Filter Grok


(Salma Ait Lhaj) #1

Please, is there any body who has an example of filter grok or fils .conf that can be use with logs that came from firwalls, I want him to separate all the fields.


(Krunal Kalaria) #2

Hi @asalma,

Can you more elaborate what is the format of your logs its CSV or JSON and so on. ?

Thanks & Regards,
Krunal.


#3

Hi @Krunal_kalaria
If you could post into a CSV format will be great onto my files they are seppareted with Spaces

Thanks

MrNerd


(Salma Ait Lhaj) #4

There format is : syslog (text files)

Thank you for your answer.


#5

thanks for your soon reply @asalma , but I was guessing if you could send me some real example like in this format of log how would you configure your CSV

Pablo msg_id="3000-3001" 07-05-2018 192.168.3.105

Thanks MrNerd


(Christian Dahlqvist) #6

Syslog can contain a lot of different formats, so you will need to be more specific and show examples. See this post for some additional details.


(Salma Ait Lhaj) #7

This :

May 3 11:39:58 fwghcadmin : %ASA-6-302015: Built outbound UDP connection 2356737924 for int-850-IntercoEXTCorporate:x.x.x.x/161 (x.x.x.x/161) to int-148-GHCTechnicalInfra:x.x.x.x/34300 (x.x.x.x/34300)

Or this :

May 3 13:16:23 frkeofwdmz01m.fr.ghc.local 1,2018/05/03 13:16:22,001801039811,TRAFFIC,end,0,2018/05/03 13:16:22,x.x.x.x,x.x.x.x,0.0.0.0,0.0.0.0,CETSI-114,,,ping,vsys1,dmz,dmz,ae1.1551,ae1.1551,frghcslnet03-4-et-Basom,2018/05/03 13:16:22,19252,2,0,0,0,0,0x100019,icmp,allow,280,140,140,4,2018/05/03 13:16:11,0,any,0,22749029075,0x0,x.x.x.x-10.255.255.255,x.x.x.x-10.255.255.255,0,2,2,aged-out,0,0,0,0,,frkeofwdmz01m,from-policy


(Salma Ait Lhaj) #8

Please I need a filter that can do this :

"timestamp" => May 3 11:39:58

"host" => fwghcadmin

"ciscotag" => Type d'équipement : %ASA

          Critisité : 6

          ID :302015

"connection_id" => 2356737924

"operation" => Built

"protoco" => UDP

"src_interface" => int-850-IntercoEXTCorporate1

"src_ip" => x.x.x.x

"src_port" => 161

"src_mapped_ip" => x.x.x.x

"src_mapped_port" => 161

"dst_interface" => int-148-GHCTechnicalInfra

"dst_ip" => x.x.x.x

"dst_port" => 34300

"dst_mapped_ip" => x.x.x.x

"dst_mapped_port" => 34300


#9

@asalma follow this guide is so usefull:

https://qbox.io/blog/import-csv-elasticsearch-logstash-sincedb

MrNerd


(system) #10

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.