# Logstash pipeline example apache.log

**URL:** <https://discuss.elastic.co/t/logstash-pipeline-example-apache-log/41236>\
**Category:** Logstash\
**Created:** [February 9, 2016, 2:37am UTC](https://discuss.elastic.co/t/logstash-pipeline-example-apache-log/41236 "2016-02-09T02:37:51Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![w0lverine](https://avatars.discourse-cdn.com/v4/letter/w/90db22/32.png) [@w0lverine](https://discuss.elastic.co/u/w0lverine)\
**Post date:** [February 9, 2016, 2:37am UTC](https://discuss.elastic.co/t/logstash-pipeline-example-apache-log/41236/1 "2016-02-09T02:37:51Z")

</div>

I am doing my first example of logstash located in the [Documents](https://www.elastic.co/guide/en/logstash/current/advanced-pipeline.html#configuring-file-input) and I am not getting a proper curl output from querying "200" from the apache log tutorial.log file

I have configured my config file correctly(tripled checked). My --configtest ran fine. And so did the:  
`bin/logstash -f first-pipeline.conf`  
And when I issue:  
`curl -XGET 'localhost:9200/alerts/_search?q=response=200'`  
I get the following message:

> {"took":3,"timed\_out":false,"\_shards":{"total":5,"successful":5,"failed":0},"hits":  
> {"total":0,"max\_score":null,"hits":}}

The only problem I could think of is I am querying the wrong index. But when you issue the `-f first-pipeline.conf` which index do we know it went too when we point the config file to a specific file location?

I have two indexes (.kibana and alerts). Any help on how to correctly curl the output of an apache log.

Here is my config file just in case you are wondering:

> input {  
> file {  
> path =\> "/home/suricata/logstash-tutorial.log"  
> start\_position =\> beginning  
> }  
> }

> filter {  
> grok {  
> match =\> { "message" =\> "%{COMBINEDAPACHELOG}"}  
> }   
> geoip {  
> source=\> "clientip"  
> }   
> }  
> output {  
> elasticsearch {}  
> stdout {}  
> }

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 10, 2016, 1:54am UTC](https://discuss.elastic.co/t/logstash-pipeline-example-apache-log/41236/2 "2016-02-10T01:54:16Z")

</div>

Please don't post images of text like that, it's hard to read and may not show up for some people 🙂

What does the output from `_cat/indices` show?

---

<div class="post-metadata">

**Author:** ![w0lverine](https://avatars.discourse-cdn.com/v4/letter/w/90db22/32.png) [@w0lverine](https://discuss.elastic.co/u/w0lverine)\
**Post date:** [February 10, 2016, 3:14am UTC](https://discuss.elastic.co/t/logstash-pipeline-example-apache-log/41236/3 "2016-02-10T03:14:37Z")

</div>

Mark,

Here is my out put states for my indices:

> health status index pri rep docs.count docs.deleted store.size pri.store.size

> yellow open .kibana 1 1 1 0 3.1kb 3.1kb

> yellow open alerts 5 1 0 0 795b 795b

It looks like I get the following message after running logstash with my config file:

> ./logstash -f first-pipeline.conf  
> Settings: Default filter workers: 1  
> Logstash startup completed

And than I just hang there with a blinking cursor. So now I ran a simple config file with logstash using stdin and stdout and it works fine. But what I realized was that as I go through the steps of adding input..filter..output in the apache log example I do not once get an output I just get the same `Logstash startup completed` message at each step of the way. Let me know if you need anymore details.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 10, 2016, 5:36am UTC](https://discuss.elastic.co/t/logstash-pipeline-example-apache-log/41236/4 "2016-02-10T05:36:30Z")

</div>

Ok, your `alerts` index has no docs in it, that 6th column in the cat output tells me that.

Chances are you have run into a [sincedb](https://www.elastic.co/guide/en/logstash/2.1/plugins-inputs-file.html#plugins-inputs-file-sincedb_path) issue. See if you can find and then delete the file.

---

<div class="post-metadata">

**Author:** ![w0lverine](https://avatars.discourse-cdn.com/v4/letter/w/90db22/32.png) [@w0lverine](https://discuss.elastic.co/u/w0lverine)\
**Post date:** [February 11, 2016, 11:49pm UTC](https://discuss.elastic.co/t/logstash-pipeline-example-apache-log/41236/5 "2016-02-11T23:49:42Z")

</div>

I had two .sincedb files at the same time. Deleted but I am still getting a blinking cursor when I issue the following:

> HOME\_NET/bin/logstash -f first-pipeline.conf

I would agree with you that the sincedb was part of the issue. Also, unless It takes more than a few minutes for logstash to log a apache log the problem still persists. (Imagine the cursor is blink on the next line)

> Settings: Default filter workers: 1  
> Logstash startup completed

I will keep troubleshooting. Let me know if you need any more questions asked about details or others paths to confirm something.

UPDATE: [Reading a log file into Logstash - #5 by gruszeckim2](https://discuss.elastic.co/t/reading-a-log-file-into-logstash/24514/5)

There is more to this issue. I will update as I get more information after deciphering the debugging phase.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:11am UTC](https://discuss.elastic.co/t/logstash-pipeline-example-apache-log/41236/6 "2017-07-06T05:11:53Z")

</div>


