# Tomcat access log analysis

**URL:** <https://discuss.elastic.co/t/tomcat-access-log-analysis/341688>\
**Category:** Logstash\
**Created:** [August 25, 2023, 1:10pm UTC](https://discuss.elastic.co/t/tomcat-access-log-analysis/341688 "2023-08-25T13:10:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Brian\_Michelsen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brian_michelsen/32/124965_2.png) [@Brian\_Michelsen](https://discuss.elastic.co/u/Brian_Michelsen)\
**Post date:** [August 25, 2023, 1:10pm UTC](https://discuss.elastic.co/t/tomcat-access-log-analysis/341688/1 "2023-08-25T13:10:16Z")

</div>

Hi,

I have setup Elasticseach, Logstash and Kibana to analyse response times on a application. The pattern of the access log is:

```auto
%a %{request.id}r %{request.username}r %t &quot;%m %U%{sanitized.query}r %H&quot; %s %b %D &quot;%{sanitized.referer}r&quot; &quot;%{User-Agent}i&quot; &quot;%{request.assession.id}r&quot;

```

And I need response/proccessing time (%D), but I'm not sure how to set it up like that, as I have tried all of the methods I found googling.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [September 4, 2023, 5:39pm UTC](https://discuss.elastic.co/t/tomcat-access-log-analysis/341688/2 "2023-09-04T17:39:14Z")

</div>

Ji @Brian_Michelsen welcome to the community.

Is this a custom format?

Is so you will need to parse it yourself using a [grok processor](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html)

If it's a common format, I would suggest using the built-in [Tomcat module](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-tomcat.html) and filebeat. You will not only get it parsed but you will get dashboard to etc.

You don't necessarily need to use Logstash... you can if you want just there are different ingest architectures.

If you want to use Filebeat -\> Logstash -\> Elasticsearch

See [Here](https://www.elastic.co/guide/en/logstash/current/use-ingest-pipelines.html)

But one thing instead of running

`filebeat setup --pipelines --modules nginx,system`

just run  
`filebeat setup -e`  
that sets up everything.

You can also just run

Filebeat -\> Elasticsearch (without Logstash)

You can also just use Logstash but then you will need to parse on your own.

Let us know what you want to do

If it is custom, the easiest way is usually to post a couple of lines of your logs. Most of us don't read Apache Tomcat log syntax.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 2, 2023, 5:39pm UTC](https://discuss.elastic.co/t/tomcat-access-log-analysis/341688/3 "2023-10-02T17:39:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
