# Grok pattern Syslog auth

**URL:** <https://discuss.elastic.co/t/grok-pattern-syslog-auth/304911>\
**Category:** Logstash\
**Created:** [May 17, 2022, 9:33am UTC](https://discuss.elastic.co/t/grok-pattern-syslog-auth/304911 "2022-05-17T09:33:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![CemG](https://avatars.discourse-cdn.com/v4/letter/c/46a35a/32.png) [@CemG](https://discuss.elastic.co/u/CemG)\
**Post date:** [May 17, 2022, 9:33am UTC](https://discuss.elastic.co/t/grok-pattern-syslog-auth/304911/1 "2022-05-17T09:33:56Z")

</div>

Hello,

I have to grok my syslog auth logs from Linux, I have a pattern, but it still nonmatch with the logs, can someone help me to see if there is an error in my gros pattern ?

My filter

```auto
filter {
        json {
                source => "message"
                target => ""
        }

        mutate {
                remove_field => ["[message]"]
        }

        if [event][module] == "system" {
                if [fileset][name] == "auth" {
                        grok {
                                match => {
                                        "[event][original]" => [
                                                "%{SYSLOGTIMESTAMP:system.auth.timestamp} %{SYSLOGHOST:system.auth.hostname} sshd(?:\\[%{POSINT:system.auth.pid}\\])?: %{DATA:system.auth.ssh.event} %{DATA:system.auth.ssh.method} for (invalid user )?%{DATA:system.auth.user} from %{IPORHOST:system.auth.ip} port %{NUMBER:system.auth.port} ssh2(: %{GREEDYDATA:system.auth.ssh.signature})?",
						"%{SYSLOGTIMESTAMP:system.auth.timestamp} %{SYSLOGHOST:system.auth.hostname} sshd(?:\\[%{POSINT:system.auth.pid}\\])?: %{DATA:system.auth.ssh.event} user %{DATA:system.auth.user} from %{IPORHOST:system.auth.ip}"
                                        ]
                                }

                                add_tag => ["_grok_system_auth_success"]
                                tag_on_failure => ["_grok_system_auth_nomatch"]
                        }

                        date {
                                match => ["[system][auth][timestamp]", "MMM d HH:mm:ss", "MMM dd HH:mm:ss" ]
                        }

                        geoip {
                                source => "[system][auth][ssh][ip]"
                                target => "[system][auth][ssh][geoip]"
                        }
                }
        }

}

```

Data in **event.original** that I want to grok

```auto
May 17 11:12:11 scanner sshd[2161]: Failed password for secu from 10.60.22.4 port 50798 ssh2
May 17 11:15:25 scanner sshd[2164]: Accepted password for secu from 10.60.22.4 port 50822 ssh2
May 16 19:19:26 scanner sshd[16153]: Failed password for invalid user seuc from 10.60.22.4 port 52772 ssh2

```

Thank you for your help

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 17, 2022, 11:03am UTC](https://discuss.elastic.co/t/grok-pattern-syslog-auth/304911/2 "2022-05-17T11:03:52Z")

</div>

Do you have double \ in sshd(?:\[%{POSINT:system.auth.pid}\])? If does, replace with single. Both pattern are OK in Grok debuger.  
Other than that, maybe IFs conditions are not OK.

---

<div class="post-metadata">

**Author:** ![CemG](https://avatars.discourse-cdn.com/v4/letter/c/46a35a/32.png) [@CemG](https://discuss.elastic.co/u/CemG)\
**Post date:** [May 17, 2022, 11:47am UTC](https://discuss.elastic.co/t/grok-pattern-syslog-auth/304911/3 "2022-05-17T11:47:51Z")

</div>

> [@CemG](#):
>
> `%{SYSLOGTIMESTAMP:system.auth.timestamp} %{SYSLOGHOST:system.auth.hostname} sshd(?:\\[%{POSINT:system.auth.pid}\\])?: %{DATA:system.auth.ssh.event} %{DATA:system.auth.ssh.method} for (invalid user )?%{DATA:system.auth.user} from %{IPORHOST:system.auth.ip} port %{NUMBER:system.auth.port} ssh2(: %{GREEDYDATA:system.auth.ssh.signature})?`

That was the issue, by replacing double \ by only one, it solve and match, Thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2022, 11:48am UTC](https://discuss.elastic.co/t/grok-pattern-syslog-auth/304911/4 "2022-06-14T11:48:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
