# Two copy of one log

**URL:** <https://discuss.elastic.co/t/two-copy-of-one-log/91139>\
**Category:** Logstash\
**Created:** [June 28, 2017, 3:46pm UTC](https://discuss.elastic.co/t/two-copy-of-one-log/91139 "2017-06-28T15:46:23Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![erion](https://avatars.discourse-cdn.com/v4/letter/e/779978/32.png) [@erion](https://discuss.elastic.co/u/erion)\
**Post date:** [June 28, 2017, 3:46pm UTC](https://discuss.elastic.co/t/two-copy-of-one-log/91139/1 "2017-06-28T15:46:23Z")

</div>

Hi, when i upload a string of apache log in kibana i see one with real timestamp and the same string with timestamp of uploaded . I use the mapping founded on github here [https://github.com/elastic/examples/tree/master/ElasticStack\_apache](https://github.com/elastic/examples/tree/master/ElasticStack_apache).

 ![](https://us1.discourse-cdn.com/elastic/original/3X/5/8/58b8920da5d6a7d18dbafc1edf840a575f6cb096.png)  
This is json of timestamp uploaded.  
 ![](https://us1.discourse-cdn.com/elastic/original/3X/a/4/a4e0f691a1ad927678fefd33888cfe109be3c31d.png)  
This is json for real date timestamp. I use different string.  
Thanks for replay

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 28, 2017, 5:51pm UTC](https://discuss.elastic.co/t/two-copy-of-one-log/91139/2 "2017-06-28T17:51:45Z")

</div>

In the first example your grok filter isn't working on your log line so the date filter that otherwise would take the timestamp from the log and store it in the `@timestamp` field doesn't work either.

---

<div class="post-metadata">

**Author:** ![erion](https://avatars.discourse-cdn.com/v4/letter/e/779978/32.png) [@erion](https://discuss.elastic.co/u/erion)\
**Post date:** [June 29, 2017, 7:51am UTC](https://discuss.elastic.co/t/two-copy-of-one-log/91139/3 "2017-06-29T07:51:04Z")

</div>

Hi @magnusbaeck i use:  
filter {  
grok {  
match =\> {  
"message" =\> '%{IPORHOST:clientip} %{USER:ident} %{USER:auth} [%{HTTPDATE:timestamp}] "%{WORD:verb} %{DATA:request} HTTP/%{NUMBER:httpversion}" %{NUMBER:respon$  
}  
}  
date {  
match =\> ["timestamp", "dd/MMM/YYYY:HH:mm:ss Z"]  
target =\> "@timestamp"  
locale =\> en  
}  
Now my question is i have the same type of log(apache), why grok filter match only some strings and not all strings? What is wrong?  
Thank you for replay.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 29, 2017, 8:41am UTC](https://discuss.elastic.co/t/two-copy-of-one-log/91139/4 "2017-06-29T08:41:05Z")

</div>

Show an example of a log line that the grok filter couldn't parse. Use copy/paste, don't post a screenshot. Please also post exactly what your grok filter looks like. The configuration you posted above is damaged (your grok expression hardly ends with "%{NUMBER:respon$"). Make sure you post your configuration as preformatted text using the `</>` toolbar button.

---

<div class="post-metadata">

**Author:** ![erion](https://avatars.discourse-cdn.com/v4/letter/e/779978/32.png) [@erion](https://discuss.elastic.co/u/erion)\
**Post date:** [June 29, 2017, 10:10am UTC](https://discuss.elastic.co/t/two-copy-of-one-log/91139/5 "2017-06-29T10:10:40Z")

</div>

@magnusbaeck , this is my grok config:

> grok {  
> match =\> {  
> "message" =\> '%{IPORHOST:clientip} %{USER:ident} %{USER:auth} [%{HTTPDATE:timestamp}] "%{WORD:verb} %{DATA:request} HTTP/%{NUMBER:httpversion}" %{NUMBE:response:int} (?:-|%{NUMBER:bytes:int}) %{QS:referrer} %{QS:agent}'  
> }  
> }

I know you ask me a complete string of log but when i investigate of this issues i've founded some similar anomalies.  
Watch yellow circle.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/7/6/7628df0e10f1fa6c3f549eb0c9f4543921e56c33.png)  
This is the correct match.  
Now watch the damaged match.  
 ![](https://us1.discourse-cdn.com/elastic/original/3X/3/7/37e39a34ee905272fcbc0d06753f61c994a3a307.png)

For me the error is that my filter grok doesn't match the message started with "-"  
Thanks for replays

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 29, 2017, 10:18am UTC](https://discuss.elastic.co/t/two-copy-of-one-log/91139/6 "2017-06-29T10:18:03Z")

</div>

Okay, so replace

```
%{IPORHOST:clientip}

```

with

```
(?:-|%{IPORHOST:clientip})

```

to make the initial IP address optional.

---

<div class="post-metadata">

**Author:** ![erion](https://avatars.discourse-cdn.com/v4/letter/e/779978/32.png) [@erion](https://discuss.elastic.co/u/erion)\
**Post date:** [June 29, 2017, 10:24am UTC](https://discuss.elastic.co/t/two-copy-of-one-log/91139/7 "2017-06-29T10:24:53Z")

</div>

Perfect, thank you very mutch @magnusbaeck

---

<div class="post-metadata">

**Author:** ![erion](https://avatars.discourse-cdn.com/v4/letter/e/779978/32.png) [@erion](https://discuss.elastic.co/u/erion)\
**Post date:** [June 30, 2017, 9:10am UTC](https://discuss.elastic.co/t/two-copy-of-one-log/91139/8 "2017-06-30T09:10:00Z")

</div>

Hi @magnusbaeck I have another problem with that filter grok and i think it's for request or HTTP verbs.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/c/c/cc98d11cd77b310b5bee3db202f0379be319d4e0.png)  
I don't know why but this json data don't be matched by filter grok.  
Thanks for replay

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 30, 2017, 9:18am UTC](https://discuss.elastic.co/t/two-copy-of-one-log/91139/9 "2017-06-30T09:18:31Z")

</div>

Show an example of a log line that the grok filter couldn't parse. Use copy/paste, don't post a screenshot. Please also post exactly what your grok filter looks like.

---

<div class="post-metadata">

**Author:** ![erion](https://avatars.discourse-cdn.com/v4/letter/e/779978/32.png) [@erion](https://discuss.elastic.co/u/erion)\
**Post date:** [June 30, 2017, 9:28am UTC](https://discuss.elastic.co/t/two-copy-of-one-log/91139/10 "2017-06-30T09:28:28Z")

</div>

This is my grok filter

> grok {  
> match =\> {  
> "message" =\> '(?:-|%{IPORHOST:clientip}) %{USER:ident} %{USER:auth} [%{HTTPDATE:timestamp}] "%{WORD:verb} %{DATA:request} HTTP/%{NUMBER:httpversion}" %{NUMBER:response:int} (?:-|%{NUMBER:bytes:int}) %{QS:referrer} %{QS:agent}'  
> }  
> }

and this is two apache log string

> "188.135.227 - - [14/Mar/2017:11:11:15 +0100] "BASELINE-CONTROL /banner/fileadmin/fileadmin/T2uCB7.htm HTTP/1.1" 200 33611 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)" "10.0.148861205248" "-" "59194""

> "188.135.227 - - [14/Mar/2017:11:11:11 +0100] "X-MS-ENUMATTS /banner/fileadmin/vLkgrYq.htm HTTP/1.1" 200 33611 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0)" "10.0.148861205248" "-" "61982""

Thank you very much @magnusbaeck for your help

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 30, 2017, 10:21am UTC](https://discuss.elastic.co/t/two-copy-of-one-log/91139/11 "2017-06-30T10:21:13Z")

</div>

Try `%{NOTSPACE:verb}` instead of `%{WORD:verb}`.

---

<div class="post-metadata">

**Author:** ![erion](https://avatars.discourse-cdn.com/v4/letter/e/779978/32.png) [@erion](https://discuss.elastic.co/u/erion)\
**Post date:** [June 30, 2017, 1:28pm UTC](https://discuss.elastic.co/t/two-copy-of-one-log/91139/12 "2017-06-30T13:28:01Z")

</div>

It go, but why word doesn't go?  
Thank you very much for replay

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 30, 2017, 1:57pm UTC](https://discuss.elastic.co/t/two-copy-of-one-log/91139/13 "2017-06-30T13:57:13Z")

</div>

Because of the hyphens. `\w` doesn't include hyphens.

> <https://github.com/logstash-plugins/logstash-patterns-core/blob/v2.0.5/patterns/grok-patterns#L14>

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 28, 2017, 1:57pm UTC](https://discuss.elastic.co/t/two-copy-of-one-log/91139/14 "2017-07-28T13:57:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
