# Filebeat Fortinet module - can't parse event as syslog rfc3164

**URL:** <https://discuss.elastic.co/t/filebeat-fortinet-module-cant-parse-event-as-syslog-rfc3164/297712>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [February 21, 2022, 5:19am UTC](https://discuss.elastic.co/t/filebeat-fortinet-module-cant-parse-event-as-syslog-rfc3164/297712 "2022-02-21T05:19:02Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![gflukas](https://avatars.discourse-cdn.com/v4/letter/g/77aa72/32.png) [@gflukas](https://discuss.elastic.co/u/gflukas)\
**Post date:** [February 21, 2022, 5:19am UTC](https://discuss.elastic.co/t/filebeat-fortinet-module-cant-parse-event-as-syslog-rfc3164/297712/1 "2022-02-21T05:19:02Z")

</div>

Hey guys my journalctl keeps filled with errors. Filebeat Fortinet module - can't parse event as syslog rfc3164. What I can do to fix it?  
I'm using Ubuntu 20.04.  
Filebeat version filebeat:amd64/stable 7.16.1 upgradeable to 7.16.3

Sample error log  
Feb 01 08:59:42 elk-ls01.xx.xx.xx filebeat[946]: 2022-02-01T08:59:42.559+0200 ERROR [syslog] syslog/input.go:285 can't parse event as syslog rfc3164 {"message": "\<14\>1 2022-02-01T08:59:42-00:00 firewall dns name- - - - 1,2022/02/01 08:59:41,012001031976,TRAFFIC,end,2049,2022/02/01 08:59:41,91.220.59.66,13.107.160.201,0.0.0.0,0.0.0.0,DMZ DNS servers to External DNS queries,,,dns,vsys1,DMZ,External,ae1.91,ae1.90,ELK\_forwarding,2022/02/01 08:59:41,123428,1,55388,53,0,0,0x19,udp,allow,220,102,118,2,2022/02/01 08:59:11,1,any,0,712654729,0x0,Poland,United States,0,1,1,aged-out,0,0,0,0,,firewallhostname,from-policy,,,0,,0,,N/A,0,0,0,0\n"}

I just use filebeat to get logs for fortigate firewalls and transport those logs into logstash. Default configuration is barely minimum just to send logs into logstash.  
Let me know if any further information would be needed.

---

<div class="post-metadata">

**Author:** ![gflukas](https://avatars.discourse-cdn.com/v4/letter/g/77aa72/32.png) [@gflukas](https://discuss.elastic.co/u/gflukas)\
**Post date:** [March 15, 2022, 10:20am UTC](https://discuss.elastic.co/t/filebeat-fortinet-module-cant-parse-event-as-syslog-rfc3164/297712/2 "2022-03-15T10:20:10Z")

</div>

By editing pipeline (like this \<%{POSINT}\>%{POSINT}%{SPACE}%{TIMESTAMP\_ISO8601}%{SPACE}%{NOTSPACE}%{SPACE}%{NOTSPACE}%{SPACE}%{NOTSPACE}%{SPACE}%{NOTSPACE}%{SPACE}%{NOTSPACE}%{SPACE}%{GREEDYDATA:syslog5424\_sd}$ ) it started to collect some info but stuck onf "tztime" it doesn't understand what is + on key values splitting. Original value is +0200  
maybe i send logs not properly? i wonder if this issue only for me

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 12, 2022, 12:20pm UTC](https://discuss.elastic.co/t/filebeat-fortinet-module-cant-parse-event-as-syslog-rfc3164/297712/3 "2022-04-12T12:20:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
