# Logstash not parsing default nginx logs

**URL:** <https://discuss.elastic.co/t/logstash-not-parsing-default-nginx-logs/199313>\
**Category:** Logstash\
**Created:** [September 12, 2019, 6:29pm UTC](https://discuss.elastic.co/t/logstash-not-parsing-default-nginx-logs/199313 "2019-09-12T18:29:54Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kushal\_Das](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kushal_das/32/54100_2.png) [@Kushal\_Das](https://discuss.elastic.co/u/Kushal_Das)\
**Post date:** [September 12, 2019, 6:29pm UTC](https://discuss.elastic.co/t/logstash-not-parsing-default-nginx-logs/199313/1 "2019-09-12T18:29:54Z")

</div>

Hi,

I am using the latest 7.x series of the stack. The filter pattern is the same for the default `nginx`. But, I can not find any of the `nginx.*` fields, and instead can see the `message` inside of the `_source` field.

Any tips will be helpful.

Here is the pattern I am using:

```auto
filter {
  if [fileset][module] == "nginx" {
    if [fileset][name] == "access" {
      grok {
        match => { "message" => ["%{IPORHOST:[nginx][access][remote_ip]} - %{DATA:[nginx][access][user_name]} \[%{HTTPDATE:[nginx][access][time]}\] \"%{WORD:[nginx][access][method]} %{DATA:[nginx][access][url]} HTTP/%{NUMBER:[nginx][access][http_version]}\" %{NUMBER:[nginx][access][response_code]} %{NUMBER:[nginx][access][body_sent][bytes]} \"%{DATA:[nginx][access][referrer]}\" \"%{DATA:[nginx][access][agent]}\""] }
        remove_field => "message"
      }
      mutate {
        add_field => { "read_timestamp" => "%{@timestamp}" }
      }
      date {
        match => ["[nginx][access][time]", "dd/MMM/YYYY:H:m:s Z" ]
        remove_field => "[nginx][access][time]"
      }
      useragent {
        source => "[nginx][access][agent]"
        target => "[nginx][access][user_agent]"
        remove_field => "[nginx][access][agent]"
      }
      geoip {
        source => "[nginx][access][remote_ip]"
        target => "[nginx][access][geoip]"
      }
    }
    else if [fileset][name] == "error" {
      grok {
        match => { "message" => ["%{DATA:[nginx][error][time]} \[%{DATA:[nginx][error][level]}\] %{NUMBER:[nginx][error][pid]}#%{NUMBER:[nginx][error][tid]}: (\*%{NUMBER:[nginx][error][connection_id]} )?%{GREEDYDATA:[nginx][error][message]}"] }
        remove_field => "message"
      }
      mutate {
        rename => { "@timestamp" => "read_timestamp" }
      }
      date {
        match => ["[nginx][error][time]", "YYYY/MM/dd H:m:s" ]
        remove_field => "[nginx][error][time]"
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 13, 2019, 1:59am UTC](https://discuss.elastic.co/t/logstash-not-parsing-default-nginx-logs/199313/2 "2019-09-13T01:59:27Z")

</div>

Perhaps you might want look at the file beat module for nginx and either send directly to elasticsearch or just use logstash as the pass through. You will get elastic common schems parsing and automatic dashboard and visualization creation.

[https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-nginx.html](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-nginx.html)

Just a thought..

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 11, 2019, 2:09am UTC](https://discuss.elastic.co/t/logstash-not-parsing-default-nginx-logs/199313/3 "2019-10-11T02:09:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
