# Logstash to parse only part of apache log file

**URL:** <https://discuss.elastic.co/t/logstash-to-parse-only-part-of-apache-log-file/161682>\
**Category:** Logstash\
**Created:** [December 20, 2018, 11:25am UTC](https://discuss.elastic.co/t/logstash-to-parse-only-part-of-apache-log-file/161682 "2018-12-20T11:25:34Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![elk\_dni\_1](https://avatars.discourse-cdn.com/v4/letter/e/82dd89/32.png) [@elk\_dni\_1](https://discuss.elastic.co/u/elk_dni_1)\
**Post date:** [December 20, 2018, 11:25am UTC](https://discuss.elastic.co/t/logstash-to-parse-only-part-of-apache-log-file/161682/1 "2018-12-20T11:25:35Z")

</div>

Hi Guys,

I am re-indexing few ones. They are monthly.

I deleted the a month index say Oct 2018 one.

Oct Index contains data :  
Oct 1st UTC - Oct 31 UTC

But my apache logs are in PST and are rotated daily. So I need to put log files from "Sep 30 5 PM PST - Oct 30 4:59 PM PST" for Oct ELK Index (UTC).

Is there a way to make logstash to parse only portion of log file instead of complete file, so that I can pass Sep 30 PST and Oct 30 PST log files and can ask logstatsh to pick from/till time specified.

Thanks

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 20, 2018, 12:03pm UTC](https://discuss.elastic.co/t/logstash-to-parse-only-part-of-apache-log-file/161682/2 "2018-12-20T12:03:30Z")

</div>

No, I do not think that is possible, but you might be able to use a drop filter to avoid processing data outside a specific interval.

---

<div class="post-metadata">

**Author:** ![elk\_dni\_1](https://avatars.discourse-cdn.com/v4/letter/e/82dd89/32.png) [@elk\_dni\_1](https://discuss.elastic.co/u/elk_dni_1)\
**Post date:** [December 20, 2018, 12:13pm UTC](https://discuss.elastic.co/t/logstash-to-parse-only-part-of-apache-log-file/161682/3 "2018-12-20T12:13:55Z")

</div>

So what is the efficient way for my issue and also to regenerate indexes ...

---

<div class="post-metadata">

**Author:** ![elk\_dni\_1](https://avatars.discourse-cdn.com/v4/letter/e/82dd89/32.png) [@elk\_dni\_1](https://discuss.elastic.co/u/elk_dni_1)\
**Post date:** [December 20, 2018, 1:38pm UTC](https://discuss.elastic.co/t/logstash-to-parse-only-part-of-apache-log-file/161682/4 "2018-12-20T13:38:33Z")

</div>

Hi Christian

Is there a way to monitor how much of a log file is parsed by logstash. As during downtimes of systems, where we have to stop logstash and es running processes, are they re-runnable. I mean they will start again where they left. Please suggest how to handle ELK processing during/post downtimes.

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 17, 2019, 1:38pm UTC](https://discuss.elastic.co/t/logstash-to-parse-only-part-of-apache-log-file/161682/5 "2019-01-17T13:38:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
