# Logstash won't parse tomcat file

**URL:** <https://discuss.elastic.co/t/logstash-wont-parse-tomcat-file/185648>\
**Category:** Logstash\
**Created:** [June 13, 2019, 1:00pm UTC](https://discuss.elastic.co/t/logstash-wont-parse-tomcat-file/185648 "2019-06-13T13:00:34Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Andreasky](https://avatars.discourse-cdn.com/v4/letter/a/57b2e6/32.png) [@Andreasky](https://discuss.elastic.co/u/Andreasky)\
**Post date:** [June 13, 2019, 1:00pm UTC](https://discuss.elastic.co/t/logstash-wont-parse-tomcat-file/185648/1 "2019-06-13T13:00:34Z")

</div>

I'm trying to parse a tomcat file, but the docs count in Kibana shows 0. It seems like there is something wrong with the filter I have added.

input {  
file {  
type =\> 'tomcat'  
path =\> "C:\Users\me\Downloads\access\_log.log"  
start\_position =\> "beginning"  
}  
}

filter {  
if [type] == "tomcat" {  
grok {  
match =\> ["message", "%{TOMCATLOG}", "message", "%{CATALINALOG}"]  
}  
date {  
match =\> ["timestamp", "yyyy-MM-dd HH:mm:ss,SSS Z", "MMM dd, yyyy HH:mm:ss a"]  
}  
}  
}

output {  
stdout{}  
elasticsearch {  
hosts =\> ["localhost:9200"]  
}

}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 11, 2019, 1:02pm UTC](https://discuss.elastic.co/t/logstash-wont-parse-tomcat-file/185648/2 "2019-07-11T13:02:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
