# Logstash does not send apache logs to elasticsearch

**URL:** <https://discuss.elastic.co/t/logstash-does-not-send-apache-logs-to-elasticsearch/90797>\
**Category:** Logstash\
**Created:** [June 26, 2017, 8:53am UTC](https://discuss.elastic.co/t/logstash-does-not-send-apache-logs-to-elasticsearch/90797 "2017-06-26T08:53:06Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![themoisis](https://avatars.discourse-cdn.com/v4/letter/t/ecd19e/32.png) [@themoisis](https://discuss.elastic.co/u/themoisis)\
**Post date:** [June 26, 2017, 8:53am UTC](https://discuss.elastic.co/t/logstash-does-not-send-apache-logs-to-elasticsearch/90797/1 "2017-06-26T08:53:06Z")

</div>

Here is the logstash.conf

input {  
file {  
path =\> "/home/test6/admin\_access.log"  
type =\> "apache-access"  
start\_position =\> "beginning"  
sincedb\_path =\> "/dev/null"

}  
}

filter {  
if [type] == "apache-access" {  
grok {  
match=\> [  
"message" , "%{COMBINEDAPACHELOG}+%{GREEDYDATA:extra\_fields}",  
"message" , "%{COMMONAPACHELOG}+%{GREEDYDATA:extra\_fields}"  
]  
overwrite =\> ["message"]  
}

```
mutate {
  convert => ["response", "integer"]
  convert => ["bytes", "integer"]
  convert => ["responsetime", "float"]

```

}

geoip {  
source =\> "clientip"  
target =\> "geoip"  
add\_tag =\> ["apache-geoip"]  
}

date {  
match =\> ["timestamp" , "dd/MMM/YYYY:HH:mm:ss Z"]  
remove\_field =\> ["timestamp"]  
}

useragent {  
source =\> "agent"  
}  
}  
}

output {  
if [type] == "apache-access" {

# if "\_grokparsefailure" in [tags] {

# null {}

# }

elasticsearch {  
hosts =\> ["es:9200"]  
index =\> "apache-%{+YYYY.MM.dd}"  
document\_type =\> "apache\_logs"  
}  
stdout { codec =\> rubydebug }  
}  
}

But from logstash container, if i create a dummy log entry i can see it in elasticsearch  
/home/test6# logstash-2.1.1/bin/logstash -e 'input { stdin { } } output { elasticsearch { hosts =\> ["es:9200"] } }'

Moreover, my linux user has acccess to the log file admin\_access.log

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [June 26, 2017, 9:06am UTC](https://discuss.elastic.co/t/logstash-does-not-send-apache-logs-to-elasticsearch/90797/2 "2017-06-26T09:06:28Z")

</div>

> [@themoisis](#):
>
> if "\_grokparsefailure" in [tags] {  
> null {}  
> }

This looks invalid. As far as I know there is no `null` output filter. If the intention is to drop these records, you will need to place the conditional in the filter block ad replace the `null` filter with a [drop filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-drop.html).

---

<div class="post-metadata">

**Author:** ![themoisis](https://avatars.discourse-cdn.com/v4/letter/t/ecd19e/32.png) [@themoisis](https://discuss.elastic.co/u/themoisis)\
**Post date:** [June 26, 2017, 9:22am UTC](https://discuss.elastic.co/t/logstash-does-not-send-apache-logs-to-elasticsearch/90797/3 "2017-06-26T09:22:52Z")

</div>

This is commented in my logstash.conf.

That's way it is in bold here. Sorry for this.

input {  
file {  
path =\> "/home/test6/admin\_access.log"  
type =\> "apache-access"  
start\_position =\> "beginning"  
sincedb\_path =\> "/dev/null"

}  
}

filter {  
if [type] == "apache-access" {  
grok {  
match=\> [  
"message" , "%{COMBINEDAPACHELOG}+%{GREEDYDATA:extra\_fields}",  
"message" , "%{COMMONAPACHELOG}+%{GREEDYDATA:extra\_fields}"  
]  
overwrite =\> ["message"]  
}

```
mutate {
  convert => ["response", "integer"]
  convert => ["bytes", "integer"]
  convert => ["responsetime", "float"]

```

}

geoip {  
source =\> "clientip"  
target =\> "geoip"  
add\_tag =\> ["apache-geoip"]  
}

date {  
match =\> ["timestamp" , "dd/MMM/YYYY:HH:mm:ss Z"]  
remove\_field =\> ["timestamp"]  
}

useragent {  
source =\> "agent"  
}  
}  
}

output {  
if [type] == "apache-access" {

elasticsearch {  
hosts =\> ["es:9200"]  
index =\> "apache-%{+YYYY.MM.dd}"  
document\_type =\> "apache\_logs"  
}  
stdout { codec =\> rubydebug }  
}  
}

---

<div class="post-metadata">

**Author:** ![themoisis](https://avatars.discourse-cdn.com/v4/letter/t/ecd19e/32.png) [@themoisis](https://discuss.elastic.co/u/themoisis)\
**Post date:** [June 26, 2017, 10:11am UTC](https://discuss.elastic.co/t/logstash-does-not-send-apache-logs-to-elasticsearch/90797/4 "2017-06-26T10:11:09Z")

</div>

Also:  
logstash version: 2.4.1,

es version: 2.1.1

---

<div class="post-metadata">

**Author:** ![themoisis](https://avatars.discourse-cdn.com/v4/letter/t/ecd19e/32.png) [@themoisis](https://discuss.elastic.co/u/themoisis)\
**Post date:** [June 26, 2017, 10:35am UTC](https://discuss.elastic.co/t/logstash-does-not-send-apache-logs-to-elasticsearch/90797/5 "2017-06-26T10:35:11Z")

</div>

so still getting no logs to es after removing of these 3 lines from my logstash.conf:  
if "\_grokparsefailure" in [tags] {  
null {}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 26, 2017, 11:08am UTC](https://discuss.elastic.co/t/logstash-does-not-send-apache-logs-to-elasticsearch/90797/6 "2017-06-26T11:08:58Z")

</div>

Have you looked in your Logstash logs for clues or indications of problems? Are you getting anything to your stdout output?

---

<div class="post-metadata">

**Author:** ![themoisis](https://avatars.discourse-cdn.com/v4/letter/t/ecd19e/32.png) [@themoisis](https://discuss.elastic.co/u/themoisis)\
**Post date:** [June 26, 2017, 11:31am UTC](https://discuss.elastic.co/t/logstash-does-not-send-apache-logs-to-elasticsearch/90797/7 "2017-06-26T11:31:44Z")

</div>

Yes i got a big logstash.log file. Trying to upload a part of it...

---

<div class="post-metadata">

**Author:** ![themoisis](https://avatars.discourse-cdn.com/v4/letter/t/ecd19e/32.png) [@themoisis](https://discuss.elastic.co/u/themoisis)\
**Post date:** [June 26, 2017, 11:33am UTC](https://discuss.elastic.co/t/logstash-does-not-send-apache-logs-to-elasticsearch/90797/8 "2017-06-26T11:33:13Z")

</div>

> {:timestamp=\>"2017-06-26T08:26:01.056000+0000", :message=\>"Reading config file", :config\_file=\>"/home/test6/logstash.conf", :level=\>:debug, :file=\>"logstash/config/loader.rb", :line=\>"69", :method=\>"local\_config"}  
> {:timestamp=\>"2017-06-26T08:26:01.155000+0000", :message=\>"Plugin not defined in namespace, checking for plugin file", :type=\>"input", :name=\>"file", :path=\>"logstash/inputs/file", :level=\>:debug, :file=\>"logstash/plugin.rb", :line=\>"86", :method=\>"lookup"}  
> {:timestamp=\>"2017-06-26T08:26:01.163000+0000", :message=\>"Plugin not defined in namespace, checking for plugin file", :type=\>"codec", :name=\>"plain", :path=\>"logstash/codecs/plain", :level=\>:debug, :file=\>"logstash/plugin.rb", :line=\>"86", :method=\>"lookup"}  
> {:timestamp=\>"2017-06-26T08:26:01.168000+0000", :message=\>"config LogStash::Codecs::Plain/@charset = "UTF-8"", :level=\>:debug, :file=\>"logstash/config/mixin.rb", :line=\>"154", :method=\>"config\_init"}  
> {:timestamp=\>"2017-06-26T08:26:01.170000+0000", :message=\>"config LogStash::Inputs::File/@path = ["/home/test6/admin\_access.log"]", :level=\>:debug, :file=\>"logstash/config/mixin.rb", :line=\>"154", :method=\>"config\_init"}  
> {:timestamp=\>"2017-06-26T08:26:01.171000+0000", :message=\>"config LogStash::Inputs::File/@type = "apache-access"", :level=\>:debug, :file=\>"logstash/config/mixin.rb", :line=\>"154", :method=\>"config\_init"}  
> {:timestamp=\>"2017-06-26T08:26:01.172000+0000", :message=\>"config LogStash::Inputs::File/@start\_position = "beginning"", :level=\>:debug, :file=\>"logstash/config/mixin.rb", :line=\>"154", :method=\>"config\_init"}  
> {:timestamp=\>"2017-06-26T08:26:01.173000+0000", :message=\>"config LogStash::Inputs::File/@sincedb\_path = "/dev/null"", :level=\>:debug, :file=\>"logstash/config/mixin.rb", :line=\>"154", :method=\>"config\_init"}  
> {:timestamp=\>"2017-06-26T08:26:01.174000+0000", :message=\>"config LogStash::Inputs::File/@codec = \<LogStash::Codecs::Plain charset=\>"UTF-8"\>", :level=\>:debug, :file=\>"logstash/config/mixin.rb", :line=\>"154", :method=\>"config\_init"}

---

<div class="post-metadata">

**Author:** ![themoisis](https://avatars.discourse-cdn.com/v4/letter/t/ecd19e/32.png) [@themoisis](https://discuss.elastic.co/u/themoisis)\
**Post date:** [June 26, 2017, 11:40am UTC](https://discuss.elastic.co/t/logstash-does-not-send-apache-logs-to-elasticsearch/90797/9 "2017-06-26T11:40:48Z")

</div>

Here is the whole log file:  
[https://filetea.me/n3wy0GRCl7xR6GAIDeqxiQoPw](https://filetea.me/n3wy0GRCl7xR6GAIDeqxiQoPw)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 26, 2017, 9:27pm UTC](https://discuss.elastic.co/t/logstash-does-not-send-apache-logs-to-elasticsearch/90797/10 "2017-06-26T21:27:40Z")

</div>

That URL is broken.

---

<div class="post-metadata">

**Author:** ![Vishal\_Sharma1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vishal_sharma1/32/20207_2.png) [@Vishal\_Sharma1](https://discuss.elastic.co/u/Vishal_Sharma1)\
**Post date:** [June 27, 2017, 5:04am UTC](https://discuss.elastic.co/t/logstash-does-not-send-apache-logs-to-elasticsearch/90797/11 "2017-06-27T05:04:51Z")

</div>

There are few things to check

1. Do a config check first
2. Check again the permission of the log file if logstash user is able to read it or not
3. Check logstash & elasticsearch logs both
4. Check if the indices are being created

If you still not able to see the issue please share the logs with us

Vishal

---

<div class="post-metadata">

**Author:** ![themoisis](https://avatars.discourse-cdn.com/v4/letter/t/ecd19e/32.png) [@themoisis](https://discuss.elastic.co/u/themoisis)\
**Post date:** [June 27, 2017, 7:37am UTC](https://discuss.elastic.co/t/logstash-does-not-send-apache-logs-to-elasticsearch/90797/12 "2017-06-27T07:37:28Z")

</div>

Uploaded here:

> **[logstash.log](http://www.mediafire.com/file/wur1od0dv8um2bk/logstash.log)**
>
> MediaFire is a simple to use free service that lets you put all your photos, documents, music, and video in a single place so you can access them anywhere and share them everywhere.

---

<div class="post-metadata">

**Author:** ![Vishal\_Sharma1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vishal_sharma1/32/20207_2.png) [@Vishal\_Sharma1](https://discuss.elastic.co/u/Vishal_Sharma1)\
**Post date:** [June 27, 2017, 7:39am UTC](https://discuss.elastic.co/t/logstash-does-not-send-apache-logs-to-elasticsearch/90797/13 "2017-06-27T07:39:03Z")

</div>

Did you check other points as well ?

---

<div class="post-metadata">

**Author:** ![themoisis](https://avatars.discourse-cdn.com/v4/letter/t/ecd19e/32.png) [@themoisis](https://discuss.elastic.co/u/themoisis)\
**Post date:** [June 27, 2017, 7:40am UTC](https://discuss.elastic.co/t/logstash-does-not-send-apache-logs-to-elasticsearch/90797/14 "2017-06-27T07:40:11Z")

</div>

Thanks Vishal,

I did the checks you mentioned. No indices are created.

Here is the es log:

> [2017-06-26 08:13:32,906][INFO][node] [Bela] version[2.1.1], pid[7], build[40e2c53/2015-12-15T13:05:55Z]  
> [2017-06-26 08:13:32,907][INFO][node] [Bela] initializing ...  
> [2017-06-26 08:13:32,942][INFO][plugins] [Bela] loaded , sites   
> [2017-06-26 08:13:32,959][INFO][env] [Bela] using [1] data paths, mounts [[/ (rootfs)]], net usable\_space [2.8gb], net total\_space [18.2gb], spins? [unknown], types [rootfs]  
> [2017-06-26 08:13:34,097][INFO][node] [Bela] initialized  
> [2017-06-26 08:13:34,098][INFO][node] [Bela] starting ...  
> [2017-06-26 08:13:34,173][WARN][common.network] [Bela] publish address: {0.0.0.0} is a wildcard address, falling back to first non-loopback: {172.17.0.2}  
> [2017-06-26 08:13:34,173][INFO][transport] [Bela] publish\_address {172.17.0.2:9300}, bound\_addresses {[::]:9300}  
> [2017-06-26 08:13:34,179][INFO][discovery] [Bela] elasticsearch/MzC-Dfc9QyKakxIe\_11vUQ  
> [2017-06-26 08:13:37,200][INFO][cluster.service] [Bela] new\_master {Bela}{MzC-Dfc9QyKakxIe\_11vUQ}{172.17.0.2}{172.17.0.2:9300}, reason: zen-disco-join(elected\_as\_master, [0] joins received)  
> [2017-06-26 08:13:37,208][WARN][common.network] [Bela] publish address: {0.0.0.0} is a wildcard address, falling back to first non-loopback: {172.17.0.2}  
> [2017-06-26 08:13:37,208][INFO][http] [Bela] publish\_address {172.17.0.2:9200}, bound\_addresses {[::]:9200}  
> [2017-06-26 08:13:37,208][INFO][node] [Bela] started  
> [2017-06-26 08:13:37,248][INFO][gateway] [Bela] recovered [0] indices into cluster\_state  
> [2017-06-26 08:14:13,769][INFO][cluster.metadata] [Bela] [.kibana] creating index, cause [api], templates , shards [1]/[1], mappings [config]  
> [2017-06-26 08:27:29,013][INFO][cluster.metadata] [Bela] [.kibana] create\_mapping [index-pattern]  
> [2017-06-26 08:27:29,160][INFO][rest.suppressed] /logstash-_/\_mapping/field/_ Params: {ignore\_unavailable=false, allow\_no\_indices=false, index=logstash-_, include\_defaults=true, fields=_, \_=1498465649152}  
> [logstash-\*] IndexNotFoundException[no such index]  
> at org.elasticsearch.cluster.metadata.IndexNameExpressionResolver$WildcardExpressionResolver.resolve(IndexNameExpressionResolver.java:636)  
> at org.elasticsearch.cluster.metadata.IndexNameExpressionResolver.concreteIndices(IndexNameExpressionResolver.java:133)  
> at org.elasticsearch.cluster.metadata.IndexNameExpressionResolver.concreteIndices(IndexNameExpressionResolver.java:77)  
> at org.elasticsearch.action.admin.indices.mapping.get.TransportGetFieldMappingsAction.doExecute(TransportGetFieldMappingsAction.java:57)  
> at org.elasticsearch.action.admin.indices.mapping.get.TransportGetFieldMappingsAction.doExecute(TransportGetFieldMappingsAction.java:40)  
> at org.elasticsearch.action.support.TransportAction.execute(TransportAction.java:70)  
> at org.elasticsearch.client.node.NodeClient.doExecute(NodeClient.java:58)  
> at org.elasticsearch.client.support.AbstractClient.execute(AbstractClient.java:347)  
> at org.elasticsearch.client.FilterClient.doExecute(FilterClient.java:52)  
> at org.elasticsearch.rest.BaseRestHandler$HeadersAndContextCopyClient.doExecute(BaseRestHandler.java:83)  
> at org.elasticsearch.client.support.AbstractClient.execute(AbstractClient.java:347)  
> at org.elasticsearch.client.support.AbstractClient$IndicesAdmin.execute(AbstractClient.java:1183)  
> at org.elasticsearch.client.support.AbstractClient$IndicesAdmin.getFieldMappings(AbstractClient.java:1383)  
> at org.elasticsearch.rest.action.admin.indices.mapping.get.RestGetFieldMappingAction.handleRequest(RestGetFieldMappingAction.java:66)

---

<div class="post-metadata">

**Author:** ![Vishal\_Sharma1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vishal_sharma1/32/20207_2.png) [@Vishal\_Sharma1](https://discuss.elastic.co/u/Vishal_Sharma1)\
**Post date:** [June 27, 2017, 7:46am UTC](https://discuss.elastic.co/t/logstash-does-not-send-apache-logs-to-elasticsearch/90797/15 "2017-06-27T07:46:16Z")

</div>

well show me the output of below command  
$ curl 'localhost:9200/\_cat/indices?v'

---

<div class="post-metadata">

**Author:** ![themoisis](https://avatars.discourse-cdn.com/v4/letter/t/ecd19e/32.png) [@themoisis](https://discuss.elastic.co/u/themoisis)\
**Post date:** [June 27, 2017, 7:48am UTC](https://discuss.elastic.co/t/logstash-does-not-send-apache-logs-to-elasticsearch/90797/16 "2017-06-27T07:48:46Z")

</div>

root@hotelgenius:/home/test6# curl 'localhost:9200/\_cat/indices?v'  
health status index pri rep docs.count docs.deleted store.size pri.store.size  
yellow open .kibana 1 1 1 0 3.1kb 3.1kb

---

<div class="post-metadata">

**Author:** ![Vishal\_Sharma1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vishal_sharma1/32/20207_2.png) [@Vishal\_Sharma1](https://discuss.elastic.co/u/Vishal_Sharma1)\
**Post date:** [June 27, 2017, 7:53am UTC](https://discuss.elastic.co/t/logstash-does-not-send-apache-logs-to-elasticsearch/90797/17 "2017-06-27T07:53:10Z")

</div>

Thank you let me read the logs now

---

<div class="post-metadata">

**Author:** ![Vishal\_Sharma1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vishal_sharma1/32/20207_2.png) [@Vishal\_Sharma1](https://discuss.elastic.co/u/Vishal_Sharma1)\
**Post date:** [June 27, 2017, 8:49am UTC](https://discuss.elastic.co/t/logstash-does-not-send-apache-logs-to-elasticsearch/90797/18 "2017-06-27T08:49:47Z")

</div>

Ok I just might have seen an issue here can you please do me a favor and run below commnads

$ cd /usr/share/logstash  
$ sudo bin/logstash --path.settings /etc/logstash -f /etc/logstash/conf.d/logstash.conf

Check the output and also check what curl 'localhost:9200/\_cat/indices?v' is showing now.

---

<div class="post-metadata">

**Author:** ![themoisis](https://avatars.discourse-cdn.com/v4/letter/t/ecd19e/32.png) [@themoisis](https://discuss.elastic.co/u/themoisis)\
**Post date:** [June 27, 2017, 9:23am UTC](https://discuss.elastic.co/t/logstash-does-not-send-apache-logs-to-elasticsearch/90797/19 "2017-06-27T09:23:26Z")

</div>

Unfortunately, I cannot run above command as i run logstash from a docker container. Logstash docker container does not have the /etc/ folder. I found these images on the net. Below is the logstash docker image:

> FROM java\_image  
> MAINTAINER Author name

> ENV DEBIAN\_FRONTEND noninteractive

> RUN   
> wget [https://download.elastic.co/logstash/logstash/logstash-2.4.1.tar.gz](https://download.elastic.co/logstash/logstash/logstash-2.4.1.tar.gz) &&   
> tar xvzf logstash-2.4.1.tar.gz &&   
> rm -f logstash-2.4.1.tar.gz &&   
> chown -R test6:test6 logstash-2.4.1

> ADD logstash.conf /home/test6

> CMD logstash-2.4.1/bin/logstash -f logstash.conf --debug

And here is the parent image (java image) of the logstash image:

> FROM ubuntu:16.10  
> MAINTAINER Author name

> RUN apt-get update  
> RUN apt-get install -y python-software-properties software-properties-common  
> RUN   
> echo oracle-java8-installer shared/accepted-oracle-license-v1-1 select true | debconf-set-selections &&   
> add-apt-repository -y ppa:webupd8team/java &&   
> apt-get update &&   
> apt-get install -y oracle-java8-installer  
> RUN useradd -m -d /home/test6 test6  
> WORKDIR /home/test6

> ENV JAVA\_HOME /usr/lib/jvm/java-8-oracle

---

<div class="post-metadata">

**Author:** ![themoisis](https://avatars.discourse-cdn.com/v4/letter/t/ecd19e/32.png) [@themoisis](https://discuss.elastic.co/u/themoisis)\
**Post date:** [June 27, 2017, 9:27am UTC](https://discuss.elastic.co/t/logstash-does-not-send-apache-logs-to-elasticsearch/90797/20 "2017-06-27T09:27:13Z")

</div>

So after logging in logstash container (docker exec -it logstash bash), i have:

> root@0d4fde3f9039:/home/test6# ls -a  
> . .. .bash\_logout .bashrc .profile logstash-2.4.1 logstash.conf  
> root@0d4fde3f9039:/home/test6# cd ~  
> root@0d4fde3f9039:~# ls  
> root@0d4fde3f9039:~# ls -a  
> . .. .bash\_history .bashrc .oracle\_jre\_usage .profile

[Next page](https://discuss.elastic.co/t/logstash-does-not-send-apache-logs-to-elasticsearch/90797.md?page=2)
