# Parse Apache Error Logs

**URL:** <https://discuss.elastic.co/t/parse-apache-error-logs/253158>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 23, 2020, 3:31pm UTC](https://discuss.elastic.co/t/parse-apache-error-logs/253158 "2020-10-23T15:31:47Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![prophoto](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Post date:** [October 23, 2020, 3:31pm UTC](https://discuss.elastic.co/t/parse-apache-error-logs/253158/1 "2020-10-23T15:31:47Z")

</div>

Is there something I'm missing? Currently using Filebeat to send Apache 2.4 logs to Elasticsearch. Access logs get parsed fine (well, mostly, have lots of grok errors) but error\_log always shows grok error and inputs log line into message field. Thanks for your help.

---

<div class="post-metadata">

**Author:** ![prophoto](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Post date:** [October 23, 2020, 3:44pm UTC](https://discuss.elastic.co/t/parse-apache-error-logs/253158/2 "2020-10-23T15:44:07Z")

</div>

I just checked. In last 24 hours I had only 28% of my error\_log entries pass the grok filter. Not a very good batting average!!

- 64,216 Total hits
- 46,032 had Grok errors
- 18, 095 listed no Grok Errors

---

<div class="post-metadata">

**Author:** ![fadjar340](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fadjar340/32/43610_2.png) [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Post date:** [October 23, 2020, 4:03pm UTC](https://discuss.elastic.co/t/parse-apache-error-logs/253158/3 "2020-10-23T16:03:25Z")

</div>

Why you make it complex?  
Just use filebeat apache module then send it directly to Elasticsearch...  
There are access and error path to get your logs...

> **[Apache module | Filebeat Reference \[7.9\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-apache.html)**

---

<div class="post-metadata">

**Author:** ![prophoto](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Post date:** [October 23, 2020, 4:15pm UTC](https://discuss.elastic.co/t/parse-apache-error-logs/253158/4 "2020-10-23T16:15:12Z")

</div>

Huh?

> [@fadjar340](#):
>
> Just use filebeat apache module then send it directly to Elasticsearch...

Thats exactly what I'm doing....

---

<div class="post-metadata">

**Author:** ![prophoto](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Post date:** [October 27, 2020, 7:29pm UTC](https://discuss.elastic.co/t/parse-apache-error-logs/253158/5 "2020-10-27T19:29:54Z")

</div>

Help please!

---

<div class="post-metadata">

**Author:** ![fadjar340](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fadjar340/32/43610_2.png) [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Post date:** [October 31, 2020, 2:45am UTC](https://discuss.elastic.co/t/parse-apache-error-logs/253158/6 "2020-10-31T02:45:45Z")

</div>

Please check the filebeat events in the log, or you can see in systemctl status filebeat -l.  
Then you need yo adjust the filebeat.yml configuration following this:

> **[Configure the internal queue | Filebeat Reference \[master\] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/master/configuring-internal-queue.html)**

Try to increase more than events that occured in the filebeat log

---

<div class="post-metadata">

**Author:** ![prophoto](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Post date:** [November 2, 2020, 1:31pm UTC](https://discuss.elastic.co/t/parse-apache-error-logs/253158/7 "2020-11-02T13:31:04Z")

</div>

@fadjar340 how does configuring the internal queue fix grok errors?

---

<div class="post-metadata">

**Author:** ![prophoto](https://avatars.discourse-cdn.com/v4/letter/p/f6c823/32.png) [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Post date:** [November 2, 2020, 1:36pm UTC](https://discuss.elastic.co/t/parse-apache-error-logs/253158/8 "2020-11-02T13:36:28Z")

</div>

Example line with issue:

```auto
Provided Grok expressions do not match field value: [{\"time\":\"2020-11-02 13:31:55.532653\", \"function\" : \"[php7:notice]\", \"process\" : \"[pid17900]\" , \"message\" : \"PHP Notice: Only variables should be assigned by reference in /var/www/hosted-domain.com/httpdocs/category.php on line 209\", \"remoteIP\" : \"207.46.13.97:20955\", \"server\" : \"server8\" }]

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 30, 2020, 3:36pm UTC](https://discuss.elastic.co/t/parse-apache-error-logs/253158/9 "2020-11-30T15:36:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
