# Filebeat syslog parse error

**URL:** <https://discuss.elastic.co/t/filebeat-syslog-parse-error/189643>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 10, 2019, 1:54am UTC](https://discuss.elastic.co/t/filebeat-syslog-parse-error/189643 "2019-07-10T01:54:59Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![mancharagopan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mancharagopan/32/60266_2.png) [@mancharagopan](https://discuss.elastic.co/u/mancharagopan)\
**Post date:** [July 10, 2019, 1:54am UTC](https://discuss.elastic.co/t/filebeat-syslog-parse-error/189643/1 "2019-07-10T01:54:59Z")

</div>

Filebeat is giving errors while parsing syslog messages from ASA.

`ERROR	[syslog]	syslog/input.go:132	can't parse event as syslog rfc3164	{"message": "<165>:Jul 10 07:10:12 IST: %ASA-config-5-111010: User 'XXXXX', running 'N/A' from IP 172.x.x.x, executed 'write memory'\n"}`

can someone help?

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [July 10, 2019, 1:23pm UTC](https://discuss.elastic.co/t/filebeat-syslog-parse-error/189643/2 "2019-07-10T13:23:10Z")

</div>

The syslog input is rather strict in what it accepts (RFC3164). Alternatively you can use the UDP (or TCP) input and do the actual parsing using dissect or grok via Logstas/Ingest Node.

---

<div class="post-metadata">

**Author:** ![mancharagopan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mancharagopan/32/60266_2.png) [@mancharagopan](https://discuss.elastic.co/u/mancharagopan)\
**Post date:** [July 10, 2019, 2:11pm UTC](https://discuss.elastic.co/t/filebeat-syslog-parse-error/189643/3 "2019-07-10T14:11:30Z")

</div>

i am not sending ASA syslog messages to logstash directly. I am using Cisco module in filebeat to parse and send it to logstash. This error is in the filebeat not logstash.

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [July 11, 2019, 1:43pm UTC](https://discuss.elastic.co/t/filebeat-syslog-parse-error/189643/4 "2019-07-11T13:43:59Z")

</div>

Hi @mancharagopan,

What's confusing the syslog input is the timestamp format being used, it's not compatible with RFC3164. We're finding that Cisco ASA devices come configured with different syslog formats that confuse Filebeat. In this case, there are two problems:

- The timestamp is surrounded by colons `:Jul 10 07:10:12 IST:`
- Once that is fixed, the timezone (`IST`) is going to be treated as the hostname part of the message. It should be removed and hostname added.

Which device are these logs coming from? Are the syslog messaging straight from the device or are they passing through another device that could be modifying the format?

Please have a look at your device configuration settings to see if you can modify the date format

---

<div class="post-metadata">

**Author:** ![mancharagopan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mancharagopan/32/60266_2.png) [@mancharagopan](https://discuss.elastic.co/u/mancharagopan)\
**Post date:** [July 11, 2019, 2:29pm UTC](https://discuss.elastic.co/t/filebeat-syslog-parse-error/189643/5 "2019-07-11T14:29:29Z")

</div>

Syslog messages are coming straightly from ASA Firewall 5505, ASA 8.4(3).  
Do i have to include hostname or the ip address of the firewall?

---

<div class="post-metadata">

**Author:** ![mancharagopan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mancharagopan/32/60266_2.png) [@mancharagopan](https://discuss.elastic.co/u/mancharagopan)\
**Post date:** [July 11, 2019, 2:51pm UTC](https://discuss.elastic.co/t/filebeat-syslog-parse-error/189643/6 "2019-07-11T14:51:53Z")

</div>

I removed timestamp and added hostname to the syslog message. but i am still receiving parsing error.  
`syslog/input.go:132	can't parse event as syslog rfc3164	{"message": "<166>hostname-FW %ASA-6-113012: AAA user authentication Successful : local database : user = user1\n"}`

I don't know what is that \<166\> in front of the message and i don't know how to remove that.

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [July 12, 2019, 3:39pm UTC](https://discuss.elastic.co/t/filebeat-syslog-parse-error/189643/7 "2019-07-12T15:39:58Z")

</div>

The `<166>` is the syslog priority, which is not a problem.

Can you find a way to keep the timestamp but in a different format?

---

<div class="post-metadata">

**Author:** ![mancharagopan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mancharagopan/32/60266_2.png) [@mancharagopan](https://discuss.elastic.co/u/mancharagopan)\
**Post date:** [July 12, 2019, 3:44pm UTC](https://discuss.elastic.co/t/filebeat-syslog-parse-error/189643/8 "2019-07-12T15:44:54Z")

</div>

What format do you suggest?

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [July 12, 2019, 6:16pm UTC](https://discuss.elastic.co/t/filebeat-syslog-parse-error/189643/9 "2019-07-12T18:16:47Z")

</div>

I don't have an ASA Firewall to play with, but by looking at a manual I found online, it doesn't look like you can change the timestamp format. We have to update the `syslog` message parser to make it support more formats.

In the mean time, I had some success by doing this change:

```diff
diff --git a/x-pack/filebeat/module/cisco/asa/config/input.yml b/x-pack/filebeat/module/cisco/asa/config/input.yml
index 32e87abc8..9d23b77f2 100644
--- a/x-pack/filebeat/module/cisco/asa/config/input.yml
+++ b/x-pack/filebeat/module/cisco/asa/config/input.yml
@@ -1,8 +1,7 @@
 {{ if eq .input "syslog" }}

-type: syslog
-protocol.udp:
- host: "{{.syslog_host}}:{{.syslog_port}}"
+type: udp
+host: "{{.syslog_host}}:{{.syslog_port}}"

```

( This file is probably `/etc/filebeat/module/cisco/asa/config/input.yml` in your installation, or `C:\program files\filebeat\module\...` in Windows )

But you will lose the original timestamp in the messages as it won't be parsed.

I will create an issue to support more `syslog` formats.

Edit: we have this [https://github.com/elastic/beats/issues/6872](https://github.com/elastic/beats/issues/6872)

---

<div class="post-metadata">

**Author:** ![dmitriy.y](https://avatars.discourse-cdn.com/v4/letter/d/4da419/32.png) [@dmitriy.y](https://discuss.elastic.co/u/dmitriy.y)\
**Post date:** [July 31, 2019, 3:16pm UTC](https://discuss.elastic.co/t/filebeat-syslog-parse-error/189643/10 "2019-07-31T15:16:08Z")

</div>

Thank you, this looks to have fixed the problem for me.  
timestamp looks the same to me

**Before Patch:**  
@timestamp:  
Jul 31, 2019 @ 10:29:59.974

**After Patch:**  
@timestamp:  
Jul 31, 2019 @ 11:04:45.926

\*I now see that log.source.address is detected as the asa ip address.  
^Has nothing to do with actual traffic being passed from source or destination.  
It's probably has to do with the message type is not yet support. O  
Everything that was previously recognized is still recognized correctly.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 28, 2019, 3:16pm UTC](https://discuss.elastic.co/t/filebeat-syslog-parse-error/189643/11 "2019-08-28T15:16:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
