# Logstash grok filter combinedapachelog does not work

**URL:** https://discuss.elastic.co/t/logstash-grok-filter-combinedapachelog-does-not-work/238133
**Category:** Logstash
**Created:** [June 22, 2020, 5:46pm UTC](https://discuss.elastic.co/t/logstash-grok-filter-combinedapachelog-does-not-work/238133 "2020-06-22T17:46:03Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![ademxoy](https://avatars.discourse-cdn.com/v4/letter/a/ee59a6/32.png) [@ademxoy](https://discuss.elastic.co/u/ademxoy)
#### Post date: [June 22, 2020, 5:46pm UTC](https://discuss.elastic.co/t/logstash-grok-filter-combinedapachelog-does-not-work/238133/1 "2020-06-22T17:46:03Z")

</div>

Grok does not seem to create any outputs for COMBINEDAPACHELOG

Here is my filter:

```auto
filter
{
	grok { 
		match => { "messages" => "%{COMBINEDAPACHELOG}"}
	}
	mutate {
		convert => { "bytes" => "integer" }
	}
	date {
		match => ["timestamp", "dd/MMM/YYYY:HH:mm:ss Z"]
		locale => en
		remove_field => "timestamp"
	}
	geoip {
		source => "clientip"
	}
	useragent {
		source => "user_agent"
		target => "useragent"
	}
}

```

```auto
"74.99.99.99 - - [22/Jun/2020:10:33:06 -0700] \"GET /page.php?link1=test HTTP/1.1\" 200 24330 \"http://xxxxxxxxxxxx.com/read/page.php\" \"Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:77.0) Gecko/20100101 Firefox/77.0\"",

```

Input comes from filebeat to this server. Logstash is version 7.8 and so is filebeat. This used to work work with 7.7 and I made some changes, deleted index from elastic, index patterns from kibana and it stopped working. I know it has nothing to do with elastic and kibana but just wanted to put it out there.

---

<div class="post-metadata">

### Author: ![ademxoy](https://avatars.discourse-cdn.com/v4/letter/a/ee59a6/32.png) [@ademxoy](https://discuss.elastic.co/u/ademxoy)
#### Post date: [June 22, 2020, 5:50pm UTC](https://discuss.elastic.co/t/logstash-grok-filter-combinedapachelog-does-not-work/238133/2 "2020-06-22T17:50:16Z")

</div>

Never mind. After I posted it, I noticed the "s" at the end of "message" in match field.

It started working after I changed the match field to:

```auto
match => { "message" => "%{COMBINEDAPACHELOG}"}

```

I left my original question here in case somebody else makes the same mistake.

Thanks,

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 20, 2020, 5:55pm UTC](https://discuss.elastic.co/t/logstash-grok-filter-combinedapachelog-does-not-work/238133/3 "2020-07-20T17:55:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
