# Processing logs from Jersey JAX-RS

**URL:** <https://discuss.elastic.co/t/processing-logs-from-jersey-jax-rs/35576>\
**Category:** Logstash\
**Created:** [November 25, 2015, 3:19pm UTC](https://discuss.elastic.co/t/processing-logs-from-jersey-jax-rs/35576 "2015-11-25T15:19:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![borillo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/borillo/32/6169_2.png) [@borillo](https://discuss.elastic.co/u/borillo)\
**Post date:** [November 25, 2015, 3:19pm UTC](https://discuss.elastic.co/t/processing-logs-from-jersey-jax-rs/35576/1 "2015-11-25T15:19:19Z")

</div>

Hi guys,

First of all, thanks a lot for such an amazing work!!

In our webapps, jersey is generating two entries in the log file, one for the HTTP request and one for the reponse. The problem is that this entries are non-adjacent:

237381 \* Server in-bound request  
237381 \> GET [http://ujiapps.uji.es/upo/rest/contenido/73851657/raw?idioma=CA](http://ujiapps.uji.es/upo/rest/contenido/73851657/raw?idioma=CA)  
237381 \> host: ujiapps.uji.es  
237381 \> accept-encoding: gzip, deflate  
237381 \> user-agent: Mozilla/5.0 (iPhone; CPU iPhone OS 9\_0\_2 like Mac OS X) AppleWebKit/601.1.46 (KHTML, like Gecko) Mobile/13A452  
237381 \> accept-language: es-es  
237381 \> accept: _/_  
237381 \> x-forwarded-proto: http  
237381 \> x\_forwarded\_protocol: http  
237381 \> via: 1.1 ujiapps.uji.es  
237381 \> x-forwarded-for: 77.228.45.125  
237381 \> x-forwarded-host: ujiapps.uji.es  
237381 \> x-forwarded-server: ujiapps.uji.es  
237381 \> connection: Keep-Alive  
237381 \>

...  
more stuff here  
...

237381 \* Server out-bound response  
237381 \< 200  
237381 \< Content-Type: image/jpeg  
237381 \< Content-Disposition: inline; filename="index.jpg"  
237381 \<

As you can see, all the lines have the same "requestid".  
I was messing up with the "multiline" options, but i was unable to merge both message and have a single entry with the request URL and the HTTP response code as attributes ☹

Sometimes, i get other messages arround:

237381 \* Server in-bound request  
237381 \> GET [http://ujiapps.uji.es/upo/rest/contenido/73851657/raw?idioma=CA](http://ujiapps.uji.es/upo/rest/contenido/73851657/raw?idioma=CA)  
237381 \> host: ujiapps.uji.es  
237381 \> accept-encoding: gzip, deflate  
237381 \> user-agent: Mozilla/5.0 (iPhone; CPU iPhone OS 9\_0\_2 like Mac OS X) AppleWebKit/601.1.46 (KHTML, like Gecko) Mobile/13A452  
237381 \> accept-language: es-es  
237381 \> accept: _/_  
237381 \> x-forwarded-proto: http  
237381 \> x\_forwarded\_protocol: http  
237381 \> via: 1.1 ujiapps.uji.es  
237381 \> x-forwarded-for: 77.228.45.125  
237381 \> x-forwarded-host: ujiapps.uji.es  
237381 \> x-forwarded-server: ujiapps.uji.es  
237381 \> connection: Keep-Alive  
237381 \>

237380 \* Server out-bound response  
237380 \< 200  
237380 \< Content-Type: image/jpeg  
237380 \< Content-Disposition: inline; filename="index.jpg"  
237380 \<

237381 \* Server out-bound response  
237381 \< 200  
237381 \< Content-Type: image/jpeg  
237381 \< Content-Disposition: inline; filename="index.jpg"  
237381 \<

Thanks a lot. Your help is very apreciated 🙂

Best regards,  
Ricardo

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 27, 2015, 5:32am UTC](https://discuss.elastic.co/t/processing-logs-from-jersey-jax-rs/35576/2 "2015-11-27T05:32:41Z")

</div>

[https://www.elastic.co/guide/en/logstash/current/plugins-filters-aggregate.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-aggregate.html) should help you.

---

<div class="post-metadata">

**Author:** ![borillo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/borillo/32/6169_2.png) [@borillo](https://discuss.elastic.co/u/borillo)\
**Post date:** [December 22, 2015, 11:55am UTC](https://discuss.elastic.co/t/processing-logs-from-jersey-jax-rs/35576/3 "2015-12-22T11:55:04Z")

</div>

Hi Mark,

Thanks a lot for your valuable help.  
Finally, using aggregate i have solved my problem and now i have one log  
entry with all information abaout the request and the response.

Have a nice holydays 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:17am UTC](https://discuss.elastic.co/t/processing-logs-from-jersey-jax-rs/35576/4 "2017-07-06T05:17:33Z")

</div>


