

also did a small example how it could work:

`%{SYSLOGTIMESTAMP:Timestamp}\s%{DATA}\W\s%{IP:Actual_Client}\s\W\s%{IP:distil_IP}\W\s%{IP:distil_IP}\s%{IP:Load_Blancer_IP}\s\W\s\W\s\W%{HTTPDATE:HttpDate}\W\s%{QUOTEDSTRING:request}\s%{INT:Http_code}\s%{INT:bytes}\s%{QUOTEDSTRING:request2}\s%{QUOTEDSTRING:client_info}\s%{QUOTEDSTRING:client_ip_request}\s%{DATA:property}$`

named the fields with the names you provided, maybe that helps 😉

---

<div class="post-metadata">

**Author:** ![aliahsan81](https://avatars.discourse-cdn.com/v4/letter/a/cab0a1/32.png) [@aliahsan81](https://discuss.elastic.co/u/aliahsan81)\
**Post date:** [February 21, 2017, 12:02pm UTC](https://discuss.elastic.co/t/logstash-apache-acces-log-parsing/75822/3 "2017-02-21T12:02:32Z")

</div>

> [@lueneburger](#):
>
> %{SYSLOGTIMESTAMP:Timestamp}\s%{DATA}\W\s%{IP:Actual\_Client}\s\W\s%{IP:distil\_IP}\W\s%{IP:distil\_IP}\s%{IP:Load\_Blancer\_IP}\s\W\s\W\s\W%{HTTPDATE:HttpDate}\W\s%{QUOTEDSTRING:request}\s%{INT:Http\_code}\s%{INT:bytes}\s%{QUOTEDSTRING:request2}\s%{QUOTEDSTRING:client\_info}\s%{QUOTEDSTRING:client\_ip\_request}\s%{DATA:property}$

Thanks

I have added your advice but I think its not working please have a look, Output of logstash

> {  
> "path" =\> "/mnt/efs/all\_logs\_httpd/apache.log",  
> "@timestamp" =\> 2017-02-21T11:59:14.135Z,  
> "geoip" =\> {},  
> "@version" =\> "1",  
> "host" =\> "ip-172-31-26-77",  
> "message" =\> "Feb 19 03:14:11 ip-172-31-24-246 apache[13865]: 77.66.11.145, 23.65.29.108, 195.10.11.229 - - [19/Feb/2017:03:14:10 +0000] "GET /to-rent/apartments/dubai/dubai-marina/mag-218-tower/spacious-2br-with-golf-course-view-in-dubai-marina-2359643.html HTTP/1.1" 410 28082 "-" "uipbot/1.0 ([uipbot@semasio.net](mailto:uipbot@semasio.net))"",  
> "type" =\> "apache-access",  
> "tags" =\> [  
> [0] "\_grokparsefailure",  
> [1] "\_geoip\_lookup\_failure"  
> ]  
> }

Please havea look at my logstash.conf

> input {

> file {  
> path =\> "/mnt/efs/all\_logs\_httpd/apache.log"  
> type =\> "apache-access"  
> start\_position =\> "beginning"  
> }  
> }

> filter {  
> if [type] == "apache-access" { # this is where we use the type from the input section  
> grok {  
> match =\> ["message", "%{SYSLOGTIMESTAMP:Timestamp}\s%{DATA}\W\s%{IP:Actual\_Client}\s\W\s%{IP:distil\_IP}\W\s%{IP:distil\_IP}\s%{IP:Load\_Blancer\_IP}\s\W\s\W\s\W%{HTTPDATE:HttpDate}\W\s%{QUOTEDSTRING:request}\s%{INT:Http\_code}\s%{INT:bytes}\s%{QUOTEDSTRING:request2}\s%{QUOTEDSTRING:client\_info}\s%{QUOTEDSTRING:client\_ip\_request}\s%{DATA:property}$"]  
> }

> }

> geoip {  
> source =\> "clientip"  
> }  
> }

> output {  
> elasticsearch {  
> #user =\> "elastic"
> 
> # password =\> "dsasa"
> 
> hosts =\> localhost

> index =\> "example.com-%{+YYYY.MM.dd}"  
> }  
> stdout {  
> codec =\> rubydebug  
> }  
> }

> "tags" =\> [  
> [0] "\_grokparsefailure",  
> [1] "\_geoip\_lookup\_failure"  
> ]  
> }

---

<div class="post-metadata">

**Author:** ![lueneburger](https://avatars.discourse-cdn.com/v4/letter/l/f475e1/32.png) [@lueneburger](https://discuss.elastic.co/u/lueneburger)\
**Post date:** [February 21, 2017, 1:18pm UTC](https://discuss.elastic.co/t/logstash-apache-acces-log-parsing/75822/4 "2017-02-21T13:18:16Z")

</div>

Hi @aliahsan81 ,

the above filter dont work because there are some differences compared to the first log.

try using only %{COMBINEDAPACHELOG:apache\_log}

grok {  
match =\> ["message", "%{COMBINEDAPACHELOG:apache\_log}"]  
}

---

<div class="post-metadata">

**Author:** ![aliahsan81](https://avatars.discourse-cdn.com/v4/letter/a/cab0a1/32.png) [@aliahsan81](https://discuss.elastic.co/u/aliahsan81)\
**Post date:** [February 22, 2017, 9:36am UTC](https://discuss.elastic.co/t/logstash-apache-acces-log-parsing/75822/5 "2017-02-22T09:36:14Z")

</div>

> [@lueneburger](#):
>
> :apache\_log

Hi @lueneburger

Thanks for advise, I used grok debugger grok patterns and able to prase sample request using grok debugger. But when I inseart same regex in logstash it did not break break my apache log (message) part. Can you please advise what will be the issue.

Ali

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2017, 9:36am UTC](https://discuss.elastic.co/t/logstash-apache-acces-log-parsing/75822/6 "2017-03-22T09:36:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
