# Parsing custom Tomcat access log

**URL:** <https://discuss.elastic.co/t/parsing-custom-tomcat-access-log/46362>\
**Category:** Logstash\
**Created:** [April 5, 2016, 9:31am UTC](https://discuss.elastic.co/t/parsing-custom-tomcat-access-log/46362 "2016-04-05T09:31:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![venediger](https://avatars.discourse-cdn.com/v4/letter/v/ac8455/32.png) [@venediger](https://discuss.elastic.co/u/venediger)\
**Post date:** [April 5, 2016, 9:31am UTC](https://discuss.elastic.co/t/parsing-custom-tomcat-access-log/46362/1 "2016-04-05T09:31:16Z")

</div>

Hi,

I have the following log line from tomcat access log:

> 192.123.120.11 (192.33.211.131) - USER123 [23/Mar/2015:00:00:12 +0000] GET /rest/url/v1/state?appStateOnly=true HTTP/1.1 200 111 7 rest.api.package:443

> 192.123.120.12 (192.33.211.131) - USER124 [23/Mar/2015:00:00:13 +0000] GET /rest/ping HTTP/1.1 200 23 177 [download.package.com:443](http://download.package.com:443)

> 192.123.120.12 (192.33.211.131) - USER003 [23/Mar/2015:00:00:14 +0000] GET /rest/url/v1/state?appStateOnly=true HTTP/1.1 200 111 6 rest.api.package:443

I've tried different examples out in the internet, is there a simple way to parse the above values?  
I run Logstash v. 2.3.

Need a bit of help getting past this issue. Thanks!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 5, 2016, 10:02am UTC](https://discuss.elastic.co/t/parsing-custom-tomcat-access-log/46362/2 "2016-04-05T10:02:20Z")

</div>

Providing some examples of what you have tried may be useful for others to help you.

---

<div class="post-metadata">

**Author:** ![venediger](https://avatars.discourse-cdn.com/v4/letter/v/ac8455/32.png) [@venediger](https://discuss.elastic.co/u/venediger)\
**Post date:** [April 5, 2016, 12:29pm UTC](https://discuss.elastic.co/t/parsing-custom-tomcat-access-log/46362/3 "2016-04-05T12:29:20Z")

</div>

I was going to handle those string as csv-file, separating it on the whitespaces. It still looks for the best parsing example to me.

---

<div class="post-metadata">

**Author:** ![venediger](https://avatars.discourse-cdn.com/v4/letter/v/ac8455/32.png) [@venediger](https://discuss.elastic.co/u/venediger)\
**Post date:** [April 5, 2016, 2:18pm UTC](https://discuss.elastic.co/t/parsing-custom-tomcat-access-log/46362/4 "2016-04-05T14:18:28Z")

</div>

Apart the solution mentioned above, I found [http://grokdebug.herokuapp.com](http://grokdebug.herokuapp.com) and [http://grokconstructor.appspot.com](http://grokconstructor.appspot.com), which is easy to develop the regex pattern

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:03am UTC](https://discuss.elastic.co/t/parsing-custom-tomcat-access-log/46362/5 "2017-07-06T05:03:50Z")

</div>


