# Filter Sonicwall Logstash

**URL:** <https://discuss.elastic.co/t/filter-sonicwall-logstash/238146>\
**Category:** Logstash\
**Created:** [June 22, 2020, 7:41pm UTC](https://discuss.elastic.co/t/filter-sonicwall-logstash/238146 "2020-06-22T19:41:28Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Danilo\_Visual](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danilo_visual/32/52956_2.png) [@Danilo\_Visual](https://discuss.elastic.co/u/Danilo_Visual)\
**Post date:** [June 22, 2020, 7:41pm UTC](https://discuss.elastic.co/t/filter-sonicwall-logstash/238146/1 "2020-06-22T19:41:28Z")

</div>

I'm new to Logstash and I'm trying to filter my Sonicwall log

My logstash.conf:

> input {  
> syslog {  
> type =\> Sonicwall  
> port =\> 9991  
> }  
> }
> 
> filter {  
> if [type] == "Sonicwall" {  
> kv {  
> exclude\_keys =\> ["c", "id", "m", "n", "pri", "proto"]  
> }  
> grok {  
> match =\> ["src", "%{IP:srcip}:%{DATA:srcinfo}"]  
> }  
> grok {  
> match =\> ["dst", "%{IP:dstip}:%{DATA:dstinfo}"]  
> }  
> grok {  
> remove\_field =\> ["srcinfo", "dstinfo"]  
> }  
> geoip {  
> add\_tag =\> ["geoip"]  
> source =\> "srcip"  
> database =\> "/etc/logstash/GeoLite2-City\_20200616/GeoLite2-City.mmdb"  
> }  
> }  
> }
> 
> output {  
> elasticsearch {  
> hosts =\> ["localhost:9200"]  
> index =\> "logstash-%{+YYYY.MM.dd}"  
> }  
> }

This code generates me some fieds in kibana, but I'm doing an integration with graphana. My question is also where I do this log filters, in elastic or in logstash.

That's right, but you give me little information. I need intrusions, viruses detected for example. Can anyone give me a light?

Sorry my english, i'm brazilian and i'm also new on the site

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 20, 2020, 7:41pm UTC](https://discuss.elastic.co/t/filter-sonicwall-logstash/238146/2 "2020-07-20T19:41:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
