# Logstash apache access referrer value parsing

**URL:** <https://discuss.elastic.co/t/logstash-apache-access-referrer-value-parsing/51474>\
**Category:** Logstash\
**Created:** [May 31, 2016, 7:06pm UTC](https://discuss.elastic.co/t/logstash-apache-access-referrer-value-parsing/51474 "2016-05-31T19:06:42Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![bhawanaus](https://avatars.discourse-cdn.com/v4/letter/b/94ad74/32.png) [@bhawanaus](https://discuss.elastic.co/u/bhawanaus)\
**Post date:** [May 31, 2016, 7:06pm UTC](https://discuss.elastic.co/t/logstash-apache-access-referrer-value-parsing/51474/1 "2016-05-31T19:06:42Z")

</div>

Hello,

I'm trying to create visualization on Kibana based upon referrer value from apache logs. Below is a sample log from apache access logs.

127.0.0.1 - - [20/May/2016:00:00:14 +0000] "GET /secure/queue/handleQueueIndex.do HTTP/1.1" 200 7127 1232 "[http://localhost:8080/secure/queue/handleQueueIndex.do](http://localhost:8080/secure/queue/handleQueueIndex.do)" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/7.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)"

Grok pattern used:  
%{COMMONAPACHELOG} %{NUMBER:time} %{QS:referrer} %{QS:agent}

Output based upon grok pattern:  
"\_source": {  
"referrer": ""[https://localhost:8080/secure/queue/handleQueueIndex.do](https://localhost:8080/secure/queue/handleQueueIndex.do)"",  
}

I want to parse referrer value and define mapping from it like below. Then create visualization on kibana based on timestamp, count and mapping values.

E.g (Key value pair)  
/secure/queue -\> queue manager  
/secure/rules -\> rule manager

Can someone help me in solving this problem or any example link?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 31, 2016, 8:34pm UTC](https://discuss.elastic.co/t/logstash-apache-access-referrer-value-parsing/51474/2 "2016-05-31T20:34:47Z")

</div>

Use a grok filter to extract the interesting parts of the URL from the `referrer` field and use a translate filter to transform those URL fragments to the human-readable strings you want to display in Kibana.

---

<div class="post-metadata">

**Author:** ![bhawanaus](https://avatars.discourse-cdn.com/v4/letter/b/94ad74/32.png) [@bhawanaus](https://discuss.elastic.co/u/bhawanaus)\
**Post date:** [May 31, 2016, 10:14pm UTC](https://discuss.elastic.co/t/logstash-apache-access-referrer-value-parsing/51474/3 "2016-05-31T22:14:50Z")

</div>

I was trying something like this using mutate and gsub but it's not working I guess. Can you please give me an example on how to do using grok filter and translate as I'm new to ELK

filter {  
grok {  
match =\> { "message" =\> "%{COMMONAPACHELOG} %{NUMBER:time} %{QS:referrer} %{QS:agent}"}  
add\_field =\> ["requestURL", "%{referrer}"]  
}  
mutate {  
gsub =\> ["requestURL", "^._/secure/queue._$", "queue module",  
"requestURL", "^._/secure/rules._$", "rule module"  
]  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 1, 2016, 3:38am UTC](https://discuss.elastic.co/t/logstash-apache-access-referrer-value-parsing/51474/4 "2016-06-01T03:38:15Z")

</div>

The following grok filter should extract the first two path components of the `requestURL` field into a `path` field:

```auto
grok {
  match => [
    "requestURL",
    '^"%{URIPROTO}://%{URIHOST}(?<path>/[^/]+/[^/]+)/',
  ]
}

```

Then use the translate filter to map the contents of the `path` field to whatever you like.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:55am UTC](https://discuss.elastic.co/t/logstash-apache-access-referrer-value-parsing/51474/5 "2017-07-06T04:55:06Z")

</div>


