# Can anyone please help me how can i parse this firewall log?

**URL:** <https://discuss.elastic.co/t/can-anyone-please-help-me-how-can-i-parse-this-firewall-log/186599>\
**Category:** Logstash\
**Created:** [June 20, 2019, 6:24am UTC](https://discuss.elastic.co/t/can-anyone-please-help-me-how-can-i-parse-this-firewall-log/186599 "2019-06-20T06:24:45Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![deepanshu\_goel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/deepanshu_goel/32/48061_2.png) [@deepanshu\_goel](https://discuss.elastic.co/u/deepanshu_goel)\
**Post date:** [June 20, 2019, 6:24am UTC](https://discuss.elastic.co/t/can-anyone-please-help-me-how-can-i-parse-this-firewall-log/186599/1 "2019-06-20T06:24:45Z")

</div>

date stamp timestamp(data)private IP [public IP]-\>[public IP(client side)(protocol)

-\>i am not able to understand the type of log and i am new in the field so kindly please help me to parse the data of this kind of log

---

<div class="post-metadata">

**Author:** ![nitzanm](https://avatars.discourse-cdn.com/v4/letter/n/258eb7/32.png) [@nitzanm](https://discuss.elastic.co/u/nitzanm)\
**Post date:** [June 20, 2019, 6:17pm UTC](https://discuss.elastic.co/t/can-anyone-please-help-me-how-can-i-parse-this-firewall-log/186599/2 "2019-06-20T18:17:00Z")

</div>

can you please past one line so we can able to fit the grok.

in the mean time try to use this

> <https://github.com/elastic/logstash/blob/v1.4.2/patterns/grok-patterns>

---

<div class="post-metadata">

**Author:** ![deepanshu\_goel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/deepanshu_goel/32/48061_2.png) [@deepanshu\_goel](https://discuss.elastic.co/u/deepanshu_goel)\
**Post date:** [June 21, 2019, 5:05am UTC](https://discuss.elastic.co/t/can-anyone-please-help-me-how-can-i-parse-this-firewall-log/186599/3 "2019-06-21T05:05:58Z")

</div>

yes you can use this as a sample log :  
2000-06-30 01:44:00: {exwire-NAT-Rules} PSERVE\_SESSION\_OPEN: application:none, lsi.32 101.22.954.358.84355 [115.109.546.105.62589] -\> 66.451.684.74:99 (TCP)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 21, 2019, 1:54pm UTC](https://discuss.elastic.co/t/can-anyone-please-help-me-how-can-i-parse-this-firewall-log/186599/4 "2019-06-21T13:54:32Z")

</div>

I would start with

```
grok { match => { "message" => "%{DATA:[@metadata][startOfLine]} %{IPV4:ip1}.%{INT:port1} \[%{IPV4:ip2}.%{INT:port2}\] -> %{IPV4:ip3}:%{INT:port3} \(%{WORD:protocol}\)$" } }
dissect { mapping => { "[@metadata][startOfLine]" => "%{[@metadata][ts]} %{+[@metadata][ts]}: %{data}" } }
date { match => ["[@metadata][ts]", "YYYY-MM-dd HH:mm:ss" ] }
```

---

<div class="post-metadata">

**Author:** ![deepanshu\_goel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/deepanshu_goel/32/48061_2.png) [@deepanshu\_goel](https://discuss.elastic.co/u/deepanshu_goel)\
**Post date:** [June 24, 2019, 11:21am UTC](https://discuss.elastic.co/t/can-anyone-please-help-me-how-can-i-parse-this-firewall-log/186599/5 "2019-06-24T11:21:39Z")

</div>

The filter you sent me above isn't working correctly and i am not able to find the problem .Can you please explain what could be the possible reason for not expected answer.  
the error coming out is that the:-  
Provided Grok patterns do not match data in the input .

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 24, 2019, 12:05pm UTC](https://discuss.elastic.co/t/can-anyone-please-help-me-how-can-i-parse-this-firewall-log/186599/6 "2019-06-24T12:05:41Z")

</div>

Have you tested it against an actual log message rather than the example you gave? The IP addresses in the example are not valid, so IPV4 does not match them.

---

<div class="post-metadata">

**Author:** ![deepanshu\_goel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/deepanshu_goel/32/48061_2.png) [@deepanshu\_goel](https://discuss.elastic.co/u/deepanshu_goel)\
**Post date:** [June 25, 2019, 10:06am UTC](https://discuss.elastic.co/t/can-anyone-please-help-me-how-can-i-parse-this-firewall-log/186599/7 "2019-06-25T10:06:27Z")

</div>

Yes , i have tried them on actual logs. but they doesn't work.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 25, 2019, 4:14pm UTC](https://discuss.elastic.co/t/can-anyone-please-help-me-how-can-i-parse-this-firewall-log/186599/8 "2019-06-25T16:14:22Z")

</div>

They work for me if I change your IP addresses and port numbers to be valid

```
input { generator { count => 1 lines => [
'2000-06-30 01:44:00: {exwire-NAT-Rules} PSERVE_SESSION_OPEN: application:none, lsi.32 101.22.54.58.4355 [115.109.46.105.62589] -> 66.51.84.74:99 (TCP)',
'2000-06-30 01:44:00: {exwire-NAT-Rules} PSERVE_SESSION_OPEN: application:none, lsi.32 101.22.95.35.8435 [115.109.56.105.6589] -> 66.41.64.74:99 (TCP)' ] } }

filter {
    grok { match => { "message" => "%{DATA:[@metadata][startOfLine]} %{IPV4:ip1}.%{INT:port1} \[%{IPV4:ip2}.%{INT:port2}\] -> %{IPV4:ip3}:%{INT:port3} \(%{WORD:protocol}\)$" } }
    dissect { mapping => { "[@metadata][startOfLine]" => "%{[@metadata][ts]} %{+[@metadata][ts]}: %{data}" } }
    date { match => ["[@metadata][ts]", "YYYY-MM-dd HH:mm:ss" ] }
}
output { stdout { codec => rubydebug { metadata => false } } }

```

gets me

{  
"ip1" =\> "101.22.95.35",  
"ip2" =\> "115.109.56.105",  
"port2" =\> "6589",  
"data" =\> "{exwire-NAT-Rules} PSERVE\_SESSION\_OPEN: application:none, lsi.32",  
"protocol" =\> "TCP",

etc.

---

<div class="post-metadata">

**Author:** ![deepanshu\_goel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/deepanshu_goel/32/48061_2.png) [@deepanshu\_goel](https://discuss.elastic.co/u/deepanshu_goel)\
**Post date:** [June 26, 2019, 10:17am UTC](https://discuss.elastic.co/t/can-anyone-please-help-me-how-can-i-parse-this-firewall-log/186599/9 "2019-06-26T10:17:57Z")

</div>

Thank you ,it is working now . But i want to actually use these logs in kibana but i am unable to connect to the elasticsearch  
TAKE A LOOK AT THE CONFIGURATION FILE I MADE FOR THE SAME ( i just added yo your file some output commands) :-

output {

```
     elasticsearch { 
                 hosts => ["localhost:9200"]
                 user => "5d5a"
                 password => "33f7"
                 index => "syslog-%{+YYYY.MM.dd}"
                 document_type => "custom_logs"
                 }
   }
}

```

(and as i am doing it for small log file i am manually inputting it through the log file and not using beats)

---

<div class="post-metadata">

**Author:** ![sjabiulla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sjabiulla/32/48429_2.png) [@sjabiulla](https://discuss.elastic.co/u/sjabiulla)\
**Post date:** [June 26, 2019, 12:09pm UTC](https://discuss.elastic.co/t/can-anyone-please-help-me-how-can-i-parse-this-firewall-log/186599/10 "2019-06-26T12:09:50Z")

</div>

> [@deepanshu\_goel](#):
>
> document\_type =\> "custom\_logs"

"document\_type" was deprecated from Elasticsearch 6.0+. Remove it and see If that works.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2019, 12:10pm UTC](https://discuss.elastic.co/t/can-anyone-please-help-me-how-can-i-parse-this-firewall-log/186599/11 "2019-07-24T12:10:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
