# WEB log config file

**URL:** <https://discuss.elastic.co/t/web-log-config-file/122080>\
**Category:** Logstash\
**Created:** [March 1, 2018, 1:46pm UTC](https://discuss.elastic.co/t/web-log-config-file/122080 "2018-03-01T13:46:41Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rahul07](https://avatars.discourse-cdn.com/v4/letter/r/9fc29f/32.png) [@Rahul07](https://discuss.elastic.co/u/Rahul07)\
**Post date:** [March 1, 2018, 1:46pm UTC](https://discuss.elastic.co/t/web-log-config-file/122080/1 "2018-03-01T13:46:42Z")

</div>

HI i am new to ELK

i have created indices and deleted through Kibana by query and manually from C:\ELK\elasticsearch-5.6.3\elasticsearch-5.6.3\data\nodes\0\indices.

when i try to create again indices with config file modification i got below message but new indices is not creating.

Need help

Sending Logstash's logs to C:/ELK/logstash-5.6.3/logstash-5.6.3/logs which is no  
w configured via log4j2.properties  
[2018-03-01T19:05:32,566][INFO][logstash.modules.scaffold] Initializing module  
{:module\_name=\>"fb\_apache", :directory=\>"C:/ELK/logstash-5.6.3/logstash-5.6.3/mo  
dules/fb\_apache/configuration"}  
[2018-03-01T19:05:32,576][INFO][logstash.modules.scaffold] Initializing module  
{:module\_name=\>"netflow", :directory=\>"C:/ELK/logstash-5.6.3/logstash-5.6.3/modu  
les/netflow/configuration"}  
[2018-03-01T19:05:36,526][INFO][logstash.outputs.elasticsearch] Elasticsearch p  
ool URLs updated {:changes=\>{:removed=\>, :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}  
[2018-03-01T19:05:36,529][INFO][logstash.outputs.elasticsearch] Running health  
check to see if an Elasticsearch connection is working {:healthcheck\_url=\>http:/  
/localhost:9200/, :path=\>"/"}  
[2018-03-01T19:05:36,798][WARN][logstash.outputs.elasticsearch] Restored connec  
tion to ES instance {:url=\>"[http://localhost:9200/](http://localhost:9200/)"}  
[2018-03-01T19:05:36,893][INFO][logstash.outputs.elasticsearch] Using mapping t  
emplate from {:path=\>nil}  
[2018-03-01T19:05:36,899][INFO][logstash.outputs.elasticsearch] Attempting to i  
nstall template {:manage\_template=\>{"template"=\>"logstash-\*", "version"=\>50001,  
"settings"=\>{"index.refresh\_interval"=\>"5s"}, "mappings"=\>{"_default_"=\>{"\_all"=

> {"enabled"=\>true, "norms"=\>false}, "dynamic\_templates"=\>[{"message\_field"=\>{"pa  
> th\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text"  
> , "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"\*", "match\_mapping\_type"=\>"str  
> ing", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=  
> "keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"da  
> te", "include\_in\_all"=\>false}, "@version"=\>{"type"=\>"keyword", "include\_in\_all"=  
> false}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "locati  
> on"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"t  
> ype"=\>"half\_float"}}}}}}}}  
> [2018-03-01T19:05:36,914][INFO][logstash.outputs.elasticsearch] New Elasticsear  
> ch output {:class=\>"LogStash::Outputs::Elasticsearch", :hosts=\>["[//localhost:920](https://localhost:920)  
> 0"]}  
> [2018-03-01T19:05:37,217][INFO][logstash.pipeline] Starting pipeline {"  
> id"=\>"main", "pipeline.workers"=\>2, "pipeline.batch.size"=\>125, "pipeline.batch.  
> delay"=\>5, "pipeline.max\_inflight"=\>250}  
> [2018-03-01T19:05:39,950][INFO][logstash.pipeline] Pipeline main starte  
> d  
> [2018-03-01T19:05:40,219][INFO][logstash.agent] Successfully started  
> Logstash API endpoint {:port=\>9600}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 1, 2018, 8:07pm UTC](https://discuss.elastic.co/t/web-log-config-file/122080/2 "2018-03-01T20:07:05Z")

</div>

> i have created indices and deleted through Kibana by query and manually from C:\ELK\elasticsearch-5.6.3\elasticsearch-5.6.3\data\nodes\0\indices.

Don't ever do that. Always delete indices via the APIs.

> when i try to create again indices with config file modification i got below message but new indices is not creating.

You haven't given us any details, but I'm guessing you're using a file input and if you want it to reprocess an old file you need to delete the sincedb file.

---

<div class="post-metadata">

**Author:** ![Rahul07](https://avatars.discourse-cdn.com/v4/letter/r/9fc29f/32.png) [@Rahul07](https://discuss.elastic.co/u/Rahul07)\
**Post date:** [March 2, 2018, 8:51am UTC](https://discuss.elastic.co/t/web-log-config-file/122080/3 "2018-03-02T08:51:29Z")

</div>

Thanks for your suggestion.

## Yes i am using file input and here it is. my log sample data---------------\>

## 1\*\*. **.**.5\*- - [21/Apr/2017:00:31:46 -0600] "GET /api/releaseInfo HTTP/1.1" 200 1479 1\*\*. **.**.5\* - - [21/Apr/2017:00:32:46 -0600] "GET /api/releaseInfo HTTP/1.1" 200 1479

* * *

input  
{  
file  
{  
path=\> "C:\ELK\input\_logs\weblogs\Weblogic\_logs.txt"  
start\_position =\>"beginning"  
}  
}  
filter  
{  
if[type]=="weblogic"  
{  
grok{

```
match => { "message" => "%{TIMESTAMP_ISO8601:log_timestamp} %{WORD:cs-method} %{URIPATH:cs-uri-stem} %{NUMBER:sc-status:int} %{NUMBER:cs-bytes:int}" }

	}
	date {
	match => ["log_timestamp", "YYYY-MM-dd HH:mm:ss"]
	timezone => "UTC"
	}
}
mutate {
	remove_field => ["log_timestamp"]
}

```

}  
output  
{  
elasticsearch  
{  
hosts =\> ["localhost:9200"]  
index =\> ["weblogic\_1"]  
document\_type =\> "weblogic\_1"  
# user =\> elastic  
# password =\> changeme  
}  
stdout{}  
}

* * *

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 2, 2018, 8:56am UTC](https://discuss.elastic.co/t/web-log-config-file/122080/4 "2018-03-02T08:56:11Z")

</div>

As I said, if you want it to reprocess an old file you need to delete the sincedb file. See the file input documentation for details.

---

<div class="post-metadata">

**Author:** ![Rahul07](https://avatars.discourse-cdn.com/v4/letter/r/9fc29f/32.png) [@Rahul07](https://discuss.elastic.co/u/Rahul07)\
**Post date:** [March 2, 2018, 9:21am UTC](https://discuss.elastic.co/t/web-log-config-file/122080/5 "2018-03-02T09:21:47Z")

</div>

i'll check and get back to you. thanks..

and one more thing, my input file code is correct or not let me know.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 2, 2018, 9:45am UTC](https://discuss.elastic.co/t/web-log-config-file/122080/6 "2018-03-02T09:45:22Z")

</div>

- You're never setting the type to weblogic so your filters will be skipped.
- The grok expression doesn't match the input data.
- The date pattern doesn't match the timestamp format in the input.

---

<div class="post-metadata">

**Author:** ![Rahul07](https://avatars.discourse-cdn.com/v4/letter/r/9fc29f/32.png) [@Rahul07](https://discuss.elastic.co/u/Rahul07)\
**Post date:** [March 2, 2018, 9:50am UTC](https://discuss.elastic.co/t/web-log-config-file/122080/7 "2018-03-02T09:50:21Z")

</div>

Thank you Magnus, i'll update and try properly.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 30, 2018, 9:50am UTC](https://discuss.elastic.co/t/web-log-config-file/122080/8 "2018-03-30T09:50:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
