# Plex Media Server Log Format

**URL:** <https://forums.plex.tv/t/plex-media-server-log-format/165405>\
**Category:** General Discussions\
**Created:** [November 1, 2016, 6:37am UTC](https://forums.plex.tv/t/plex-media-server-log-format/165405 "2016-11-01T06:37:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dot\_Cipher](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/dot_cipher/32/113697_2.png) [@dot\_Cipher](https://forums.plex.tv/u/dot_Cipher)\
**Post date:** [November 1, 2016, 6:37am UTC](https://forums.plex.tv/t/plex-media-server-log-format/165405/1 "2016-11-01T06:37:40Z")

</div>

I am working on building an [ElasticSearch](https://www.elastic.co/products/elasticsearch "ElasticSearch") / [Logstash](https://www.elastic.co/products/logstash "Logstash") pipeline and building [grok](https://www.elastic.co/guide/en/logstash/current/plugins-filters-grok.html "grok") filters to parse the Plex Media Server logs.

After pull in some of my logs I found that the Plex Media Server logs don’t really have a standardized format besides the simple pattern:

```
%{MONTH} %{MONTHDAY}, %{YEAR} %{TIME} \[(?<session_id>[0-9]x[0-9a-f]{4,9})\] %{LOGLEVEL} - %{GREEDYDATA:message}

```

However I would like to be able to determine when a login occurs, when a movie / tv show is played / etc. Does anyone have insight on this?

Thanks!

---

<div class="post-metadata">

**Author:** ![OttoKerner](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/ottokerner/32/10079_2.png) [@OttoKerner](https://forums.plex.tv/u/OttoKerner)\
**Post date:** [November 1, 2016, 1:23pm UTC](https://forums.plex.tv/t/plex-media-server-log-format/165405/2 "2016-11-01T13:23:46Z")

</div>

Why are you inventing the wheel twice? 😉  
[PlexPy](https://forums.plex.tv/discussion/169591/plexpy-another-plex-monitoring-program/p1#top "PlexPy") does already do that.  
You could also analyze its source code to find out how it works.

---

<div class="post-metadata">

**Author:** ![dot\_Cipher](https://sea1.discourse-cdn.com/plex/user_avatar/forums.plex.tv/dot_cipher/32/113697_2.png) [@dot\_Cipher](https://forums.plex.tv/u/dot_Cipher)\
**Post date:** [November 1, 2016, 3:50pm UTC](https://forums.plex.tv/t/plex-media-server-log-format/165405/3 "2016-11-01T15:50:48Z")

</div>

Oh wow, thanks! Totally didn’t know that existed. Thanks @OttoKerner ! I will give that a shot but the main purpose of me trying this out was to learn the ELK stack 😃

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/plex/original/3X/2/a/2acb9765406f63293d357b4ec509ec39aa28f2ad.png) [@system](https://forums.plex.tv/u/system)\
**Post date:** [January 7, 2020, 10:09pm UTC](https://forums.plex.tv/t/plex-media-server-log-format/165405/4 "2020-01-07T22:09:43Z")

</div>


