{"id":2388,"date":"2023-07-23T08:21:47","date_gmt":"2023-07-23T07:21:47","guid":{"rendered":"https:\/\/cdblog.cdstealer.com\/?p=2388"},"modified":"2023-07-23T08:28:02","modified_gmt":"2023-07-23T07:28:02","slug":"apache-custom-logformats","status":"publish","type":"post","link":"https:\/\/cdblog.cdstealer.com\/?p=2388","title":{"rendered":"Apache Custom LogFormats"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Take the leg work out of reading your apache logs by converting them to a structured format that's easy to read.  Enter JSON :)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Create the file \/etc\/apache2\/vhosts.d\/00_default_logging.conf<br>You will also need to ensure the \"logio_module\" is enabled.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For the access log, I use the format:  <a href=\"https:\/\/httpd.apache.org\/docs\/2.4\/mod\/mod_log_config.html\" data-type=\"URL\" data-id=\"https:\/\/httpd.apache.org\/docs\/2.4\/mod\/mod_log_config.html\" target=\"_blank\" rel=\"noreferrer noopener\">Apache doc.<\/a><\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">LogFormat \"{\\\"time\\\":\\\"%{msec}t\\\", \\\"bytes_in\\\":\\\"%I\\\", \\\"bytes_out\\\":\\\"%O\\\", \\\"cookie\\\":\\\"%{Cookie}i\\\", \\\"server\\\":\\\"%v\\\", \\\"dest_port\\\":\\\"%p\\\", \\\"http_content_type\\\":\\\"%{Content-type}i\\\", \\\"http_method\\\":\\\"%m\\\", \\\"http_referrer\\\":\\\"%{Referer}i\\\", \\\"http_user_agent\\\":\\\"%{User-agent}i\\\", \\\"ident\\\":\\\"%l\\\", \\\"response_time_microseconds\\\":\\\"%D\\\", \\\"client\\\":\\\"%h\\\", \\\"remoteAddr\\\":\\\"%a\\\", \\\"status\\\":\\\"%&gt;s\\\", \\\"uri_path\\\":\\\"%U\\\", \\\"uri_query\\\":\\\"%q\\\", \\\"user\\\":\\\"%u\\\"}\" apache_json<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">And for the error log, I use:  <a href=\"https:\/\/httpd.apache.org\/docs\/2.4\/mod\/core.html#errorlogformat\" data-type=\"URL\" data-id=\"https:\/\/httpd.apache.org\/docs\/2.4\/mod\/core.html#errorlogformat\" target=\"_blank\" rel=\"noreferrer noopener\">Apache doc.<\/a><\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">ErrorLogFormat \"{\\\"time\\\":\\\"%{msec}t\\\", \\\"client\\\":\\\"%a\\\", \\\"log_level\\\":\\\"%l\\\", \\\"pid\\\":\\\"%P\\\", \\\"srcln\\\":\\\"%F\\\", \\\"error_code\\\":\\\"%E\\\", \\\"message\\\":\\\"%M\\\"}\"<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">In the vhost.conf I have the following at the bottom of my VirtualHost block:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">&lt;VirtualHost>\n    ...\n    CustomLog \"\/var\/log\/apache2\/ssl_access.log\" apache_json\n    ErrorLog \/var\/log\/apache2\/ssl_error.log\n&lt;\/VirtualHost><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Give the command to test the config is sane:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">apachectl configtest<\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">If nothing is returned, go ahead and restart apache.<br>This also makes importing the logs much easier into tools like ELK or Splunk.                                                                                                                                                                                                                                                                                                                                                                                                              <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Take the leg work out of reading your apache logs by converting them to a structured format that's easy to read. Enter JSON :) Create the file \/etc\/apache2\/vhosts.d\/00_default_logging.confYou will also need to ensure the \"logio_module\" is enabled. For the access log, I use the format: Apache doc. LogFormat \"{\\\"time\\\":\\\"%{msec}t\\\", \\\"bytes_in\\\":\\\"%I\\\", \\\"bytes_out\\\":\\\"%O\\\", \\\"cookie\\\":\\\"%{Cookie}i\\\", \\\"server\\\":\\\"%v\\\", \\\"dest_port\\\":\\\"%p\\\", \\\"http_content_type\\\":\\\"%{Content-type}i\\\", &hellip; <a href=\"https:\/\/cdblog.cdstealer.com\/?p=2388\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Apache Custom LogFormats<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[45,213,18,215],"class_list":["post-2388","post","type-post","status-publish","format-standard","hentry","category-gentoo","tag-apache","tag-gentoo","tag-linux","tag-splunk"],"_links":{"self":[{"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=\/wp\/v2\/posts\/2388","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2388"}],"version-history":[{"count":3,"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=\/wp\/v2\/posts\/2388\/revisions"}],"predecessor-version":[{"id":2392,"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=\/wp\/v2\/posts\/2388\/revisions\/2392"}],"wp:attachment":[{"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2388"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2388"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2388"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}