# Grok pattern for snort alerts

**URL:** <https://discuss.elastic.co/t/grok-pattern-for-snort-alerts/306625>\
**Category:** Logstash\
**Created:** [June 8, 2022, 5:28am UTC](https://discuss.elastic.co/t/grok-pattern-for-snort-alerts/306625 "2022-06-08T05:28:19Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![anushka1203](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anushka1203/32/98018_2.png) [@anushka1203](https://discuss.elastic.co/u/anushka1203)\
**Post date:** [June 8, 2022, 5:28am UTC](https://discuss.elastic.co/t/grok-pattern-for-snort-alerts/306625/1 "2022-06-08T05:28:19Z")

</div>

HI everyone,

Need help constructing grok pattern for the snort alert log file. I have the so far, but the output is incomplete -

```auto
%{MONTHNUM:month}\/%{MONTHDAY:day}-%{HOUR:hour}:%{MINUTE:minute}:%{SECOND:second}\s+\[\*\*\]\s+\[%{INT:ids_gid}\:%{INT:ids_sid}\:%{INT:ids_rev}\]\s+%{DATA:ids_proto}\s+\[\*\*\]\s+\[Classification:\s+%{DATA:ids_classification}\]\s+\[Priority:\s+%{INT:priority}\]\s+\{%{WORD:ids_proto}\}\s+%{IP:src_ip}\:%{INT:src_port}\s+\-\>\s+%{IP:dst_ip}\:%{INT:dst_port}

```

Output-

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/3/63b717c789f7446bdd01a79fcf4a68cb7fa35c56.png)

why are the fields from priority onwards not extracted?  
Help would be appreciated.  
Thanks in advance

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 8, 2022, 4:01pm UTC](https://discuss.elastic.co/t/grok-pattern-for-snort-alerts/306625/2 "2022-06-08T16:01:53Z")

</div>

Please do not post pictures of text, they cannot be searched, and we cannot copy and paste them to try to reproduce and diagnose the issue.

---

<div class="post-metadata">

**Author:** ![anushka1203](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anushka1203/32/98018_2.png) [@anushka1203](https://discuss.elastic.co/u/anushka1203)\
**Post date:** [June 8, 2022, 5:11pm UTC](https://discuss.elastic.co/t/grok-pattern-for-snort-alerts/306625/3 "2022-06-08T17:11:43Z")

</div>

My apologies. These are my sample log messages-

```auto
05/25-12:03:17.905976 [**] [1:100001:1] ICMP Ping Detected [**] [Priority: 0] {IPV6-ICMP} fe80::20c:29ff:feba:be38 -> ff02::1
05/25-12:03:17.914533 [**] [1:100001:1] ICMP Ping Detected [**] [Classification: a i l] [Priority: 0] {IPV6-ICMP} fe80::20c:29ff:feca:579 -> ff02::16

```

ANd this is the pattern that works for the @nd entre but not the first one.

```auto
%{MONTHNUM:month}\/%{MONTHDAY:day}-%{HOUR:hour}:%{MINUTE:minute}:%{SECOND:second}\s+\[\*\*\] \[%{INT:ids_gid}:%{INT:ids_sid}:%{INT:ids_rev}\]\s+%{DATA:ids_proto}\s+\[\*\*\] \[.*?: %{DATA:Classification}\] \[.*?: %{INT:Priority}\] \{%{DATA:data}} %{IP:dst_ip} .*?> %{IP:dest_port}

```

It is due to the presence of the field "classification". how do I get it to work for both?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 8, 2022, 5:31pm UTC](https://discuss.elastic.co/t/grok-pattern-for-snort-alerts/306625/4 "2022-06-08T17:31:09Z")

</div>

You can make a field (and related whitespace) option by surrounding them with `()?`, which means zero-or-more-of.

```
grok { match => { "message" => "%{MONTHNUM:month}\/%{MONTHDAY:day}-%{HOUR:hour}:%{MINUTE:minute}:%{SECOND:second}\s+\[\*\*\] \[%{INT:ids_gid}:%{INT:ids_sid}:%{INT:ids_rev}\]\s+%{DATA:ids_proto}\s+\[\*\*\] (\[.*?: %{DATA:Classification}\] )?\[.*?: %{INT:Priority}\] \{%{DATA:data}} %{IP:dst_ip} .*?> %{IP:dest_port}" } }

```

If there are more variants then you might want to take an alternate approach. Perhaps something like [this](https://discuss.elastic.co/t/metatrader-how-parse-such-logs/248406/2).

---

<div class="post-metadata">

**Author:** ![anushka1203](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anushka1203/32/98018_2.png) [@anushka1203](https://discuss.elastic.co/u/anushka1203)\
**Post date:** [June 9, 2022, 1:54pm UTC](https://discuss.elastic.co/t/grok-pattern-for-snort-alerts/306625/5 "2022-06-09T13:54:27Z")

</div>

This works. Thank you so much!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 7, 2022, 1:54pm UTC](https://discuss.elastic.co/t/grok-pattern-for-snort-alerts/306625/6 "2022-07-07T13:54:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
