# GROK filter is not parsing the windows firewall logs for ICMP traffic

**URL:** <https://discuss.elastic.co/t/grok-filter-is-not-parsing-the-windows-firewall-logs-for-icmp-traffic/228011>\
**Category:** Logstash\
**Created:** [April 15, 2020, 12:06am UTC](https://discuss.elastic.co/t/grok-filter-is-not-parsing-the-windows-firewall-logs-for-icmp-traffic/228011 "2020-04-15T00:06:46Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Prabhu\_Chinnasamy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/prabhu_chinnasamy/32/66238_2.png) [@Prabhu\_Chinnasamy](https://discuss.elastic.co/u/Prabhu_Chinnasamy)\
**Post date:** [April 15, 2020, 12:06am UTC](https://discuss.elastic.co/t/grok-filter-is-not-parsing-the-windows-firewall-logs-for-icmp-traffic/228011/1 "2020-04-15T00:06:46Z")

</div>

All,

I am sending the windows firewall logs to logstash and created a GROK filter to parse the log.  
my GROK filter is:

"%{TIMESTAMP\_ISO8601:TimeStamp} %{WORD:Action} %{WORD:Protocol} %{IP:Source\_IP} %{IP:Destination\_IP} %{INT:SrcPort} %{INT:DstPort} %{INT:Size} %{GREEDYDATA:Flags} %{GREEDYDATA:Direction}

Its parsing the logs perfectly for TCP and UDP protocols but for the ICMP traffic its not doing that.  
in Kibana all I see for ICMP connections is:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/a/dad395bbfbc637586ea78806923a7ad2d93cd9f6.png)

Please help.

---

<div class="post-metadata">

**Author:** ![Fabio-sama](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@Fabio-sama](https://discuss.elastic.co/u/Fabio-sama)\
**Post date:** [April 15, 2020, 8:48am UTC](https://discuss.elastic.co/t/grok-filter-is-not-parsing-the-windows-firewall-logs-for-icmp-traffic/228011/2 "2020-04-15T08:48:19Z")

</div>

Hi there,

do those documents have `_grokparsefailure` in their tags field? Can you share here a sample of ICMP event you're trying to parse?

---

<div class="post-metadata">

**Author:** ![Prabhu\_Chinnasamy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/prabhu_chinnasamy/32/66238_2.png) [@Prabhu\_Chinnasamy](https://discuss.elastic.co/u/Prabhu_Chinnasamy)\
**Post date:** [April 15, 2020, 3:11pm UTC](https://discuss.elastic.co/t/grok-filter-is-not-parsing-the-windows-firewall-logs-for-icmp-traffic/228011/3 "2020-04-15T15:11:03Z")

</div>

HI Fabio,

no errors but the fileds are blank in kibana for ICMP traffic.

I amusing the below GROK filters:  
%{TIMESTAMP\_ISO8601:TimeStamp} %{WORD:Action} %{WORD:Protocol} %{IP:Source IP} %{IP:Destination IP} %{INT:SrcPort} %{INT:DstPort} %{INT:Size} %{GREEDYDATA:Flags} %{GREEDYDATA:Direction}

And,  
I see all the fields in kibana for TCP /UDP traffic:  
Sample TCP log:  
2020-04-14 14:51:12 ALLOW TCP 127.0.0.1 127.0.0.1 61010 49671 0 - 0 0 0 - - - RECEIVE

BUt for ICMP traffic, the fields in kibana are empty:  
Sample ICMP traffic:  
2020-04-14 15:46:03 ALLOW ICMP 10.34.1.176 10.100.24.146 - - 0 - - - - 8 0 - RECEIVE

When i try in GROK debugger, looks like the pattern is not matching for the fields in ICMP srcport /destport " - - 0 - - - - " as ICMP traffic will not be having source or destination port in log.

Need help to build GROK filter which can correctly parse teh TCP/UDP and ICMP as well so that I can see all the fields in kibana.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 15, 2020, 3:34pm UTC](https://discuss.elastic.co/t/grok-filter-is-not-parsing-the-windows-firewall-logs-for-icmp-traffic/228011/4 "2020-04-15T15:34:40Z")

</div>

- does not match INT. You can use alternation to match it...

```
(%{INT:SrcPort}|-)
```

---

<div class="post-metadata">

**Author:** ![Prabhu\_Chinnasamy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/prabhu_chinnasamy/32/66238_2.png) [@Prabhu\_Chinnasamy](https://discuss.elastic.co/u/Prabhu_Chinnasamy)\
**Post date:** [April 15, 2020, 3:58pm UTC](https://discuss.elastic.co/t/grok-filter-is-not-parsing-the-windows-firewall-logs-for-icmp-traffic/228011/5 "2020-04-15T15:58:25Z")

</div>

Hi Badger,

I have changed my GROK filter as below:  
"%{TIMESTAMP\_ISO8601:TimeStamp} %{WORD:Action} %{WORD:Protocol} %{IP:Source\_IP} %{IP:Destination\_IP} (%{INT:SrcPort}|-) (%{INT:DStPort}|-) %{INT:Size} %{GREEDYDATA:Flags} %{GREEDYDATA:Direction}"

Now, the ICMP traffic is logging correctly but the TCP/UDP traffic is missing the 'destport'.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/d/ed99813f8a3b3c42aa4ce8a27a81173d6b391682.png)

---

<div class="post-metadata">

**Author:** ![Fabio-sama](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@Fabio-sama](https://discuss.elastic.co/u/Fabio-sama)\
**Post date:** [April 16, 2020, 1:53pm UTC](https://discuss.elastic.co/t/grok-filter-is-not-parsing-the-windows-firewall-logs-for-icmp-traffic/228011/6 "2020-04-16T13:53:14Z")

</div>

> [@Prabhu\_Chinnasamy](#):
>
> 2020-04-14 14:51:12 ALLOW TCP 127.0.0.1 127.0.0.1 61010 49671 0 - 0 0 0 - - - RECEIVE

You sure those events do have a destination port? Can you expand one of them? Cause it seems to work properly with the TCP event you posted above:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/c/ec6ccc93fe66fbb580e47db479548df9e47f0e5d.png)

---

<div class="post-metadata">

**Author:** ![Prabhu\_Chinnasamy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/prabhu_chinnasamy/32/66238_2.png) [@Prabhu\_Chinnasamy](https://discuss.elastic.co/u/Prabhu_Chinnasamy)\
**Post date:** [April 20, 2020, 7:05pm UTC](https://discuss.elastic.co/t/grok-filter-is-not-parsing-the-windows-firewall-logs-for-icmp-traffic/228011/7 "2020-04-20T19:05:32Z")

</div>

Correct: The ICMP traffic doesn't have dest port, thats why this field is empty. Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 18, 2020, 7:05pm UTC](https://discuss.elastic.co/t/grok-filter-is-not-parsing-the-windows-firewall-logs-for-icmp-traffic/228011/8 "2020-05-18T19:05:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
