# Fortinet log reading error in filebeat fortinet module v7.8.1

**URL:** <https://discuss.elastic.co/t/fortinet-log-reading-error-in-filebeat-fortinet-module-v7-8-1/245149>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 16, 2020, 3:18pm UTC](https://discuss.elastic.co/t/fortinet-log-reading-error-in-filebeat-fortinet-module-v7-8-1/245149 "2020-08-16T15:18:11Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![varun1992](https://avatars.discourse-cdn.com/v4/letter/v/3da27b/32.png) [@varun1992](https://discuss.elastic.co/u/varun1992)\
**Post date:** [August 16, 2020, 3:18pm UTC](https://discuss.elastic.co/t/fortinet-log-reading-error-in-filebeat-fortinet-module-v7-8-1/245149/1 "2020-08-16T15:18:11Z")

</div>

i am using filebeat version 7.8.1  
i got error saying

`Provided Grok expressions do not match field value: [date=2020-04-23 time=12:17:45 devname=\"testswitch1\" devid=\"somerouterid\" logid=\"0317013312\" type=\"utm\" subtype=\"webfilter\" eventtype=\"ftgd_allow\" level=\"notice\" vd=\"root\" eventtime=1587230266314799756 tz=\"-0500\" policyid=38 sessionid=543234 user=\"elasticuser\" group=\"elasticgroup\" authserver=\"elasticauth\" srcip=192.168.2.1 srcport=65236 srcintf=\"port1\" srcintfrole=\"lan\" dstip=8.8.8.8 dstport=443 dstintf=\"wan1\" dstintfrole=\"wan\" proto=6 service=\"HTTPS\" hostname=\"elastic.co\" profile=\"elasticruleset\" action=\"passthrough\" reqtype=\"direct\" url=\"/\" sentbyte=3545 rcvdbyte=6812 direction=\"outgoing\" msg=\"URL belongs to an allowed category in policy\" method=\"domain\" cat=23 catdesc=\"Web-based Email\"]`

original log as below

`date=2020-04-23 time=12:17:45 devname="testswitch1" devid="somerouterid" logid="0317013312" type="utm" subtype="webfilter" eventtype="ftgd_allow" level="notice" vd="root" eventtime=1587230266314799756 tz="-0500" policyid=38 sessionid=543234 user="elasticuser" group="elasticgroup" authserver="elasticauth" srcip=192.168.2.1 srcport=65236 srcintf="port1" srcintfrole="lan" dstip=8.8.8.8 dstport=443 dstintf="wan1" dstintfrole="wan" proto=6 service="HTTPS" hostname="elastic.co" profile="elasticruleset" action="passthrough" reqtype="direct" url="/" sentbyte=3545 rcvdbyte=6812 direction="outgoing" msg="URL belongs to an allowed category in policy" method="domain" cat=23 catdesc="Web-based Email"`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 13, 2020, 5:18pm UTC](https://discuss.elastic.co/t/fortinet-log-reading-error-in-filebeat-fortinet-module-v7-8-1/245149/2 "2020-09-13T17:18:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
