# Where can I find the grok pattern for the COMBINEDAPACHELOG in logstash?

**URL:** <https://discuss.elastic.co/t/where-can-i-find-the-grok-pattern-for-the-combinedapachelog-in-logstash/236990>\
**Category:** Logstash\
**Created:** [June 13, 2020, 5:09pm UTC](https://discuss.elastic.co/t/where-can-i-find-the-grok-pattern-for-the-combinedapachelog-in-logstash/236990 "2020-06-13T17:09:52Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![curiousmind](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/curiousmind/32/69452_2.png) [@curiousmind](https://discuss.elastic.co/u/curiousmind)\
**Post date:** [June 13, 2020, 5:09pm UTC](https://discuss.elastic.co/t/where-can-i-find-the-grok-pattern-for-the-combinedapachelog-in-logstash/236990/1 "2020-06-13T17:09:52Z")

</div>

When I try parsing the **apache access** logs with the following grok rule, it comes out with 0 grokparsefailures  
` match => { "message" => ["%{COMBINEDAPACHELOG}"] }`

But when I try doing the same with the following grok pattern, which was found in this [Elastic Documentation](https://www.elastic.co/guide/en/logstash/current/logstash-config-for-filebeat-modules.html#parsing-apache2), I end up with more than 30% errors.  
The pattern used from the above link is below:

```auto
 grok {
        match => { "message" => ["%{IPORHOST:[apache2][access][remote_ip]} - %{DATA:[apache2][access][user_name]} \[%{HTTPDATE:[apache2][access][time]}\] \"%{WORD:[apache2][access][method]} %{DATA:[apache2][access][url]} HTTP/%{NUMBER:[apache2][access][http_version]}\" %{NUMBER:[apache2][access][response_code]} %{NUMBER:[apache2][access][body_sent][bytes]}( \"%{DATA:[apache2][access][referrer]}\")?( \"%{DATA:[apache2][access][agent]}\")?",
          "%{IPORHOST:[apache2][access][remote_ip]} - %{DATA:[apache2][access][user_name]} \\[%{HTTPDATE:[apache2][access][time]}\\] \"-\" %{NUMBER:[apache2][access][response_code]} -" ] }
        remove_field => "message"
      }

```

Can anyone tell me what is happening here?.  
Also, where can I find the complete grok patterns used by the %{COMBINEDAPACHELOGS} ?

---

<div class="post-metadata">

**Author:** ![Coinology](https://avatars.discourse-cdn.com/v4/letter/c/3e96dc/32.png) [@Coinology](https://discuss.elastic.co/u/Coinology)\
**Post date:** [June 14, 2020, 12:01am UTC](https://discuss.elastic.co/t/where-can-i-find-the-grok-pattern-for-the-combinedapachelog-in-logstash/236990/2 "2020-06-14T00:01:46Z")

</div>

See the httpd patterns here:

> <https://github.com/logstash-plugins/logstash-patterns-core/blob/4ba9bf573583ad510aaf4bd0b3418bdbe3402585/patterns/httpd>

Does that answer your question?

---

<div class="post-metadata">

**Author:** ![curiousmind](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/curiousmind/32/69452_2.png) [@curiousmind](https://discuss.elastic.co/u/curiousmind)\
**Post date:** [June 14, 2020, 2:57am UTC](https://discuss.elastic.co/t/where-can-i-find-the-grok-pattern-for-the-combinedapachelog-in-logstash/236990/3 "2020-06-14T02:57:59Z")

</div>

Hi @Coinology  
I tried the above raw pattern to match the following lines of logs, but it was not successfull

```auto
45.203.10.210 - - [13/Jan/2020:05:30:38 +0000] \"POST /wp-cron.php?doing_wp_cron=149332.6687 HTTP/1.1\" 200 - \"http://technopart.com/wp-cron.php?doing_wp_cron=149332.6687\" \"WordPress/4.7.2; http://technopart.com\"

```

I modified the raw pattern a bit in order to get a match but was not successful.  
The pattern I tried using was

```auto
%{IPORHOST:clientip} %{DATA:ident} %{DATA:auth} \[%{HTTPDATE:timestamp}\] "(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})" %{NUMBER:response} (?:%{NUMBER:bytes}|-) 

```

Screenshot for reference:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/a/8a32b8d3f93e949073cbe4f20c161dcda007a5e8.png)

When I parse this with Logstash using the %{COMBINEDAPACHELOG} pattern, it is successfull though.

Can you please help me with this?

---

<div class="post-metadata">

**Author:** ![Coinology](https://avatars.discourse-cdn.com/v4/letter/c/3e96dc/32.png) [@Coinology](https://discuss.elastic.co/u/Coinology)\
**Post date:** [June 14, 2020, 1:55pm UTC](https://discuss.elastic.co/t/where-can-i-find-the-grok-pattern-for-the-combinedapachelog-in-logstash/236990/4 "2020-06-14T13:55:16Z")

</div>

@curiousmind I'm no grok expert so I'm sorry if the answer is obvbious, but if `%{COMBINEDAPACHELOG}` is working for you, why do you want to use the raw pattern?

---

<div class="post-metadata">

**Author:** ![Coinology](https://avatars.discourse-cdn.com/v4/letter/c/3e96dc/32.png) [@Coinology](https://discuss.elastic.co/u/Coinology)\
**Post date:** [June 14, 2020, 2:41pm UTC](https://discuss.elastic.co/t/where-can-i-find-the-grok-pattern-for-the-combinedapachelog-in-logstash/236990/5 "2020-06-14T14:41:53Z")

</div>

@curiousmind I believe the issue is twofold: the backslashes in your log + your agent section. I've adjusted the raw pattern as below and it seems to be working, but I'm not sure whether this is the best way to handle it or not. Give it a try and tell me what you think.

`%{IPORHOST:clientip} %{USER:ident} %{USER:auth} \[%{HTTPDATE:timestamp}\] \\"(?:%{WORD:verb} %{NOTSPACE:request}(?: HTTP/%{NUMBER:httpversion})?|%{DATA:rawrequest})" %{NUMBER:response} (?:%{NUMBER:bytes}|-) \\"%{NOTSPACE:referrer}\\" \\"%{GREEDYDATA:agent}\\"`

I'm still perplexed as to why you would be getting matches with `%{COMBINEDAPACHELOGS}` but grokparsefailures with the raw version of the pattern.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 12, 2020, 2:42pm UTC](https://discuss.elastic.co/t/where-can-i-find-the-grok-pattern-for-the-combinedapachelog-in-logstash/236990/6 "2020-07-12T14:42:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
