# Grok Parse Failure when dealing with IPv6 addresses

**URL:** <https://discuss.elastic.co/t/grok-parse-failure-when-dealing-with-ipv6-addresses/69629>\
**Category:** Logstash\
**Created:** [December 21, 2016, 3:20am UTC](https://discuss.elastic.co/t/grok-parse-failure-when-dealing-with-ipv6-addresses/69629 "2016-12-21T03:20:59Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rebelpyr7](https://avatars.discourse-cdn.com/v4/letter/r/8c91f0/32.png) [@Rebelpyr7](https://discuss.elastic.co/u/Rebelpyr7)\
**Post date:** [December 21, 2016, 3:20am UTC](https://discuss.elastic.co/t/grok-parse-failure-when-dealing-with-ipv6-addresses/69629/1 "2016-12-21T03:20:59Z")

</div>

Hello all!

I’ve been slowly learning how to use the ELK stack and getting it to work with my PFsense logs and have gotten almost everything to work. Right now the only issue I have seems to be related to IPv6 addresses.

The logs that failed parsing are below.

> 7,16777216,,1000000105,bridge0,match,block,in,6,0x00,0x00000,1,UDP,17,99,fe80::d48f:e3dc:dbbe:c74,ff02::1:2,546,547,99

> 12,16777216,,1000000107,em0,match,pass,in,6,0x00,0x00000,255,ICMPv6,58,32,fe80::217:10ff:fe87:a91f,fe80::278:2aff:fee8:3554

The pattern that I am matching the log against is below.

> %{PFSENSE\_LOG\_DATA}%{PFSENSE\_IP\_SPECIFIC\_DATA}%{PFSENSE\_IP\_DATA}%{PFSENSE\_PROTOCOL\_DATA}

Doing some testing and changes on [https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/) let me narrow down the issue to the last bit (%{PFSENSE\_PROTOCOL\_DATA}). I’ve provided the pattern for that section below.

> PFSENSE\_PROTOCOL\_DATA (%{PFSENSE\_TCP\_DATA}|%{PFSENSE\_UDP\_DATA}|%{PFSENSE\_ICMP\_DATA}|%{PFSENSE\_CARP\_DATA})

> PFSENSE\_TCP\_DATA (%{INT:src\_port}),(%{INT:dest\_port}),(%{INT:data\_length}),(%{WORD:tcp\_flags}),(%{INT:sequence\_number}),(%{INT:ack\_number}),(%{INT:tcp\_window}),(%{DATA:urg\_data}),(%{DATA:tcp\_options})

> PFSENSE\_UDP\_DATA (%{INT:src\_port}),(%{INT:dest\_port}),(%{INT:data\_length})

> PFSENSE\_ICMP\_DATA (%{PFSENSE\_ICMP\_TYPE}%{PFSENSE\_ICMP\_RESPONSE})

> PFSENSE\_ICMP\_TYPE (?\<icmp\_type\>(request|reply|unreachproto|unreachport|unreach|timeexceed|paramprob|redirect|maskreply|needfrag|tstamp|tstampreply)),

> PFSENSE\_ICMP\_RESPONSE (%{PFSENSE\_ICMP\_ECHO\_REQ\_REPLY}|%{PFSENSE\_ICMP\_UNREACHPORT}| %{PFSENSE\_ICMP\_UNREACHPROTO}|%{PFSENSE\_ICMP\_UNREACHABLE}|%{PFSENSE\_ICMP\_NEED\_FLAG}|%{PFSENSE\_ICMP\_TSTAMP}|%{PFSENSE\_ICMP\_TSTAMP\_REPLY})

> PFSENSE\_ICMP\_ECHO\_REQ\_REPLY (%{INT:icmp\_echo\_id}),(%{INT:icmp\_echo\_sequence})

> PFSENSE\_ICMP\_UNREACHPORT (%{IP:icmp\_unreachport\_dest\_ip}),(%{WORD:icmp\_unreachport\_protocol}),(%{INT:icmp\_unreachport\_port})

> PFSENSE\_ICMP\_UNREACHPROTO (%{IP:icmp\_unreach\_dest\_ip}),(%{WORD:icmp\_unreachproto\_protocol})

> PFSENSE\_ICMP\_UNREACHABLE (%{GREEDYDATA:icmp\_unreachable})

> PFSENSE\_ICMP\_NEED\_FLAG (%{IP:icmp\_need\_flag\_ip}),(%{INT:icmp\_need\_flag\_mtu})

> PFSENSE\_ICMP\_TSTAMP (%{INT:icmp\_tstamp\_id}),(%{INT:icmp\_tstamp\_sequence})

> PFSENSE\_ICMP\_TSTAMP\_REPLY (%{INT:icmp\_tstamp\_reply\_id}),(%{INT:icmp\_tstamp\_reply\_sequence}),(%{INT:icmp\_tstamp\_reply\_otime}),(%{INT:icmp\_tstamp\_reply\_rtime}),(%{INT:icmp\_tstamp\_reply\_ttime})

> PFSENSE\_CARP\_DATA (%{WORD:carp\_type}),(%{INT:carp\_ttl}),(%{INT:carp\_vhid}),(%{INT:carp\_version}),(%{INT:carp\_advbase}),(%{INT:carp\_advskew})

I am currently using the latest versions of the ELK stack and PFSense.

I want to believe it has something to do with the syntax of the custom pattern regarding IPv6 addresses but I am not that familiar with the IPv6 syntax so not sure if I am looking at the wrong area or not.

Any guidance would be appreciated.

---

<div class="post-metadata">

**Author:** ![Rebelpyr7](https://avatars.discourse-cdn.com/v4/letter/r/8c91f0/32.png) [@Rebelpyr7](https://discuss.elastic.co/u/Rebelpyr7)\
**Post date:** [December 29, 2016, 3:02am UTC](https://discuss.elastic.co/t/grok-parse-failure-when-dealing-with-ipv6-addresses/69629/2 "2016-12-29T03:02:27Z")

</div>

Anyone have any advice on this?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 26, 2017, 3:02am UTC](https://discuss.elastic.co/t/grok-parse-failure-when-dealing-with-ipv6-addresses/69629/3 "2017-01-26T03:02:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
