# Responsetime doesnt come in JSON object in case of %{COMMONAPACHELOG}"

**URL:** <https://discuss.elastic.co/t/responsetime-doesnt-come-in-json-object-in-case-of-commonapachelog/42562>\
**Category:** Logstash\
**Created:** [February 24, 2016, 8:55am UTC](https://discuss.elastic.co/t/responsetime-doesnt-come-in-json-object-in-case-of-commonapachelog/42562 "2016-02-24T08:55:52Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Post date:** [February 24, 2016, 8:55am UTC](https://discuss.elastic.co/t/responsetime-doesnt-come-in-json-object-in-case-of-commonapachelog/42562/1 "2016-02-24T08:55:52Z")

</div>

Hi,  
I am using logstash 1.5.0 as indexer to filter apache access logs.  
I use match =\> { "message" =\> "%{COMMONAPACHELOG}" } in my groke filter.

Sample log is :

> xx.xx.xx.xxx - - [24/Feb/2016:07:45:54 +0200] "GET /serviceprovider/id/101 HTTP/1.1" 500 2267 28

JSON is:

> ```
> {
> "_index": "logstash-2016.02.24",
> "_type": "access-logs",
> "_id": "AVMScwRBC7tfwD5zOg5k",
> "_score": null,
> "_source": {
> "message": "xx.xx.xx.xxx - - [24/Feb/2016:07:45:54 +0200] \"GET /serviceprovider/id/101 HTTP/1.1\" 500 2267 28",
> "@version": "1",
> "@timestamp": "2016-02-24T08:44:00.664Z",
> "type": "access-logs",
> "host": "HostName",
> "path": "localhost-access.log",
> "clientip": "xx.xx.xx.xxx",
> "ident": "-",
> "auth": "-",
> "timestamp": "24/Feb/2016:07:45:54 +0200",
> "verb": "GET",
> "request": "/serviceprovider/id/101",
> "httpversion": "1.1",
> "response": "500",
> "bytes": "2267"
> },
> "fields": {
> "@timestamp": [
> 1456303440664
> ]
> },
> "sort": [
> 1456303440664
> ]
> }
> 
> ```

I am expecting response time which is th elast field should be splited and added in json docuemnt, but it doesn't.  
Also there is not any \_grokeParseFailure error.  
Please guide which format should be used instead of COMMONAPACHELOG

br,  
Sunil Chaudhari

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 24, 2016, 9:14am UTC](https://discuss.elastic.co/t/responsetime-doesnt-come-in-json-object-in-case-of-commonapachelog/42562/2 "2016-02-24T09:14:22Z")

</div>

> I am expecting response time which is th elast field should be splited and added in json docuemnt, but it doesn't.

Why would you expect that? The response time isn't included in the Apache common log format.

> Please guide which format should be used instead of COMMONAPACHELOG

Try this:

```
%{COMMONAPACHELOG} %{INT:response_time:int}

```

You should use the mutate filter's convert option to convert the type of at least the `bytes` field to an integer. Otherwise you won't be able to perform numerical aggregations in e.g. Kibana.

---

<div class="post-metadata">

**Author:** ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Post date:** [February 24, 2016, 9:24am UTC](https://discuss.elastic.co/t/responsetime-doesnt-come-in-json-object-in-case-of-commonapachelog/42562/3 "2016-02-24T09:24:04Z")

</div>

Hi Magnus,  
It doesnt work. It tags \_grokeParseFailure .

br,  
Sunil

---

<div class="post-metadata">

**Author:** ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Post date:** [February 24, 2016, 9:44am UTC](https://discuss.elastic.co/t/responsetime-doesnt-come-in-json-object-in-case-of-commonapachelog/42562/4 "2016-02-24T09:44:12Z")

</div>

Hi,  
It works when I give proper unit in miliseconds:

%{INT:response\_ **ms** :int}

Thanks a lot! 🙂

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 24, 2016, 9:48am UTC](https://discuss.elastic.co/t/responsetime-doesnt-come-in-json-object-in-case-of-commonapachelog/42562/5 "2016-02-24T09:48:53Z")

</div>

Uh, what? The "\_ms" suffix can't possibly have anything to do with this. It must've been something else. Going back to your original sample message,

```
xx.xx.xx.xxx - - [24/Feb/2016:07:45:54 +0200] \"GET /serviceprovider/id/101 HTTP/1.1\" 500 2267 28

```

do you _really_ have backslashes before the double quotes in your log? If so that's why COMMONAPACHELOG doesn't work.

---

<div class="post-metadata">

**Author:** ![sunilmchaudhari](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sunilmchaudhari/32/9475_2.png) [@sunilmchaudhari](https://discuss.elastic.co/u/sunilmchaudhari)\
**Post date:** [February 24, 2016, 11:20am UTC](https://discuss.elastic.co/t/responsetime-doesnt-come-in-json-object-in-case-of-commonapachelog/42562/6 "2016-02-24T11:20:59Z")

</div>

Hi,  
I have tested this twice and I am sure it is because of time units.  
About backslash, its not there, it might be due to manipulation of input log file.

br,  
Sunil

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:09am UTC](https://discuss.elastic.co/t/responsetime-doesnt-come-in-json-object-in-case-of-commonapachelog/42562/7 "2017-07-06T05:09:56Z")

</div>


