# Barracuda WAF log input format

**URL:** <https://discuss.elastic.co/t/barracuda-waf-log-input-format/298214>\
**Category:** Beats\
**Tags:** beats-module, filebeat\
**Created:** [February 24, 2022, 8:07pm UTC](https://discuss.elastic.co/t/barracuda-waf-log-input-format/298214 "2022-02-24T20:07:09Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![JGreene](https://avatars.discourse-cdn.com/v4/letter/j/c68b51/32.png) [@JGreene](https://discuss.elastic.co/u/JGreene)\
**Post date:** [February 24, 2022, 8:07pm UTC](https://discuss.elastic.co/t/barracuda-waf-log-input-format/298214/1 "2022-02-24T20:07:09Z")

</div>

Continuing the discussion from [Barracuda WAF Log Parsing](https://discuss.elastic.co/t/barracuda-waf-log-parsing/266665):

We are seeking guidance on how to configure the Barracuda WAF logs to output to Filebeat in a format that is accepted by the provided following scripts in the module:

```auto
    - ${path.home}/module/barracuda/waf/config/liblogparser.js
    - ${path.home}/module/barracuda/waf/config/pipeline.js

```

We have attempted the default and the RSA enVision formats, but neither worked. Basically, what output format is required to make the Barracuda filebeat module function properly?

This is the module that we are attempting to use:

> **[beats/x-pack/filebeat/module/barracuda at main · elastic/beats](https://github.com/elastic/beats/tree/main/x-pack/filebeat/module/barracuda)**
>
> main/x-pack/filebeat/module/barracuda

@PhilA - Were you ever able to get this working?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 24, 2022, 10:07pm UTC](https://discuss.elastic.co/t/barracuda-waf-log-input-format/298214/2 "2022-03-24T22:07:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
