# Mapping Apache HTTPD log output to ECS Schema?

**URL:** https://discuss.elastic.co/t/mapping-apache-httpd-log-output-to-ecs-schema/363082
**Category:** Elasticsearch
**Tags:** ecs-elastic-common-schema
**Created:** [July 13, 2024, 10:09pm UTC](https://discuss.elastic.co/t/mapping-apache-httpd-log-output-to-ecs-schema/363082 "2024-07-13T22:09:18Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![greenbeans](https://avatars.discourse-cdn.com/v4/letter/g/5f9b8f/32.png) [@greenbeans](https://discuss.elastic.co/u/greenbeans)
#### Post date: [July 13, 2024, 10:09pm UTC](https://discuss.elastic.co/t/mapping-apache-httpd-log-output-to-ecs-schema/363082/1 "2024-07-13T22:09:18Z")

</div>

Has anyone mapped the various Apache HTTPD logging variables/output to the Elastic Common Schema? Seems like it should be pretty straightforward but tedious, and really useful.

If you've done any of this, please share!

I've dumped a CSV file of most of the variables here: [Apache HTTPD output variables](https:// pastebin . com / RfsV7bSr ) to help get this started.

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [July 13, 2024, 11:28pm UTC](https://discuss.elastic.co/t/mapping-apache-httpd-log-output-to-ecs-schema/363082/2 "2024-07-13T23:28:59Z")

</div>

Hi @greenbeans

This has already been done with filebeat Apache module.

> **[Apache module | Filebeat Reference \[8.14\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-apache.html)**

Or elastic agent Apache logs integration.

> **[Apache HTTP Server | Documentation](https://www.elastic.co/docs/current/en/integrations/apache)**
>
> Collect logs and metrics from Apache servers with Elastic Agent.

---

<div class="post-metadata">

### Author: ![greenbeans](https://avatars.discourse-cdn.com/v4/letter/g/5f9b8f/32.png) [@greenbeans](https://discuss.elastic.co/u/greenbeans)
#### Post date: [July 14, 2024, 12:38am UTC](https://discuss.elastic.co/t/mapping-apache-httpd-log-output-to-ecs-schema/363082/3 "2024-07-14T00:38:37Z")

</div>

Hi @stephenb

Thanks for the superfast response and pointers to documentation!

I looked over both, and I'll certainly be trying out the Elastic Agent integration.

The filebeat module looks to me like it reads the standard Combined LogFormat plus a few variations. The most detailed one is "Combined Log Format + X-Forwarded-For header + Response time".

I need more, especially the SSL DN of the client, and the UNIQUE\_ID. So I think there's an opportunity to do a more thorough mapping. In the meantime, I'll look through the Apache module's source on github to try to figure out what's already been mapped.

If anyone has more to contribute, please get in touch!

Thanks again,  
-Robert

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [July 14, 2024, 1:40am UTC](https://discuss.elastic.co/t/mapping-apache-httpd-log-output-to-ecs-schema/363082/4 "2024-07-14T01:40:54Z")

</div>

You can install either then make a copy of the ingest pipeline and the modify... It will be a good place to start from.
