# Trouble configuring Logstash to Squid Logs

**URL:** <https://discuss.elastic.co/t/trouble-configuring-logstash-to-squid-logs/17920>\
**Category:** Elasticsearch\
**Created:** [June 5, 2014, 8:39am UTC](https://discuss.elastic.co/t/trouble-configuring-logstash-to-squid-logs/17920 "2014-06-05T08:39:24Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![SG\_Chan](https://avatars.discourse-cdn.com/v4/letter/s/ba8739/32.png) [@SG\_Chan](https://discuss.elastic.co/u/SG_Chan)\
**Post date:** [June 5, 2014, 8:39am UTC](https://discuss.elastic.co/t/trouble-configuring-logstash-to-squid-logs/17920/1 "2014-06-05T08:39:24Z")

</div>

My Logstash (1.4.1) config to read Squid log is shown below:

_input { file{ path =\> "/var/log/squid3/access.log" }}filter { grok  
{ match =\> ["message","%{NUMBER:timestamp} \s+  
%{NUMBER:request\_msec:float} %{IPORHOST:src\_ip}  
%{WORD:cache\_result}/%{NUMBER:response\_status:int}  
%{NUMBER:response\_size:int} %{WORD:http\_method}  
(%{URIPROTO:http\_proto}://)?%{IPORHOST:dst\_host}(?::%{POSINT:port})?(?:%{URIPATHPARAM:uri\_param})?  
%{USERNAME:cache\_user} %{WORD:request\_route}/(%{IPORHOST:forwarded\_to}|-)  
%{GREEDYDATA:content\_type}"] add\_tag =\> ["squid"] }  
date { match =\> ["timestamp", "ISO8601"] }}output {  
elasticsearch { host =\> localhost } stdout { codec =\> rubydebug }}_  
I have tested the pattern (using Grok debugger) and it is ok. However,  
Logstash does nothing. It doesn't produce any error message and shows  
nothing when I use "stdout { }".

Can somebody advise me on how to troubleshoot? Many thanks in advance.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/12c57a63-af80-4e77-9251-e724d01ac824%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/12c57a63-af80-4e77-9251-e724d01ac824%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![Antonio\_Augusto\_Sant](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/antonio_augusto_sant/32/82851_2.png) [@Antonio\_Augusto\_Sant](https://discuss.elastic.co/u/Antonio_Augusto_Sant)\
**Post date:** [June 5, 2014, 12:56pm UTC](https://discuss.elastic.co/t/trouble-configuring-logstash-to-squid-logs/17920/2 "2014-06-05T12:56:38Z")

</div>

While not a squid user myself, I do my debugging on logstash by  
increasingly expantind the grok filter.  
For example, try replacing all the content of you match with  
{GREEDYDATA:the\_message} and see if outputs something.

If it does start adding more filters:  
%{NUMBER:timestamp}%{GREEDYDATA:the\_message} and so on, until you find the  
problem.

On Thursday, June 5, 2014 5:39:24 AM UTC-3, SG Chan wrote:

> My Logstash (1.4.1) config to read Squid log is shown below:
> 
> _input { file{ path =\> "/var/log/squid3/access.log" }}filter {  
> grok { match =\> ["message","%{NUMBER:timestamp} \s+  
> %{NUMBER:request\_msec:float} %{IPORHOST:src\_ip}  
> %{WORD:cache\_result}/%{NUMBER:response\_status:int}  
> %{NUMBER:response\_size:int} %{WORD:http\_method}  
> (%{URIPROTO:http\_proto}://)?%{IPORHOST:dst\_host}(?::%{POSINT:port})?(?:%{URIPATHPARAM:uri\_param})?  
> %{USERNAME:cache\_user} %{WORD:request\_route}/(%{IPORHOST:forwarded\_to}|-)  
> %{GREEDYDATA:content\_type}"] add\_tag =\> ["squid"] }  
> date { match =\> ["timestamp", "ISO8601"] }}output {  
> elasticsearch { host =\> localhost } stdout { codec =\> rubydebug }}_  
> I have tested the pattern (using Grok debugger) and it is ok. However,  
> Logstash does nothing. It doesn't produce any error message and shows  
> nothing when I use "stdout { }".
> 
> Can somebody advise me on how to troubleshoot? Many thanks in advance.

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/b70d3404-1a73-4215-a57e-98bdb4195d1b%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/b70d3404-1a73-4215-a57e-98bdb4195d1b%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:24am UTC](https://discuss.elastic.co/t/trouble-configuring-logstash-to-squid-logs/17920/3 "2017-07-06T01:24:29Z")

</div>


