# Grok stopping output to elasticsearch from logstash

**URL:** <https://discuss.elastic.co/t/grok-stopping-output-to-elasticsearch-from-logstash/185914>\
**Category:** Logstash\
**Created:** [June 14, 2019, 9:57pm UTC](https://discuss.elastic.co/t/grok-stopping-output-to-elasticsearch-from-logstash/185914 "2019-06-14T21:57:49Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![legacyboy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legacyboy/32/48165_2.png) [@legacyboy](https://discuss.elastic.co/u/legacyboy)\
**Post date:** [June 14, 2019, 9:57pm UTC](https://discuss.elastic.co/t/grok-stopping-output-to-elasticsearch-from-logstash/185914/1 "2019-06-14T21:57:49Z")

</div>

I am having an issue with grok on my syslog content.

I am getting logs but when I try to use grok on it everything stops.

Sample data;

```auto
<85>Jun 14 16:38:36--5:00 10.128.107.37 Action="drop" UUid="{0x0,0x0,0x0,0x0}" inzone="External"

```

There is more information after inzone, but I am trying to figure out the issue so right now I am just trying to match the Date IP of the host then GreedyData for the rest.  
I had thought that removing greedydata might help but it does not.

grok

```auto
 <%{NUMBER}>%{SYSLOGTIMESTAMP:syslog_timestamp}\S+ %{IP:syslog_host} %{GREEDYDATA:syslog_message}

```

I get no errors, I just stop getting data in Kibana to see. if I comment out the grok in my config it starts coming back in again.

Logstash is starting after I uncomment the grok in the config file I just get no data. Then I remove it and the data comes back.

A full line of data with that grok works fine in the debugger.

Config file.  
=-=-=-=-=-=-=-=-=-=-

```auto
input {
        tcp {
        type => "syslog"
        port => 5140
        }
}

input {
        udp {
        type => "syslog"
        port => 5140
        }
}

filter {
               grok {
                       match => { "message" => ["<%{NUMBER}>%{SYSLOGTIMESTAMP:syslog_timestamp}\S+ %{IP:syslog_hostname} %{GREEDYDATA:test}"
                               ]}
               }

        date {
                match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
                timezone => "UTC"
        }
}

output {
if [type] == "syslog" and "_grokparsefailure" in [tags] {
        file { path => "/var/log/failed_syslog_events" }
}
  elasticsearch {
        hosts => ["localhost:9200"]
  }
}

```

_[EDIT: added code fences (`~~~`) around each code block to improve readability -- @yaauie]_

---

<div class="post-metadata">

**Author:** ![Andre\_Letterer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andre_letterer/32/42248_2.png) [@Andre\_Letterer](https://discuss.elastic.co/u/Andre_Letterer)\
**Post date:** [June 17, 2019, 11:36am UTC](https://discuss.elastic.co/t/grok-stopping-output-to-elasticsearch-from-logstash/185914/2 "2019-06-17T11:36:06Z")

</div>

Hi,

Have a very welcome at the Elastic community.  
Thank you for your post.

At first I had a short look on your message format.  
What is weird on this message for me, is the timestamp. Would you mind to describe the source of this message?  
In the defined rfc definitions especially this string especially is not possible `--5:00`  
[https://www.ietf.org/rfc/rfc3164.txt](https://www.ietf.org/rfc/rfc3164.txt) rfc3164 bsd syslog protocol 4.1.2  
[https://www.ietf.org/rfc/rfc5424.txt](https://www.ietf.org/rfc/rfc5424.txt) rfc5424 syslog protocol 6.2.3.1. examples  
[https://www.ietf.org/rfc/rfc3339.txt](https://www.ietf.org/rfc/rfc3339.txt) rfc3339 internet timestamps  
If you have a look to the examples there, there is always without a timezone information or if timezone, then like this `+00:00` or `-00:00` and without space after the seconds.

Ok if you have this grok active what happens in your logstash log? Would you mind posting the logfile and the logstash configuration file. Because I had a short test and apart, that I would change some things on the grok itself which we could discuss later on, the logstash configuration started very normally. What logstash version you are using?

---

<div class="post-metadata">

**Author:** ![legacyboy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legacyboy/32/48165_2.png) [@legacyboy](https://discuss.elastic.co/u/legacyboy)\
**Post date:** [June 17, 2019, 3:40pm UTC](https://discuss.elastic.co/t/grok-stopping-output-to-elasticsearch-from-logstash/185914/3 "2019-06-17T15:40:00Z")

</div>

The source is a checkpoint firewall;  
Here is anything in logstash.yml that does not have a # in front.

```
 cat logstash.yml | grep -v \#
pipeline.batch.size: 225
path.data: /var/lib/logstash
pipeline.workers: 8
path.logs: /var/log/logstash

```

I think I have found where all my events are going to;

```
if [type] == "syslog" and "_grokparsefailure" in [tags] {
    file { path => "/var/log/failed_syslog_events" }
}

```

It looks like all the events are going in to that. So its failing grok parsing. I am just not sure why.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 17, 2019, 4:49pm UTC](https://discuss.elastic.co/t/grok-stopping-output-to-elasticsearch-from-logstash/185914/4 "2019-06-17T16:49:09Z")

</div>

Which version are you running? With 7.1.1 the following parses just fine

```
input { generator { count => 1 lines => ['<85>Jun 14 16:38:36--5:00 10.128.107.37 Action="drop" UUid="{0x0,0x0,0x0,0x0}" inzone="External"'] } }
filter {
    grok {
        match => {
            "message" => ["<%{NUMBER}>%{SYSLOGTIMESTAMP:syslog_timestamp}\S+ %{IP:syslog_hostname} %{GREEDYDATA:test}"]
        }
    }
}
output { stdout { codec => rubydebug { metadata => false } } }

```

It took me a minute to understand that you are using \S+ to discard the timezone 🙂

---

<div class="post-metadata">

**Author:** ![legacyboy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legacyboy/32/48165_2.png) [@legacyboy](https://discuss.elastic.co/u/legacyboy)\
**Post date:** [June 17, 2019, 6:22pm UTC](https://discuss.elastic.co/t/grok-stopping-output-to-elasticsearch-from-logstash/185914/5 "2019-06-17T18:22:25Z")

</div>

I am using 7.1.1.  
I just tried your exact parser, which makes sense to me, and it it tests fine in grok debugger.  
But its now tossing everything into my failed\_syslog\_events file.  
Even stuff that is working in the debugger.

It seems to be something with the date.

This does not work;  
\<%{NUMBER}\>%{SYSLOGTIMESTAMP:syslog\_timestamp}\S+ %{IP:syslog\_hostname} %{GREEDYDATA:test}

Nor this;  
\<%{NUMBER}\>%{SYSLOGTIMESTAMP:syslog\_timestamp}\S+ %{GREEDYDATA:test}

Or this;  
\<%{NUMBER}\>%{SYSLOGTIMESTAMP:syslog\_timestamp}%{GREEDYDATA:test}  
But this does  
\<%{NUMBER}\>%{GREEDYDATA:test}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 17, 2019, 6:41pm UTC](https://discuss.elastic.co/t/grok-stopping-output-to-elasticsearch-from-logstash/185914/6 "2019-06-17T18:41:40Z")

</div>

I would suggest running with '--log.level debug --config.debug --config.test\_and\_exit' to make sure you really do just have the one grok filter that you think you have, and you are not picking up another version from a some.conf.bak file in the path.config directory.

---

<div class="post-metadata">

**Author:** ![Andre\_Letterer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andre_letterer/32/42248_2.png) [@Andre\_Letterer](https://discuss.elastic.co/u/Andre_Letterer)\
**Post date:** [June 17, 2019, 7:10pm UTC](https://discuss.elastic.co/t/grok-stopping-output-to-elasticsearch-from-logstash/185914/7 "2019-06-17T19:10:27Z")

</div>

Yes, they go to this file /var/log/failed\_syslog\_events.

I have seen this \S+ but this is what I wanted to write about after knowing what it.  
With the date filter you transport these dates into your timestampe and at the moment you are assuming, that this timestamp is UTC time. But without the timezone information, this is - at least what I assume - just a wrong information. Would be good, if you have a look into file /var/log/failed\_syslog\_events, and look to the timestamps, if they really match your time, or if this time zone information is needed. Apart from that, yes, this line you posted is rendering.  
Because these syslogs are not normated like a normal syslog format should be.  
There are as well forum entries regarding Checkpoint Firewalls. Could you please check, what format you have configured in your Checkpoint firewall?

> **[how to forwad firewall log to 3rd party syslog server](https://community.checkpoint.com/t5/Logging-and-Reporting/how-to-forwad-firewall-log-to-3rd-party-syslog-server/td-p/33726)**
>
> Hi. I'd like to forward firewall log to 3rd party syslog server. but only get as follows. Mar  5 10:15:12 192.168.90.8 CP-GW Mar  5 10:15:12 192.168.90.8 CP-GW Mar  5 10:15:12 192.168.90.8 CP-GW Mar  5 10:15:12 192.168.90.8...

  
[https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit\_doGoviewsolutiondetails=&solutionid=sk122323](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk122323)  
Do you maybe use this tool CPLogToSyslog?  
[https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit\_doGoviewsolutiondetails=&solutionid=sk115392](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk115392)  

> **[CPLogToSyslog Utility Now GA](https://community.checkpoint.com/t5/Logging-and-Reporting/CPLogToSyslog-Utility-Now-GA/td-p/3633)**
>
> Check Point has recently made available publicly a tool that allows you to export Check Point logs from the management to a syslog server. Refer to the following SK: How to export Check Point logs to a Syslog server using CPLogToSyslog 

  
[https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit\_doGoviewsolutiondetails=&solutionid=sk87560&partition=Advanced&product=Security](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk87560&partition=Advanced&product=Security)  
[https://help.deepsecurity.trendmicro.com/Events-Alerts/syslog-parsing.html](https://help.deepsecurity.trendmicro.com/Events-Alerts/syslog-parsing.html)

Apart from the fact, that you can do the config.test\_and\_exit and if this is delivering OK, you could still disable the inputs with beat and output with elasticsearch and replace them by stdin {} and stdout{}.  
Then start logstash by hand with -e parameter. This enables you to just pasting your logline to the logstash wating for input and pressing enter when logstash started?  
What is the output you get back?  
Otherwise, it still would make sense to use a configuration with a bit more debugging information if needed I could send one.

And like Badger told about already, be secure, that depending on your version, there are no additional configuration files. If you are not sure, please post a `ls -lR /etc/logstash`.

---

<div class="post-metadata">

**Author:** ![legacyboy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legacyboy/32/48165_2.png) [@legacyboy](https://discuss.elastic.co/u/legacyboy)\
**Post date:** [June 17, 2019, 7:59pm UTC](https://discuss.elastic.co/t/grok-stopping-output-to-elasticsearch-from-logstash/185914/8 "2019-06-17T19:59:41Z")

</div>

I just wrote my on definition for the date section and its fine now.

Thanks for helping.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 15, 2019, 7:59pm UTC](https://discuss.elastic.co/t/grok-stopping-output-to-elasticsearch-from-logstash/185914/9 "2019-07-15T19:59:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
