# FortiGate Firewall

**URL:** <https://discuss.elastic.co/t/fortigate-firewall/129245>\
**Category:** Logstash\
**Created:** [April 24, 2018, 7:35am UTC](https://discuss.elastic.co/t/fortigate-firewall/129245 "2018-04-24T07:35:44Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![lcguy](https://avatars.discourse-cdn.com/v4/letter/l/35a633/32.png) [@lcguy](https://discuss.elastic.co/u/lcguy)\
**Post date:** [April 24, 2018, 7:35am UTC](https://discuss.elastic.co/t/fortigate-firewall/129245/1 "2018-04-24T07:35:44Z")

</div>

Hi All,  
I am trying to parse the FortiGate firewall syslog in Logstash and still failing after spending many times.

Need your expertise for standard FortiGate syslog logstash config.

Here is current config. I'm getting the logs but all have \_grokparsefailure error. I am seeing whole "message" full of long output.

I would like to retrieve, dstip, srcip, srcport, dstport, geoip, etc.  
Thanks in advance.

input {  
udp {  
port =\> 5514  
type =\> syslog  
}  
}

filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}

output {  
elasticsearch { hosts =\> ["localhost:9200"] }  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![Krunal\_kalaria](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krunal_kalaria/32/23862_2.png) [@Krunal\_kalaria](https://discuss.elastic.co/u/Krunal_kalaria)\
**Post date:** [April 24, 2018, 7:39am UTC](https://discuss.elastic.co/t/fortigate-firewall/129245/2 "2018-04-24T07:39:22Z")

</div>

Hi @lcguy,  
This is working example of fortigate firewall config for logstash you can change with your environment if you have x-pack then leave as it is otherwise comment in output. I hope this helps to you.

input {  
udp {  
port =\> 7000  
type =\> "forti\_log"  
tags =\> ["location\_a"]  
}  
}

filter {  
#The Fortigate syslog contains a type field as well, we'll need to rename that field in order for this to work  
if [type] == "forti\_log" {

```
grok {
		match => ["message", "%{SYSLOG5424PRI:syslog_index}%{GREEDYDATA:message}"]
		overwrite => ["message"]
		tag_on_failure => ["forti_grok_failure"]
	}

    kv {
source => "message"
value_split => "="

```

#Expects you have csv enable set on your Fortigate. If not I think you'll have to change it to " " but I didn't test that.  
field\_split =\> ","  
}

```
mutate {

```

#I want to use the timestamp inside the logs instead of Logstash's timestamp so we'll first create a new field containing the date and time fields from the syslog before we convert that to the @timestamp field  
add\_field =\> { "temp\_time" =\> "%{date} %{time}" }  
#The syslog contains a type field which messes with the Logstash type field so we have to rename it.  
rename =\> { "type" =\> "ftg\_type" }  
rename =\> { "subtype" =\> "ftg\_subtype" }  
add\_field =\> { "type" =\> "forti\_log" }  
convert =\> { "rcvdbyte" =\> "integer" }  
convert =\> { "sentbyte" =\> "integer" }  
}

date {  
match =\> ["temp\_time", "yyyy-MM-dd HH:mm:ss"]  
timezone =\> "UTC"  
target =\> "@timestamp"  
}

```
mutate {

```

#add/remove fields as you see fit.  
remove\_field =\> ["syslog\_index","syslog5424\_pri","path","temp\_time","service","date","time","sentpkt","rcvdpkt","log\_id","message","poluuid"]  
}  
}  
}

output {  
stdout { codec =\> rubydebug }  
if [type] == "forti\_log" {  
elasticsearch {  
hosts =\> "localhost:9200"  
http\_compression =\> "true"  
index =\> "forti-%{+YYYY.MM.dd}"  
user =\> "elastic"  
password =\> "elastic"  
template =\> "/usr/share/logstash/bin/forti.json"  
template\_name =\> "forti-\*"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![lcguy](https://avatars.discourse-cdn.com/v4/letter/l/35a633/32.png) [@lcguy](https://discuss.elastic.co/u/lcguy)\
**Post date:** [April 24, 2018, 7:51am UTC](https://discuss.elastic.co/t/fortigate-firewall/129245/3 "2018-04-24T07:51:27Z")

</div>

Thanks, Krunal.  
I tried this logstash config but failed with only few message come out in Kibana.

Some questions allow me to ask;

- I didn't install Xpack. Do I need? I want to capture FortiGate firewall log. Fortigate will send syslog to CentOS Logstash via udp 5514.
- I also didn't see template name forti.json in "/usr/share/logstash/bin/forti.json". Where I can get this file?

Thanks.

---

<div class="post-metadata">

**Author:** ![Krunal\_kalaria](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krunal_kalaria/32/23862_2.png) [@Krunal\_kalaria](https://discuss.elastic.co/u/Krunal_kalaria)\
**Post date:** [April 24, 2018, 7:56am UTC](https://discuss.elastic.co/t/fortigate-firewall/129245/4 "2018-04-24T07:56:50Z")

</div>

So you can just remove those things that you dot need try this one this is without x-pack and no any template are used.

input {  
udp {  
port =\> 5514  
type =\> "forti\_log"  
}  
}

filter {  
if [type] == "forti\_log" {

```
grok {
		match => ["message", "%{SYSLOG5424PRI:syslog_index}%{GREEDYDATA:message}"]
		overwrite => ["message"]
		tag_on_failure => ["forti_grok_failure"]
	}

    kv {
source => "message"
value_split => "="
field_split => ","

```

}

```
mutate {
add_field => { "temp_time" => "%{date} %{time}" }
rename => { "type" => "ftg_type" }
rename => { "subtype" => "ftg_subtype" }
add_field => { "type" => "forti_log" }
convert => { "rcvdbyte" => "integer" }
convert => { "sentbyte" => "integer" }

```

}

date {  
match =\> ["temp\_time", "yyyy-MM-dd HH:mm:ss"]  
timezone =\> "UTC"  
target =\> "@timestamp"  
}

```
mutate {

```

#add/remove fields as you see fit.  
remove\_field =\> ["syslog\_index","syslog5424\_pri","path","temp\_time","service","date","time","sentpkt","rcvdpkt","log\_id","message","poluuid"]  
}  
}  
}

output {  
stdout { codec =\> rubydebug }  
if [type] == "forti\_log" {  
elasticsearch {  
hosts =\> "localhost:9200"  
http\_compression =\> "true"  
index =\> "forti-%{+YYYY.MM.dd}"  
}  
}  
}

Note:  
In fortigate firewall you have enable the csv forwarding if its not then do that first and then run this config.

Otherwise you can this following config:

input  
{  
udp  
{  
port =\> 5514  
type =\> "syslog"  
}  
}

filter  
{  
mutate  
{  
gsub =\>  
["message", ": ", ":",  
"message", "^\<[0-9][0-9][0-9]\>", ""]  
}  
kv  
{  
field\_split =\> ""," "  
source =\> "message"  
add\_field =\> ["sourcetime", "%{date}:%{time}"]  
}  
date { match =\> ["sourcetime","yyyy-MM-dd:HH:mm:ss"]}   
}

output  
{  
stdout { codec =\> rubydebug }  
elasticsearch  
{  
host =\> ["localhost:9200"]  
manage\_template =\> "false"  
index =\> "fortigate1-%{YYYY.mm.dd}"   
}  
}

Thanks & Regards,  
Krunal.

---

<div class="post-metadata">

**Author:** ![lcguy](https://avatars.discourse-cdn.com/v4/letter/l/35a633/32.png) [@lcguy](https://discuss.elastic.co/u/lcguy)\
**Post date:** [April 24, 2018, 8:12am UTC](https://discuss.elastic.co/t/fortigate-firewall/129245/5 "2018-04-24T08:12:13Z")

</div>

Thanks, Krunal. It seems like something wrong with config. I think syntax or white space in somewhere?  
Logstash can't load.

Mine is no CSV export enabled. Only using pure Syslog.

---

<div class="post-metadata">

**Author:** ![simmel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simmel/32/48040_2.png) [@simmel](https://discuss.elastic.co/u/simmel)\
**Post date:** [April 24, 2018, 8:26am UTC](https://discuss.elastic.co/t/fortigate-firewall/129245/6 "2018-04-24T08:26:02Z")

</div>

> Here is current config. I'm getting the logs but all have  
> \_grokparsefailure error. I am seeing whole "message" full of long  
> output.

No need to reinvent the wheel, use the `SYSLOGLINE` pattern from  
[https://github.com/logstash-plugins/logstash-patterns-core/blob/master/patterns/linux-syslog](https://github.com/logstash-plugins/logstash-patterns-core/blob/master/patterns/linux-syslog)

> I would like to retrieve, dstip, srcip, srcport, dstport, geoip, etc.

I'd use the [kv filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-kv.html)  
with `include_keys`.

---

<div class="post-metadata">

**Author:** ![lcguy](https://avatars.discourse-cdn.com/v4/letter/l/35a633/32.png) [@lcguy](https://discuss.elastic.co/u/lcguy)\
**Post date:** [April 24, 2018, 8:33am UTC](https://discuss.elastic.co/t/fortigate-firewall/129245/7 "2018-04-24T08:33:54Z")

</div>

Wow...Simmel.  
I am very new to programming. No idea where to put these lines.  
Can give me some simple config and I can play later?

Thanks.

---

<div class="post-metadata">

**Author:** ![Krunal\_kalaria](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krunal_kalaria/32/23862_2.png) [@Krunal\_kalaria](https://discuss.elastic.co/u/Krunal_kalaria)\
**Post date:** [April 24, 2018, 8:34am UTC](https://discuss.elastic.co/t/fortigate-firewall/129245/8 "2018-04-24T08:34:10Z")

</div>

if you are collecting without csv syslog then last conf file working fine for me with csv also its working fine for me.

Do one thing create one normal conf file only input and output and then you will add this filter in last.

filter  
{  
mutate  
{  
gsub =\>  
["message", ": ", ":",  
"message", "^\<[0-9][0-9][0-9]\>", ""]  
}  
kv  
{  
field\_split =\> ""," "  
source =\> "message"  
add\_field =\> ["sourcetime", "%{date}:%{time}"]  
}  
date { match =\> ["sourcetime","yyyy-MM-dd:HH:mm:ss"]}   
}

first you create normal input and output file and run and see that logs are coming in what format then you add above filter. it;s may be worked for you.

Thanks & Regards,  
Krunal.

---

<div class="post-metadata">

**Author:** ![lcguy](https://avatars.discourse-cdn.com/v4/letter/l/35a633/32.png) [@lcguy](https://discuss.elastic.co/u/lcguy)\
**Post date:** [April 24, 2018, 8:49am UTC](https://discuss.elastic.co/t/fortigate-firewall/129245/9 "2018-04-24T08:49:45Z")

</div>

Works with following config now. Seems like error in kv. After I comment out kv, all works.  
Do I need to install something to work with kv filter?

input {  
udp {  
port =\> 5514  
type =\> "syslog"  
}  
}

filter {  
mutate {  
gsub =\>  
["message", ": ", ":",  
"message", "^\<[0-9][0-9][0-9]\>", ""]  
}

#kv {

# field\_split =\> ""," "

# source =\> "message"

# add\_field =\> ["sourcetime", "%{date}:%{time}"]

# }

#date { match =\> ["sourcetime","yyyy-MM-dd:HH:mm:ss"]}  
}

output {  
elasticsearch { hosts =\> ["localhost:9200"] }  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![Krunal\_kalaria](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/krunal_kalaria/32/23862_2.png) [@Krunal\_kalaria](https://discuss.elastic.co/u/Krunal_kalaria)\
**Post date:** [April 24, 2018, 11:01am UTC](https://discuss.elastic.co/t/fortigate-firewall/129245/10 "2018-04-24T11:01:42Z")

</div>

ohhh Great!!

now what is your output all the information you want that you are receiving or not ?

or still something is missing ?

Thanks & Regards,  
Krunal.

---

<div class="post-metadata">

**Author:** ![lcguy](https://avatars.discourse-cdn.com/v4/letter/l/35a633/32.png) [@lcguy](https://discuss.elastic.co/u/lcguy)\
**Post date:** [April 24, 2018, 3:37pm UTC](https://discuss.elastic.co/t/fortigate-firewall/129245/11 "2018-04-24T15:37:14Z")

</div>

Yes, it works now for FortiGate firewall.  
I have tweak a bit. I copied some from other people's posts.

Thanks a lot, Krunal.

input {  
udp {  
port =\> 5514  
type =\> "syslog"  
}  
}

filter {  
mutate {  
gsub =\>  
["message", ": ", ":",  
"message", "^\<[0-9][0-9][0-9]\>", ""]  
}

kv { }

if [msg] {  
mutate {  
replace =\> ["message", "%{msg}"]  
}  
}  
}

output {  
elasticsearch { hosts =\> ["localhost:9200"] }  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 22, 2018, 3:49pm UTC](https://discuss.elastic.co/t/fortigate-firewall/129245/12 "2018-05-22T15:49:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
