# Logstash Apache and Spring log files issue

**URL:** <https://discuss.elastic.co/t/logstash-apache-and-spring-log-files-issue/251717>\
**Category:** Logstash\
**Created:** [October 12, 2020, 5:54am UTC](https://discuss.elastic.co/t/logstash-apache-and-spring-log-files-issue/251717 "2020-10-12T05:54:53Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ashish\_Jindal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashish_jindal/32/46023_2.png) [@Ashish\_Jindal](https://discuss.elastic.co/u/Ashish_Jindal)\
**Post date:** [October 12, 2020, 5:54am UTC](https://discuss.elastic.co/t/logstash-apache-and-spring-log-files-issue/251717/1 "2020-10-12T05:54:53Z")

</div>

Our task was Read both Apache and Springboot log file and add a tag name as given below, to differentiate the logs.

- Apache logfile -\> **apacheLog**
- spring-boot logfile -\> **javaLog**

Print the standard output and write it to **/usr/share/logstash/output.txt** file

we written code as below which is not working please help us -

```
input { 
  file { 
    type => "apache" 
    path => ["/usr/share/logstash/logstash-tutorial.log"] 
    start_position => "beginning"
    ignore_older => 0
  }
  file { 
    type => "java" 
    path => ["/usr/share/logstash/Application-Log/springboot3.log"] 
    codec => multiline {
      pattern => "^%{YEAR}-%{MONTHNUM}-%{MONTHDAY} %{TIME}.*"
      negate => "true"
      what => "previous"
    }
  }
}

filter {
  if [message] =~ "%{COMBINEDAPACHELOG}" {
  grok {
    match => { "message" => "%{COMBINEDAPACHELOG}" }
    add_tag => ["apacheLog"]
  }
  if [message] =~ "\tat" {
    grok {
      match => ["message", "^(\tat)"]
      add_tag => ["JavaLog"]
    }
  }

output {
   stdout {
     codec => 'rubydebug'
   }
    file {
       path => "/usr/share/logstash/output.txt"
    }
 }
```

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [October 12, 2020, 7:21am UTC](https://discuss.elastic.co/t/logstash-apache-and-spring-log-files-issue/251717/2 "2020-10-12T07:21:31Z")

</div>

i think logstash already adds tag witht the path in it.

---

<div class="post-metadata">

**Author:** ![Ashish\_Jindal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashish_jindal/32/46023_2.png) [@Ashish\_Jindal](https://discuss.elastic.co/u/Ashish_Jindal)\
**Post date:** [October 12, 2020, 7:24am UTC](https://discuss.elastic.co/t/logstash-apache-and-spring-log-files-issue/251717/3 "2020-10-12T07:24:02Z")

</div>

our error si

> [2020-10-12T07:19:46,485][ERROR][logstash.agent] Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :exception=\>"LogStash::ConfigurationError", :message=\>"Expected one of #, =\> at line 33, column 11 (byte 694) after filter {\n if [message] =~ "%{COMBINEDAPACHELOG}" {\n grok {\n match =\> { "message" =\> "%{COMBINEDAPACHELOG}" }\n add\_tag =\> ["apacheLog"]\n }\n if [message] =~ "\tat" {\n grok {\n match =\> ["message", "^(\tat)"]\n add\_tag =\> ["JavaLog"]\n }\n }\n\noutput {\n stdout ", :backtrace=\>["/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:42:in `compile_imperative'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:50:in `compile\_graph'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:12:in `block in compile_sources'", "org/jruby/RubyArray.java:2486:in `map'", "/usr/share/logstash/logstash-core/lib/logstash/compiler.rb:11:in `compile_sources'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:51:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:169:in `initialize'", "/usr/share/logstash/logstash-core/lib/logstash/pipeline_action/create.rb:40:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:315:in `block in converge_state'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:141:in `with\_pipelines'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:312:in `block in converge_state'", "org/jruby/RubyArray.java:1734:in `each'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:299:in `converge_state'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:166:in `block in converge\_state\_and\_update'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:141:in `with_pipelines'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:164:in `converge\_state\_and\_update'", "/usr/share/logstash/logstash-core/lib/logstash/agent.rb:90:in `execute'", "/usr/share/logstash/logstash-core/lib/logstash/runner.rb:348:in `block in execute'", "/usr/share/logstash/vendor/bundle/jruby/2.3.0/gems/stud-0.0.23/lib/stud/task.rb:24:in `block in initialize'"]}  
> [2020-10-12T07:19:46,605][INFO][logstash.inputs.metrics] Monitoring License OK  
> [2020-10-12T07:19:48,676][INFO][logstash.pipeline] Pipeline has terminated {:pipeline\_id=\>".monitoring-logstash", :thread=\>"#\<Thread:0x2f0da7ca run\>"}

---

<div class="post-metadata">

**Author:** ![Ashish\_Jindal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ashish_jindal/32/46023_2.png) [@Ashish\_Jindal](https://discuss.elastic.co/u/Ashish_Jindal)\
**Post date:** [October 12, 2020, 7:33am UTC](https://discuss.elastic.co/t/logstash-apache-and-spring-log-files-issue/251717/4 "2020-10-12T07:33:55Z")

</div>

We feel issue with

```
filter {
  if [message] =~ "%{COMBINEDAPACHELOG}" {
  grok {
    match => { "message" => "%{COMBINEDAPACHELOG}" }
    add_tag => ["apacheLog"]
  }
  if [message] =~ "\tat" {
    grok {
      match => ["message", "^(\tat)"]
      add_tag => ["JavaLog"]
    }
  }
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 12, 2020, 2:09pm UTC](https://discuss.elastic.co/t/logstash-apache-and-spring-log-files-issue/251717/5 "2020-10-12T14:09:25Z")

</div>

> [@Ashish\_Jindal](#):
>
> `ignore_older => 0`

The error you quoted is caused by a missing } to end the filter section, so logstash is trying to parse the output section as a filter configuration.

In filebeat, setting ignore\_older to zero disables age based filtering. In logstash, it configures the input to ignore any files more then zero seconds old, which is all files, so the file input will not read anything.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 9, 2020, 2:09pm UTC](https://discuss.elastic.co/t/logstash-apache-and-spring-log-files-issue/251717/6 "2020-11-09T14:09:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
