# Parse custom Apache2 log

**URL:** https://discuss.elastic.co/t/parse-custom-apache2-log/55736
**Category:** Logstash
**Created:** [July 18, 2016, 8:25am UTC](https://discuss.elastic.co/t/parse-custom-apache2-log/55736 "2016-07-18T08:25:13Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![massinissa](https://avatars.discourse-cdn.com/v4/letter/m/e19b73/32.png) [@massinissa](https://discuss.elastic.co/u/massinissa)
#### Post date: [July 18, 2016, 8:25am UTC](https://discuss.elastic.co/t/parse-custom-apache2-log/55736/1 "2016-07-18T08:25:13Z")

</div>

Hello, i have an Apache log like this:

`443 84.14.49.234 - - [04/Jul/2016:10:11:32 +0200] "GET /ws/1/kpi HTTP/1.1" 200 63 "-" "Mozilla/5.0 (iPhone; CPU **iPhone OS 8_1_3** like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Mobile/12B466[5a612141d67644a1]"`

i would like to extract all bolded elements  
I have already this FILTER config:  
`filter { grok { match => { "message" => "%{COMBINEDAPACHELOG}"} } geoip { source => "clientip" }`  
But i can't extract certain elements, like:  
in "/ws/1/kpi" i need just kpi  
model of phone and version  
in "Mobile/12B466[5a612141d67644a1]" extract in a bracketed text

I hope you can help me.  
Thank you.

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [July 18, 2016, 11:50am UTC](https://discuss.elastic.co/t/parse-custom-apache2-log/55736/2 "2016-07-18T11:50:35Z")

</div>

The easiest is to use additional grok filters to further parse the fields extracted by the COMBINEDAPACHELOG grok pattern. Alternatively, copy the definition of COMBINEDAPACHELOG into the grok filter block of your Logstash configuration and adjust it to suit your needs. This is more work but will be faster (if that matters in your case).

---

<div class="post-metadata">

### Author: ![massinissa](https://avatars.discourse-cdn.com/v4/letter/m/e19b73/32.png) [@massinissa](https://discuss.elastic.co/u/massinissa)
#### Post date: [July 18, 2016, 3:31pm UTC](https://discuss.elastic.co/t/parse-custom-apache2-log/55736/3 "2016-07-18T15:31:47Z")

</div>

Thank you for your answer.

this is my new config:

`filter { grok { patterns_dir => ["./patterns"] match => { "message" => "%{NUMBER:port} %{IP:} - - \[%{HTTPDATE:logedtimestamp}\] \"(?:%{WORD:methode} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})\" %{NUMBER:response} (?:%{NUMBER:bytes}|-) %{QS:referrer} %{TRUEAGENT:trueagent}"} } }`  
With pattern : (logstash/patterns/trueagent)

`TRUEAGENT ([0-9a-f]{16})`

But it doesn't match.  
When i put it without `%{TRUEAGENT:trueagent}` that work, but it not work when i add that.

Thanks

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [July 18, 2016, 3:40pm UTC](https://discuss.elastic.co/t/parse-custom-apache2-log/55736/4 "2016-07-18T15:40:07Z")

</div>

As your expression is written you require a string matching your TRUEAGENT pattern to directly follow the referred, which isn't the case with the actual strings you want to match against. You need something like this:

```
... %{QS:referrer} .*\[%{TRUEAGENT:trueagent}\]\"
```

---

<div class="post-metadata">

### Author: ![massinissa](https://avatars.discourse-cdn.com/v4/letter/m/e19b73/32.png) [@massinissa](https://discuss.elastic.co/u/massinissa)
#### Post date: [July 18, 2016, 4:20pm UTC](https://discuss.elastic.co/t/parse-custom-apache2-log/55736/5 "2016-07-18T16:20:20Z")

</div>

IT WORKS !  
Thank you very much for your help !

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 4:47am UTC](https://discuss.elastic.co/t/parse-custom-apache2-log/55736/6 "2017-07-06T04:47:34Z")

</div>


