# Filebeat Sonicwall module - dissect\_parsing\_error

**URL:** https://discuss.elastic.co/t/filebeat-sonicwall-module-dissect-parsing-error/252708
**Category:** Beats
**Created:** [October 20, 2020, 3:20pm UTC](https://discuss.elastic.co/t/filebeat-sonicwall-module-dissect-parsing-error/252708 "2020-10-20T15:20:26Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![PhilA](https://avatars.discourse-cdn.com/v4/letter/p/c6cbf5/32.png) [@PhilA](https://discuss.elastic.co/u/PhilA)
#### Post date: [October 20, 2020, 3:20pm UTC](https://discuss.elastic.co/t/filebeat-sonicwall-module-dissect-parsing-error/252708/1 "2020-10-20T15:20:26Z")

</div>

I have attempted to enable the SonicWall Filebeat module but it doesn't seem to support our logs fully.

I am running v7.9.2 and looked at enabling this through ingest manager in the Kibana GUI but that doesn't seem to be ready so have enabled the module on Filebeat. Data is coming in but most entries are getting tagged with dissect\_parsing\_error.

The result seems different depending on the original log message and what values it contains but I don't understand the pipeline files well enough to debug. If someone could point me at what to look at I will happily try to diagnose.

It looks like a lot of it is working and many of the fields are populated but how many depends on the original message. Some will get the source details extracted (source.ip, source.port, etc.) but fail to get the destination details. Others get no IP information and others get all.

Is there a way of determining what part of the log caused the dissect\_parsing\_error and where int he pipeline.js file that issue was?

---

<div class="post-metadata">

### Author: ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)
#### Post date: [October 21, 2020, 3:03pm UTC](https://discuss.elastic.co/t/filebeat-sonicwall-module-dissect-parsing-error/252708/2 "2020-10-21T15:03:10Z")

</div>

Are you using the Elastic Agent or filebeat to collect the logs?

---

<div class="post-metadata">

### Author: ![PhilA](https://avatars.discourse-cdn.com/v4/letter/p/c6cbf5/32.png) [@PhilA](https://discuss.elastic.co/u/PhilA)
#### Post date: [October 21, 2020, 3:05pm UTC](https://discuss.elastic.co/t/filebeat-sonicwall-module-dissect-parsing-error/252708/3 "2020-10-21T15:05:40Z")

</div>

Filebeat. I tried Elastic Agent but not a lot seemed to happen but that may be me. The documentation on configuring Elastic Agents seems minimal

I'll try that again and see if I can get it working with Elastic Agent and see if the result is different.

I will do some more testing and update.

---

<div class="post-metadata">

### Author: ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)
#### Post date: [October 21, 2020, 3:16pm UTC](https://discuss.elastic.co/t/filebeat-sonicwall-module-dissect-parsing-error/252708/4 "2020-10-21T15:16:49Z")

</div>

If you tried with Filebeat this look like a module issue. I will move this to the beats board.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 18, 2020, 5:16pm UTC](https://discuss.elastic.co/t/filebeat-sonicwall-module-dissect-parsing-error/252708/5 "2020-11-18T17:16:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
