So I should change the first line frommcapra wrote:It looks as if your apache logs don't have the program field set, which is what our default apache filter looks for:
A simple modification of this filter to match if [type] == 'apache_access' should start tagging your events correctly moving forward.Code: Select all
if [program] == 'apache_access' { grok { match => [ 'message', '%{COMBINEDAPACHELOG}'] } date { match => [ 'timestamp', 'dd/MMM/yyyy:HH:mm:ss Z' ] } mutate { replace => [ 'type', 'apache_access' ] convert => [ 'bytes', 'integer' ] convert => [ 'response', 'integer' ] } }
Code: Select all
if [program] == 'apache_access' {
Code: Select all
if [type] == 'apache_access