# Error Events with "\>"

**URL:** <https://discuss.elastic.co/t/error-events-with/326192>\
**Category:** Logstash\
**Created:** [February 22, 2023, 3:27pm UTC](https://discuss.elastic.co/t/error-events-with/326192 "2023-02-22T15:27:50Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![akrog79](https://avatars.discourse-cdn.com/v4/letter/a/e9c0ed/32.png) [@akrog79](https://discuss.elastic.co/u/akrog79)\
**Post date:** [February 22, 2023, 3:27pm UTC](https://discuss.elastic.co/t/error-events-with/326192/1 "2023-02-22T15:27:51Z")

</div>

Hello people!

I have a trouble with the ingestion of a anomaly events in fortigate.

The raw event is:

`<185>logver=702032456 timestamp=1676305141 devname="FG200-E" devid="FG200ETK189243" vd="root" date=2023-02-13 time=17:19:01 eventtime=1676305141602895749 tz="+0100" logid="0720018433" type="utm" subtype="gorkapablo" eventtype="anomaly" level="alert" severity="critical" srcip=63.222.61.134 srccountry="France" dstip=109.111.111.203 dstcountry="Spain" srcintf="port13" srcintfrole="wan" sessionid=0 action="detected" proto=1 service="PING" count=236 attack="icmp_flood" icmpid="0x3721" icmptype="0x08" icmpcode="0x00" attackid=16777316 policyid=1 policytype="DoS-policy" ref="[http://www.fortinet.com/ids/VID16777316"](http://www.fortinet.com/ids/VID16777316%22) msg="anomaly: icmp_flood, 251 > threshold 250, repeats 236 times since last log, pps 30 of prior second" crscore=50 craction=4096 crlevel="critical"`

As you can see, the field msg (anomaly: icmp\_flood, 251 \> threshold 250, repeats 236 times since last log, pps 30 of prior second) have a "\>" symbol. This symbol makes me crazy because when appears, the event doesn't appear in Elastic, but if I erase it, the event appears.

My logstash conf.d file is:

```auto
input {
  tcp {
    port => 1025
    tags => ["fortigate"]
  }
}

filter {
    if "fortigate" in [tags] {
        grok {
                match => {"message" => "<(?<ruleID>.*)>(?<msg>.*)"}
        }
        kv { source => "msg" }
        mutate {
            rename => ["msg","message"]
            rename => ["type","log_type"]
            rename => ["dst", "DestinationIP"]
            rename => ["dstip", "DestinationIP"]
            rename => ["dstport", "DestinationPort"]
            rename => ["dstintf", "DestinationZone"]
            rename => ["devname", "DeviceName"]
            rename => ["status", "Action"]
            rename => ["src", "SourceIP"]
            rename => ["srcip", "SourceIP"]
            rename => ["zone", "SourceZone"]
            rename => ["srcintf", "SourceZone"]
            rename => ["srcport", "SourcePort"]
            rename => ["service", "Application"]
            rename => ["policyname", "RuleName"]
            rename => ["action", "Action"]
            rename => ["rcvdbyte", "BytesReceived"]
            rename => ["sentbyte", "BytesSent"]
            convert => {"DestinationZone" => "string"}
        }
}
}

output {
  if "fortigate" in [tags] {
          elasticsearch {
              hosts => ["X.X.X.X:9200"]
              index => "fortigate-%{+YYYY.MM.dd}"
              document_type => "fortigate"
              template => "/etc/logstash/elastic-fortigate-template.json"
              template_name => "fortigate"
              template_overwrite => true
          }
         }
 }

```

Someone can help me?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 22, 2023, 3:43pm UTC](https://discuss.elastic.co/t/error-events-with/326192/2 "2023-02-22T15:43:21Z")

</div>

The issue is that the character `>` breaks your grok filter as the first regex will capture everything between a `<` and a `>`.

In your case you do not even need to use grok as the fortigate messages will always have the same format, you can use the dissect filter to parse the message.

Replace your `grok` filter with this `dissect` and it will work:

```auto
    dissect {
        mapping => {
            "message" => "<%{ruleId}>%{msg}"
        }
    }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2023, 3:44pm UTC](https://discuss.elastic.co/t/error-events-with/326192/3 "2023-03-22T15:44:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
