# Grok help with cisco firepower 2130

**URL:** https://discuss.elastic.co/t/grok-help-with-cisco-firepower-2130/211465
**Category:** Logstash
**Created:** [December 11, 2019, 12:29pm UTC](https://discuss.elastic.co/t/grok-help-with-cisco-firepower-2130/211465 "2019-12-11T12:29:56Z")
**Posts on this page:** 1
**Showing post:** 4

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [January 3, 2020, 3:41pm UTC](https://discuss.elastic.co/t/grok-help-with-cisco-firepower-2130/211465/4 "2020-01-03T15:41:40Z")

</div>

I would use dissect to parse the first 2 fields, then dissect to parse the rest of the line. See [this](https://discuss.elastic.co/t/parsing-firewall-logs-in-logstash/212786/2) for an example.

---

_[View the full topic](https://discuss.elastic.co/t/grok-help-with-cisco-firepower-2130/211465)._
