# Unable to Parse HTTP Logs when the remote IP is empty

**URL:** <https://discuss.elastic.co/t/unable-to-parse-http-logs-when-the-remote-ip-is-empty/115375>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [January 12, 2018, 10:11pm UTC](https://discuss.elastic.co/t/unable-to-parse-http-logs-when-the-remote-ip-is-empty/115375 "2018-01-12T22:11:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![abhilashusha](https://avatars.discourse-cdn.com/v4/letter/a/7c8e57/32.png) [@abhilashusha](https://discuss.elastic.co/u/abhilashusha)\
**Post date:** [January 12, 2018, 10:11pm UTC](https://discuss.elastic.co/t/unable-to-parse-http-logs-when-the-remote-ip-is-empty/115375/1 "2018-01-12T22:11:15Z")

</div>

HTTP Parsing fails

Grok Pattern Working Logs

```auto
172.27.81.113, 192.34.56.67 - - [07/Jan/2018:19:00:30 -0500] RspTime= 555 microsecond + "GET / HTTP/1.1" 200 3493 - "-" "-"

```

GrokPattern Non Working Log

```auto
- - - [07/Jan/2018:19:00:30 -0500] RspTime= 666 microsecond + "GET / HTTP/1.1" 600 6493 - "-" "-"

```

Grok Pattern I have:

```auto
{
"description": "Parse HTTP Access Logs",
"processors": [
  {
        "grok" : {
      "field" : "message",
      "patterns" : [
       "%{NOTSPACE:client} %{NOTSPACE:ident} %{NOTSPACE:auth} \[%{HTTPDATE:ts}\] (?:RspTime\= %{NUMBER:timetaken} microsecond) %{NOTSPACE:connstatus} \"(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})\" %{NUMBER:response} (?:%{NUMBER:bytes}|-) (?(?:%{HOSTNAME:server})(?:\:%{NUMBER:portnumber})|-) \"(?:%{DATA:referer}|-)\" \"(?:%{DATA:UserAgent}|-)\""
                      ],

```

I tried `(?:%{IPORHOST:client}|-)` and `%{NOTSPACE:client}`, still I face issues with parsing the log which has the first field as `-`.

Can anyone help us?

---

<div class="post-metadata">

**Author:** ![abhilashusha](https://avatars.discourse-cdn.com/v4/letter/a/7c8e57/32.png) [@abhilashusha](https://discuss.elastic.co/u/abhilashusha)\
**Post date:** [January 12, 2018, 10:12pm UTC](https://discuss.elastic.co/t/unable-to-parse-http-logs-when-the-remote-ip-is-empty/115375/2 "2018-01-12T22:12:36Z")

</div>

The non working logs is first three values are `-`.

```auto
- - - [07/Jan/2018:19:00:30 -0500] RspTime= 666 microsecond + "GET / HTTP/1.1" 600 6493 - "-" "-"

```

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [January 16, 2018, 5:55pm UTC](https://discuss.elastic.co/t/unable-to-parse-http-logs-when-the-remote-ip-is-empty/115375/3 "2018-01-16T17:55:45Z")

</div>

You can specify multiple patterns and grok will try each one. `patterns` accepts a list. So if it's easier for you to handle each of these logs as two separate grok patterns then do this.

Are you aware of the simulate API for testing ingest node and the grok tester in Kibana.

- [https://www.elastic.co/guide/en/elasticsearch/reference/master/simulate-pipeline-api.html](https://www.elastic.co/guide/en/elasticsearch/reference/master/simulate-pipeline-api.html)
- [https://www.elastic.co/guide/en/kibana/current/grokdebugger-getting-started.html](https://www.elastic.co/guide/en/kibana/current/grokdebugger-getting-started.html)

Also you might find look it useful to look at the ingest pipeline used by the nginx module. [https://github.com/elastic/beats/blob/59f728a60239d5464575beef911b2ee9a9f2427e/filebeat/module/nginx/access/ingest/default.json#L7](https://github.com/elastic/beats/blob/59f728a60239d5464575beef911b2ee9a9f2427e/filebeat/module/nginx/access/ingest/default.json#L7)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 13, 2018, 5:56pm UTC](https://discuss.elastic.co/t/unable-to-parse-http-logs-when-the-remote-ip-is-empty/115375/4 "2018-02-13T17:56:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
