# Filebeats for UFW logs - how to define fields?

**URL:** <https://discuss.elastic.co/t/filebeats-for-ufw-logs-how-to-define-fields/155263>\
**Category:** Beats\
**Created:** [November 3, 2018, 3:00pm UTC](https://discuss.elastic.co/t/filebeats-for-ufw-logs-how-to-define-fields/155263 "2018-11-03T15:00:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bvickers](https://avatars.discourse-cdn.com/v4/letter/b/a9adbd/32.png) [@bvickers](https://discuss.elastic.co/u/bvickers)\
**Post date:** [November 3, 2018, 3:00pm UTC](https://discuss.elastic.co/t/filebeats-for-ufw-logs-how-to-define-fields/155263/1 "2018-11-03T15:00:53Z")

</div>

Hello.

I am trying to set up Elastic Stack to manage some typical and some custom logs.

I have **Windows** and **Linux** servers to grab logs from and I decided to use **Beats** to make it a little bit more secure (using logstash to control which server can push to which elasticsearch index).

The logs I want to take care of include:

- UFW logs
- Snort alerts
- typical logs like nginx, apache, etc.
- some custom logs

And I want to make them easily searchable, atomic (with separate fields and not the one huge message field). So I tried setting it all up and have realized that Beats does not include templates (fields?) for at least UFW.

UFW log entry looks like that:

`Nov 3 14:49:37 XXX kernel: [UFW BLOCK] IN=eth0 OUT= MAC=XXX SRC=XXX DST=XXX LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=XXX DF PROTO=TCP SPT=XXX DPT=XXX WINDOW=XXX RES=0x00 SYN URGP=0`

So I've identified two options:

- filebeat -\> logstash (filter here) -\> elasticsearch
- filebeat (filter here) -\> logstash -\> elasticsearch

I have an idea how filter (parse, map the fields, etc.) UFW logs with logstash, **but can you point me to the right direction about how to filter them with filebeat?**

I would be happy to see general advices and links to docs too.. Thanks in advance

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [November 5, 2018, 8:52am UTC](https://discuss.elastic.co/t/filebeats-for-ufw-logs-how-to-define-fields/155263/2 "2018-11-05T08:52:17Z")

</div>

Filebeat does not have as advanced filtering capabilites as Logstash does. So if you want to put together a complex filtering for your logs, I suggest you do the filtering in Logstash.  
Filebeat uses processors to filter messages: [https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html](https://www.elastic.co/guide/en/beats/filebeat/current/defining-processors.html)

To parse UFW logs the "Filebeat way" is to add a new module and a fileset. Here is a guide on how to do it: [https://www.elastic.co/guide/en/beats/devguide/current/filebeat-modules-devguide.html](https://www.elastic.co/guide/en/beats/devguide/current/filebeat-modules-devguide.html)  
Do you mind opening and enhancement request on Github? [https://github.com/elastic/beats/issues/new](https://github.com/elastic/beats/issues/new)  
I think it would be a good addition to the existing Filebeat modules. If you have time, we would appreciate if you contributed back what you have created. Let me know if you need help with creating a new module.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 3, 2018, 11:04am UTC](https://discuss.elastic.co/t/filebeats-for-ufw-logs-how-to-define-fields/155263/3 "2018-12-03T11:04:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
