# Add grok patterns on system auth ssh module

**URL:** <https://discuss.elastic.co/t/add-grok-patterns-on-system-auth-ssh-module/231703>\
**Category:** Beats\
**Tags:** beats-module, filebeat\
**Created:** [May 8, 2020, 11:20am UTC](https://discuss.elastic.co/t/add-grok-patterns-on-system-auth-ssh-module/231703 "2020-05-08T11:20:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![flyme](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flyme/32/55705_2.png) [@flyme](https://discuss.elastic.co/u/flyme)\
**Post date:** [May 8, 2020, 11:20am UTC](https://discuss.elastic.co/t/add-grok-patterns-on-system-auth-ssh-module/231703/1 "2020-05-08T11:20:52Z")

</div>

I use filebeat to send my logs to logstash. I have these logs :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/7/37e413007119845ac5ff371721e8544f822405ba.png)

So I'm trying to change the grok patterns of the system.auth module in this file in order to have "source.ip" field like this :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/8/c80c7aef425ba52f8a20aeab9e3e04fa91e4f013.png)

I modified this file

```auto
/usr/share/filebeat/module/system/auth/ingest/pipeline.json

```

And here is my change :

```auto
@@ -13,6 +13,7 @@
                     "%{TIMESTAMP:system.auth.timestamp} %{SYSLOGHOST:host.hostname} %{DATA:process.name}(?:\\[%{POSINT:process.pid:long}\\])?: %{DATA:system.auth.ssh.event} %{DATA:system.auth.ssh.method} for (invalid user )?%{DATA:user.name} from %{IPORHOST:source.ip} port %{NUMBER:source.port:long} ssh2(: %{GREEDYDATA:system.auth.ssh.signature})?",
                     "%{TIMESTAMP:system.auth.timestamp} %{SYSLOGHOST:host.hostname} %{DATA:process.name}(?:\\[%{POSINT:process.pid:long}\\])?: %{DATA:system.auth.ssh.event} user %{DATA:user.name} from %{IPORHOST:source.ip}",
                     "%{TIMESTAMP:system.auth.timestamp} %{SYSLOGHOST:host.hostname} %{DATA:process.name}(?:\\[%{POSINT:process.pid:long}\\])?: Did not receive identification string from %{IPORHOST:system.auth.ssh.dropped_ip}",
+ "%{TIMESTAMP:system.auth.timestamp} %{SYSLOGHOST:host.hostname} %{DATA:process.name}(?:\\[%{POSINT:process.pid:long}\\])?: refused connect from %{IPORHOST:system.auth.ssh.dropped_ip}",
                     "%{TIMESTAMP:system.auth.timestamp} %{SYSLOGHOST:host.hostname} %{DATA:process.name}(?:\\[%{POSINT:process.pid:long}\\])?: \\s*%{DATA:user.name} :( %{DATA:system.auth.sudo.error} ;)? TTY=%{DATA:system.auth.sudo.tty} ; PWD=%{DATA:system.auth.sudo.pwd} ; USER=%{DATA:system.auth.sudo.user} ; COMMAND=%{GREEDYDATA:system.auth.sudo.command}",
                     "%{TIMESTAMP:system.auth.timestamp} %{SYSLOGHOST:host.hostname} %{DATA:process.name}(?:\\[%{POSINT:process.pid:long}\\])?: new group: name=%{DATA:group.name}, GID=%{NUMBER:group.id}",
                     "%{TIMESTAMP:system.auth.timestamp} %{SYSLOGHOST:host.hostname} %{DATA:process.name}(?:\\[%{POSINT:process.pid:long}\\])?: new user: name=%{DATA:user.name}, UID=%{NUMBER:user.id}, GID=%{NUMBER:group.id}, home=%{DATA:system.auth.useradd.home}, shell=%{DATA:system.auth.useradd.shell}$",
@@ -108,7 +109,7 @@
             "script": {
                 "lang": "painless",
                 "ignore_failure": true,
- "source": "if (ctx.system.auth.ssh.event == \"Accepted\") { if (!ctx.containsKey(\"event\")) { ctx.event = [:]; } ctx.event.type = \"authentication_success\"; ctx.event.category = \"authentication\"; ctx.event.action = \"ssh_login\"; ctx.event.outcome = \"success\"; } else if (ctx.system.auth.ssh.event == \"Invalid\" || ctx.system.auth.ssh.event == \"Failed\") { if (!ctx.containsKey(\"event\")) { ctx.event = [:]; } ctx.event.type = \"authentication_failure\"; ctx.event.category = \"authentication\"; ctx.event.action = \"ssh_login\"; ctx.event.outcome = \"failure\"; }"
+ "source": "if (ctx.system.auth.ssh.event == \"Accepted\") { if (!ctx.containsKey(\"event\")) { ctx.event = [:]; } ctx.event.type = \"authentication_success\"; ctx.event.category = \"authentication\"; ctx.event.action = \"ssh_login\"; ctx.event.outcome = \"success\"; } else if (ctx.system.auth.ssh.event == \"Invalid\" || ctx.system.auth.ssh.event == \"Failed\") || ctx.system.auth.ssh.event == \"refused\") { if (!ctx.containsKey(\"event\")) { ctx.event = [:]; } ctx.event.type = \"authentication_failure\"; ctx.event.category = \"authentication\"; ctx.event.action = \"ssh_login\"; ctx.event.outcome = \"failure\"; }"
             }
         }
     ],

```

I restart filebeat but I didn't see any change.

Any thoughts/feedback on this?

// Cheers hn

---

<div class="post-metadata">

**Author:** ![nmoham](https://avatars.discourse-cdn.com/v4/letter/n/77aa72/32.png) [@nmoham](https://discuss.elastic.co/u/nmoham)\
**Post date:** [May 20, 2020, 12:36pm UTC](https://discuss.elastic.co/t/add-grok-patterns-on-system-auth-ssh-module/231703/2 "2020-05-20T12:36:02Z")

</div>

@flyme

Did you try to reload the ingest pipeline ?

filebeat setup --pipelines --modules system

and then check from Dev tools in Kibana to see, if the new pattern is reflected.

GET \_ingest/pipeline

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 17, 2020, 12:36pm UTC](https://discuss.elastic.co/t/add-grok-patterns-on-system-auth-ssh-module/231703/3 "2020-06-17T12:36:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
