# Filter Logs from Firewall

**URL:** <https://discuss.elastic.co/t/filter-logs-from-firewall/172494>\
**Category:** Logstash\
**Created:** [March 15, 2019, 9:15am UTC](https://discuss.elastic.co/t/filter-logs-from-firewall/172494 "2019-03-15T09:15:02Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 15, 2019, 12:45pm UTC](https://discuss.elastic.co/t/filter-logs-from-firewall/172494/3 "2019-03-15T12:45:38Z")

</div>

You can use dissect to parse the first two elements, and a kv filter to parse the rest

```
dissect { mapping => { "message" => "%{[@metadata][ts]} %{+[@metadata][ts]} %{+[@metadata][ts]} %{ip} %{[@metadata][restOfLine]}" } }
kv { source => "[@metadata][restOfLine]" }
date { match => ["[@metadata][ts]", "MMM dd HH:mm:ss" ] }
```

---

_[View the full topic](https://discuss.elastic.co/t/filter-logs-from-firewall/172494)._
