# Filebeat F5 AFM Module Log Format

**URL:** <https://discuss.elastic.co/t/filebeat-f5-afm-module-log-format/259106>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 18, 2020, 1:19pm UTC](https://discuss.elastic.co/t/filebeat-f5-afm-module-log-format/259106 "2020-12-18T13:19:09Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![cyber\_crab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cyber_crab/32/81108_2.png) [@cyber\_crab](https://discuss.elastic.co/u/cyber_crab)\
**Post date:** [December 18, 2020, 1:19pm UTC](https://discuss.elastic.co/t/filebeat-f5-afm-module-log-format/259106/1 "2020-12-18T13:19:09Z")

</div>

We're currently trying to get the bigipafm fileset in the F5 module to parse the logs that are incoming from the F5 appliance. The documentation is missing the required log format, as well as the F5 AFM versions that are supported.

There is an example log in [https://github.com/elastic/beats/blob/master/x-pack/filebeat/module/f5/bigipafm/test/generated.log](https://github.com/elastic/beats/blob/master/x-pack/filebeat/module/f5/bigipafm/test/generated.log) but it does not match what we're getting from the appliance. A redacted sample string from our input:  
` <13>Dec 14 15:10:20 afm-h14lb-8 afmlog /Common/vlan124 75.189.17.66:49268 EN/Norfolk via /Common/vlan10-ACME-dmz-IN --> 195.50.81.18:443 TCP Accept Rule auth.ACME.test`

Does someone have experience regarding the settings that are required on the F5 side to make the module's parsing script work?

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [December 22, 2020, 10:45am UTC](https://discuss.elastic.co/t/filebeat-f5-afm-module-log-format/259106/2 "2020-12-22T10:45:04Z")

</div>

Generally speaking, Filebeat filesets only supports default formats from the modules. Is it possible that your F5 is outputting non-default information and that's why Filebeat is not parsing it correctly?

Can you provide more information? Can you paste the output error here, please? 🙂

---

<div class="post-metadata">

**Author:** ![cyber\_crab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cyber_crab/32/81108_2.png) [@cyber\_crab](https://discuss.elastic.co/u/cyber_crab)\
**Post date:** [December 22, 2020, 2:35pm UTC](https://discuss.elastic.co/t/filebeat-f5-afm-module-log-format/259106/3 "2020-12-22T14:35:41Z")

</div>

It's very likely that the output isn't standard, you're right. I understand that the error stems from the mismatch in the log formats. I'm looking for the format that the F5 admin needs to set so the output complies to what's expected by the module.

I can't extract the error right now, but it fails at the [pipeline.js processor](https://github.com/elastic/beats/blob/master/x-pack/filebeat/module/f5/bigipafm/config/pipeline.js), because the format coming in differs from what's expected as we established before.

```
var hdr1 = match("HEADER#0:0001", "message", "%{hfld1->} %{hfld2->} %{hhostname->} %{hfld3->} %{hfld4->} %{hfld5->} [F5@%{hfld6->} %{payload}", processor_chain([
    	setc("header_id","0001"),
    	setc("messageid","BIGIP_AFM"),
    ]));
```

---

<div class="post-metadata">

**Author:** ![fadjar340](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fadjar340/32/43610_2.png) [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Post date:** [December 22, 2020, 4:00pm UTC](https://discuss.elastic.co/t/filebeat-f5-afm-module-log-format/259106/4 "2020-12-22T16:00:18Z")

</div>

You can add the `Dissect` processor in the `Ingest Node Pipeline` - `filebeat-7.10.0-f5-bigipafm-pipeline`

If you have the exact log, you can add the `Dissect` in the last line of the processor.  
The sample as follow:

- Fill `Field` with value `event.original`
- Fill the `Pattern` with `%{?month} %{?date} %{?time} %{observer.name} %{observer.apps} %{source.profile} %{source.ip}:%{source.port} %{source.region} %{?via} %{source.gateway.profile} %{?} %{destination.ip}:%{destination.port} %{network.type} %{event.action} %{?} %{firewall.rule->}`
- Choose `Ignore missing`
- Fill `Condition (optional)` dengan `ctx?.event?.original.contains('-->')`
- Update the Processor
- Save pipeline

---

<div class="post-metadata">

**Author:** ![cyber\_crab](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cyber_crab/32/81108_2.png) [@cyber\_crab](https://discuss.elastic.co/u/cyber_crab)\
**Post date:** [December 22, 2020, 4:15pm UTC](https://discuss.elastic.co/t/filebeat-f5-afm-module-log-format/259106/5 "2020-12-22T16:15:56Z")

</div>

Thanks for the suggestion, I'll try that as soon as we get the connection to Elasticsearch up and running - which will take a while. I will update you once I've tried it out.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 19, 2021, 6:16pm UTC](https://discuss.elastic.co/t/filebeat-f5-afm-module-log-format/259106/6 "2021-01-19T18:16:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
