# Logstash Filter Pattern for Weblogic application logs

**URL:** <https://discuss.elastic.co/t/logstash-filter-pattern-for-weblogic-application-logs/60078>\
**Category:** Logstash\
**Created:** [September 8, 2016, 12:54pm UTC](https://discuss.elastic.co/t/logstash-filter-pattern-for-weblogic-application-logs/60078 "2016-09-08T12:54:22Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![dvkawa](https://avatars.discourse-cdn.com/v4/letter/d/ccd318/32.png) [@dvkawa](https://discuss.elastic.co/u/dvkawa)\
**Post date:** [September 8, 2016, 12:54pm UTC](https://discuss.elastic.co/t/logstash-filter-pattern-for-weblogic-application-logs/60078/1 "2016-09-08T12:54:23Z")

</div>

Hi ,

I am very new to ELK stack and I am trying to parse our weblogic application server logs using logstash and feed that to Elastic Search index and view in Kibana. Although I am able to get that indexed, I am looking for a way to capture few fields from the logs like log level (info, debug, error) and capture specific errors like connection time out etc. Can some one help with filter patterns for the same?

Thanks for any help.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 8, 2016, 1:28pm UTC](https://discuss.elastic.co/t/logstash-filter-pattern-for-weblogic-application-logs/60078/2 "2016-09-08T13:28:15Z")

</div>

For best results I suggest you edit your post and move it from Logstash-forwarder category to the Logstash category.

---

<div class="post-metadata">

**Author:** ![dvkawa](https://avatars.discourse-cdn.com/v4/letter/d/ccd318/32.png) [@dvkawa](https://discuss.elastic.co/u/dvkawa)\
**Post date:** [September 9, 2016, 2:47am UTC](https://discuss.elastic.co/t/logstash-filter-pattern-for-weblogic-application-logs/60078/3 "2016-09-09T02:47:23Z")

</div>

Thanks, updated the category, any help/suggestion is appreciated.Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 9, 2016, 5:28am UTC](https://discuss.elastic.co/t/logstash-filter-pattern-for-weblogic-application-logs/60078/4 "2016-09-09T05:28:53Z")

</div>

Without knowing exactly what the log looks like it's impossible to give specific help, but I can offer some general advice:

- Read and make sure you understand the examples in the documentation: [https://www.elastic.co/guide/en/logstash/current/config-examples.html](https://www.elastic.co/guide/en/logstash/current/config-examples.html)
- Write a grok filter to extract fields from the event text. If you're not very familiar with regular expressions [http://grokconstructor.appspot.com/](http://grokconstructor.appspot.com/) can be of great help.
- Use a date filter to parse the extracted timestamp into the `@timestamp` field.

---

<div class="post-metadata">

**Author:** ![dvkawa](https://avatars.discourse-cdn.com/v4/letter/d/ccd318/32.png) [@dvkawa](https://discuss.elastic.co/u/dvkawa)\
**Post date:** [September 9, 2016, 5:43am UTC](https://discuss.elastic.co/t/logstash-filter-pattern-for-weblogic-application-logs/60078/5 "2016-09-09T05:43:05Z")

</div>

Many Thanks.  
Log Snippet's screenshot attached.

 ![](https://us1.discourse-cdn.com/elastic/original/2X/8/808dc4e5300598a184ac799cfa2452c25c570485.png)

 ![](https://us1.discourse-cdn.com/elastic/original/2X/e/eb6de97ce9528cbbc65f43632d9085d45d4ecc0b.png)

---

<div class="post-metadata">

**Author:** ![Gokhan\_Sahin](https://avatars.discourse-cdn.com/v4/letter/g/e495f1/32.png) [@Gokhan\_Sahin](https://discuss.elastic.co/u/Gokhan_Sahin)\
**Post date:** [February 15, 2017, 11:36am UTC](https://discuss.elastic.co/t/logstash-filter-pattern-for-weblogic-application-logs/60078/6 "2017-02-15T11:36:27Z")

</div>

Hi

You can examine,

[http://grokconstructor.appspot.com/do/match#result](http://grokconstructor.appspot.com/do/match#result)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:28am UTC](https://discuss.elastic.co/t/logstash-filter-pattern-for-weblogic-application-logs/60078/7 "2017-07-06T04:28:36Z")

</div>


