# Grok Filter For my Log file

**URL:** <https://discuss.elastic.co/t/grok-filter-for-my-log-file/170276>\
**Category:** Logstash\
**Created:** [February 28, 2019, 6:00am UTC](https://discuss.elastic.co/t/grok-filter-for-my-log-file/170276 "2019-02-28T06:00:06Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![sana1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sana1/32/46439_2.png) [@sana1](https://discuss.elastic.co/u/sana1)\
**Post date:** [February 28, 2019, 6:00am UTC](https://discuss.elastic.co/t/grok-filter-for-my-log-file/170276/1 "2019-02-28T06:00:06Z")

</div>

[**] [1:1000039:0] updatelocation - Alert [**]  
[Priority: 0]  
02/27-14:29:46.412090 0A:01:01:01:01:01 -\> 0A:02:02:02:02:02 type:0x800 len:0xC6  
10.1.1.1 -\> 10.2.2.2 SCTP TTL:255 TOS:0x0 ID:4660 IpLen:20 DgmLen:184

This is my log snort log file content, Please help me write the grok filter for logtsash  
Thankyou in Adv, I tried myself but no luck

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [February 28, 2019, 6:02am UTC](https://discuss.elastic.co/t/grok-filter-for-my-log-file/170276/2 "2019-02-28T06:02:41Z")

</div>

Sharing what you have tried would be useful 🙂

---

<div class="post-metadata">

**Author:** ![sana1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sana1/32/46439_2.png) [@sana1](https://discuss.elastic.co/u/sana1)\
**Post date:** [February 28, 2019, 6:28am UTC](https://discuss.elastic.co/t/grok-filter-for-my-log-file/170276/3 "2019-02-28T06:28:50Z")

</div>

I am using Logstash 6.6.0, and I am newbie to grok Filters..

input {  
beats{  
port =\> 5044   
}  
}  
filter {  
if [type] == "snort" {  
grok {  
patterns\_dir =\> ["misc.patterns"]  
match =\> { "message" =\> "%{\<?[?]:bracket} %{\<?1:00:0?\>:duration}" }  
}  
}  
}  
output {  
elasticsearch { hosts =\> ["localhost:9200"] }  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Post date:** [February 28, 2019, 7:51am UTC](https://discuss.elastic.co/t/grok-filter-for-my-log-file/170276/4 "2019-02-28T07:51:51Z")

</div>

can you place your log with prefromatted text so it will be helpful and explain do you have any recommended fields to store the value

---

<div class="post-metadata">

**Author:** ![sana1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sana1/32/46439_2.png) [@sana1](https://discuss.elastic.co/u/sana1)\
**Post date:** [February 28, 2019, 11:10am UTC](https://discuss.elastic.co/t/grok-filter-for-my-log-file/170276/5 "2019-02-28T11:10:46Z")

</div>

These are Snort Logs with no exact format, or predefined format.

these are four repetitive lines

[**] [1:1000089:0] notifySS - Alert [**]  
[Priority: 0]  
01/15-11:32:33.917427 0A:01:01:01:01:01 -\> 0A:02:02:02:02:02 type:0x800 len:0xA2  
12.12.12.12 -\> 11.11.11.11 SCTP TTL:255 TOS:0x0 ID:4660 IpLen:20 DgmLen:148

---

<div class="post-metadata">

**Author:** ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Post date:** [February 28, 2019, 11:16am UTC](https://discuss.elastic.co/t/grok-filter-for-my-log-file/170276/6 "2019-02-28T11:16:46Z")

</div>

> [@sana1](#):
>
> [**] [1:1000089:0] notifySS - Alert [**]  
> [Priority: 0]  
> 01/15-11:32:33.917427 0A:01:01:01:01:01 -\> 0A:02:02:02:02:02 type:0x800 len:0xA2  
> 12.12.12.12 -\> 11.11.11.11 SCTP TTL:255 TOS:0x0 ID:4660 IpLen:20 DgmLen:148

In this 4 lines what all value you need to capture

---

<div class="post-metadata">

**Author:** ![sana1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sana1/32/46439_2.png) [@sana1](https://discuss.elastic.co/u/sana1)\
**Post date:** [March 1, 2019, 7:53am UTC](https://discuss.elastic.co/t/grok-filter-for-my-log-file/170276/7 "2019-03-01T07:53:18Z")

</div>

Source IP, Destination IP and Protocol  
12.12.12.12 -\> 11.11.11.11 SCTP

---

<div class="post-metadata">

**Author:** ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Post date:** [March 1, 2019, 8:08am UTC](https://discuss.elastic.co/t/grok-filter-for-my-log-file/170276/8 "2019-03-01T08:08:25Z")

</div>

i want to one more thing above message which you have mentioned each line is new line or multiple line message

---

<div class="post-metadata">

**Author:** ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Post date:** [March 1, 2019, 8:42am UTC](https://discuss.elastic.co/t/grok-filter-for-my-log-file/170276/9 "2019-03-01T08:42:38Z")

</div>

> [@Ganesh2303](#):
>
> 12.12.12.12 -\> 11.11.11.11 SCTP TTL:255 TOS:0x0 ID:4660 IpLen:20 DgmLen:148

Try this grok pattern,

%{IP:Source} -\> %{IP:Destination} %{WORD:Protocol}

---

<div class="post-metadata">

**Author:** ![sana1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sana1/32/46439_2.png) [@sana1](https://discuss.elastic.co/u/sana1)\
**Post date:** [March 1, 2019, 9:16am UTC](https://discuss.elastic.co/t/grok-filter-for-my-log-file/170276/10 "2019-03-01T09:16:05Z")

</div>

Thankyou Ganesh its working, Please tell me how to parse the first two lines in the logs as well, Each line is a new line and also log pattern repeats every every fourth line

first two lines  
[**] [1:1000089:0] notifySS - Alert [**]  
[Priority: 0]

---

<div class="post-metadata">

**Author:** ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Post date:** [March 1, 2019, 9:18am UTC](https://discuss.elastic.co/t/grok-filter-for-my-log-file/170276/11 "2019-03-01T09:18:26Z")

</div>

> [@sana1](#):
>
> [**] [1:1000089:0] notifySS - Alert [**]  
> [Priority: 0]

If you dont want to index those value mean you can ignore the line before it get indexed

---

<div class="post-metadata">

**Author:** ![sana1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sana1/32/46439_2.png) [@sana1](https://discuss.elastic.co/u/sana1)\
**Post date:** [March 1, 2019, 9:28am UTC](https://discuss.elastic.co/t/grok-filter-for-my-log-file/170276/12 "2019-03-01T09:28:34Z")

</div>

Thankyou Ganesh 🙂

---

<div class="post-metadata">

**Author:** ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)\
**Post date:** [March 1, 2019, 9:57am UTC](https://discuss.elastic.co/t/grok-filter-for-my-log-file/170276/13 "2019-03-01T09:57:21Z")

</div>

You welcome.. If your issue resolved mark the resolved solution

---

<div class="post-metadata">

**Author:** ![sana1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sana1/32/46439_2.png) [@sana1](https://discuss.elastic.co/u/sana1)\
**Post date:** [March 3, 2019, 8:11am UTC](https://discuss.elastic.co/t/grok-filter-for-my-log-file/170276/14 "2019-03-03T08:11:38Z")

</div>

Please tell me how to add the parsed into separate fields?

---

<div class="post-metadata">

**Author:** ![sana1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sana1/32/46439_2.png) [@sana1](https://discuss.elastic.co/u/sana1)\
**Post date:** [March 4, 2019, 4:34am UTC](https://discuss.elastic.co/t/grok-filter-for-my-log-file/170276/15 "2019-03-04T04:34:27Z")

</div>

I have done that 🙂 Thankyou

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 1, 2019, 4:34am UTC](https://discuss.elastic.co/t/grok-filter-for-my-log-file/170276/16 "2019-04-01T04:34:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
