# Logstash is not splitting apache log fields

**URL:** <https://discuss.elastic.co/t/logstash-is-not-splitting-apache-log-fields/129197>\
**Category:** Logstash\
**Created:** [April 24, 2018, 12:47am UTC](https://discuss.elastic.co/t/logstash-is-not-splitting-apache-log-fields/129197 "2018-04-24T00:47:57Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mriggy](https://avatars.discourse-cdn.com/v4/letter/m/a4c791/32.png) [@mriggy](https://discuss.elastic.co/u/mriggy)\
**Post date:** [April 24, 2018, 12:47am UTC](https://discuss.elastic.co/t/logstash-is-not-splitting-apache-log-fields/129197/1 "2018-04-24T00:47:58Z")

</div>

Hello,

I am trying to parse apache access logs and assign a value to each field. The problem is that the whole message goes into the message field instead. Could you please help with parsing.

conf file:

```
filter {
  if [fields.apachetype] =~ "error" {
    grok {
      patterns_dir => ["/etc/logstash/patterns.d"]
      match => { "message" => "%{COMBINEDAPACHELOG}" }
    }
  } else if [fields.apachetype] =~ "access" {
    grok {
      match => { "message" => "%{COMBINEDAPACHELOG}" }
    }
  }
}

```

 ![12%20PM](https://us1.discourse-cdn.com/elastic/original/3X/b/e/be04f4a9b97ed84adc51a92c7de01cec5a018dc9.png)

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 24, 2018, 6:18am UTC](https://discuss.elastic.co/t/logstash-is-not-splitting-apache-log-fields/129197/2 "2018-04-24T06:18:35Z")

</div>

`[fields][apachetype]`, not `[fields.apachetype]`. See [https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 22, 2018, 6:18am UTC](https://discuss.elastic.co/t/logstash-is-not-splitting-apache-log-fields/129197/3 "2018-05-22T06:18:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
