# Simple logstash for syslog and apache error

**URL:** <https://discuss.elastic.co/t/simple-logstash-for-syslog-and-apache-error/29788>\
**Category:** Logstash\
**Created:** [September 22, 2015, 2:39pm UTC](https://discuss.elastic.co/t/simple-logstash-for-syslog-and-apache-error/29788 "2015-09-22T14:39:51Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![lukas\_meier](https://avatars.discourse-cdn.com/v4/letter/l/df705f/32.png) [@lukas\_meier](https://discuss.elastic.co/u/lukas_meier)\
**Post date:** [September 22, 2015, 2:39pm UTC](https://discuss.elastic.co/t/simple-logstash-for-syslog-and-apache-error/29788/1 "2015-09-22T14:39:51Z")

</div>

hello,

im trying to get a logstash config file,  
that can parse syslogs and apachelogs too,

the following conf shows up in a result:  
Error: Expected one of #, =\> at line 37, column 17 (byte 722)

but i didnt changed the output,  
it was always like this,  
just added the

if "\_grokparsefailure" in [tags] {  
mutate {  
type =\> "apache" }  
}}

and suddenly i get the error,  
nothing changed in the output,  
how can be there errors now ?  
pls help me

input {  
lumberjack {  
# The port to listen on  
port =\> 5000

```
# The paths to your ssl cert and key
ssl_certificate => XXX"
ssl_key => "XXX"

    }

```

}  
filter {

if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program} %{GREEDYDATA:syslog\_message}" }  
}

if "\_grokparsefailure" in [tags] {  
mutate {  
type =\> "apache" }

}

else if [type] == "apache" {  
grok {  
match =\> { "message" =\> "%{COMBINEDAPACHELOG}" } }

}

if "\_grokparsefailure" in [tags] {  
mutate {  
type =\> "syslog" }

}  
output {  
elasticsearch { host =\> localhost }  
stdout { codec =\> rubydebug } }

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 22, 2015, 2:44pm UTC](https://discuss.elastic.co/t/simple-logstash-for-syslog-and-apache-error/29788/2 "2015-09-22T14:44:40Z")

</div>

There are two closing curly braces after the lines you just added; neither `if [type] == "syslog" {` nor `filter {` is closed before `output {` begins.

If you indent your configuration files better errors like this will be much easier to spot.

---

<div class="post-metadata">

**Author:** ![lukas\_meier](https://avatars.discourse-cdn.com/v4/letter/l/df705f/32.png) [@lukas\_meier](https://discuss.elastic.co/u/lukas_meier)\
**Post date:** [September 22, 2015, 3:31pm UTC](https://discuss.elastic.co/t/simple-logstash-for-syslog-and-apache-error/29788/3 "2015-09-22T15:31:42Z")

</div>

thanks

didnt saw it anymore

now it works  
but how can i put the \_grokparsefailures out of saving into ES?  
now i got lines at my ES,  
one with \_grokparsefailure on the wrong side(syslog or apache) and one then with the right (syslog or apache)  
if you understand my bad english 😛

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 22, 2015, 5:29pm UTC](https://discuss.elastic.co/t/simple-logstash-for-syslog-and-apache-error/29788/4 "2015-09-22T17:29:18Z")

</div>

If you want to avoid passing messages with `_grokparsefailure` to ES, there's an example of exactly this at the end of the following section in the documentation: [https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#conditionals](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#conditionals)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:28am UTC](https://discuss.elastic.co/t/simple-logstash-for-syslog-and-apache-error/29788/5 "2017-07-06T05:28:21Z")

</div>


