# How do I grok this Cisco log?

**URL:** <https://discuss.elastic.co/t/how-do-i-grok-this-cisco-log/149049>\
**Category:** Logstash\
**Created:** [September 19, 2018, 3:13am UTC](https://discuss.elastic.co/t/how-do-i-grok-this-cisco-log/149049 "2018-09-19T03:13:53Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![ramindia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramindia/32/32459_2.png) [@ramindia](https://discuss.elastic.co/u/ramindia)\
**Post date:** [September 19, 2018, 3:13am UTC](https://discuss.elastic.co/t/how-do-i-grok-this-cisco-log/149049/1 "2018-09-19T03:13:53Z")

</div>

Hi

Thank you for the earlier help, iam progressing in good way.

Iam going here is more granular logging and get more information for statistic purpose, at the same time i would like retain some message as it is for user to view.

Now i have 2 queries

Log messages :

**Sep 19 03:53:51 DHCP-CA-DNS %LINEPROTO-5-UPDOWN: Line protocol on Interface Ethernet0/0, changed state to up**

Grok Pattern :

**%{SYSLOGTIMESTAMP:syslog\_timestamp} %{HOSTNAME:device\_src} %{GREEDYDATA:syslog\_message}**

Output :

**{**  
\*\* "syslog\_timestamp": "Sep 19 03:53:51",\*\*  
\*\* "syslog\_message": "%LINEPROTO-5-UPDOWN: Line protocol on Interface Ethernet0/0, changed state to up",\*\*  
\*\* "device\_src": "DHCP-CA-DNS"\*\*  
**}**

all good so far.

When i go granular i am breaking my syslog\_message. breaks in to different data as expected, that is good.

Log :

**Sep 19 03:53:51 DHCP-CA-DNS %LINEPROTO-5-UPDOWN: Line protocol on Interface Ethernet0/0, changed state to up**

Grok :  
**%{SYSLOGTIMESTAMP:syslog\_timestamp} %{HOSTNAME:device\_src} %%{CISCO\_REASON:facility}-%{INT:severity\_level}-%{CISCO\_REASON:facility\_mnemonic}: %{GREEDYDATA:syslog\_message}**

Output :  
**{**  
\*\* "syslog\_timestamp": "Sep 19 03:53:51",\*\*  
\*\* "severity\_level": "5",\*\*  
\*\* "syslog\_message": "Line protocol on Interface Ethernet0/0, changed state to up",\*\*  
\*\* "facility": "LINEPROTO",\*\*  
\*\* "facility\_mnemonic": "UPDOWN",\*\*  
\*\* "device\_src": "DHCP-CA-DNS"\*\*  
**}**

but iam looking as below :

{  
"syslog\_timestamp": "Sep 19 03:53:51",  
"severity\_level": "5",  
**"syslog\_message1": "Line protocol on Interface Ethernet0/0, changed state to up",**  
"facility": "LINEPROTO",  
"facility\_mnemonic": "UPDOWN",  
"device\_src": "DHCP-CA-DNS"  
**"syslog\_message" : %LINEPROTO-5-UPDOWN: Line protocol on Interface Ethernet0/0, changed state to up"**  
}

How can i achieve this ?

appreciate your help.

---

<div class="post-metadata">

**Author:** ![ramindia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramindia/32/32459_2.png) [@ramindia](https://discuss.elastic.co/u/ramindia)\
**Post date:** [September 21, 2018, 9:21pm UTC](https://discuss.elastic.co/t/how-do-i-grok-this-cisco-log/149049/2 "2018-09-21T21:21:25Z")

</div>

any help here...

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [September 25, 2018, 1:37pm UTC](https://discuss.elastic.co/t/how-do-i-grok-this-cisco-log/149049/3 "2018-09-25T13:37:31Z")

</div>

Do you have 2 grok filters? I ask because I don't know where/why you get `syslog_message` and a `syslog_message1` fields.

Use one grok filter and try anchoring the grok pattern to the start-of-string.

```auto
^%{SYSLOGTIMESTAMP:syslog_timestamp} %{HOSTNAME:device_src} %%{CISCO_REASON:facility}-%{INT:severity_level}-%{CISCO_REASON:facility_mnemonic}: %{GREEDYDATA:syslog_message}

```

---

<div class="post-metadata">

**Author:** ![ramindia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramindia/32/32459_2.png) [@ramindia](https://discuss.elastic.co/u/ramindia)\
**Post date:** [September 25, 2018, 9:24pm UTC](https://discuss.elastic.co/t/how-do-i-grok-this-cisco-log/149049/4 "2018-09-25T21:24:05Z")

</div>

Thank for the reply, no i have only 1 grok filter, the output iam looking what i want to achieve,

can you give example how i can "Use one grok filter and try anchoring the grok pattern to the start-of-string."

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [September 26, 2018, 8:35am UTC](https://discuss.elastic.co/t/how-do-i-grok-this-cisco-log/149049/5 "2018-09-26T08:35:03Z")

</div>

In return for the example please edit the title of this discussion to make it easier for other to find the example below. "How do I grok this Cisco `<device name here>` log?"

Config example:

```auto
input {
  generator {
    message => 'Sep 19 03:53:51 DHCP-CA-DNS %LINEPROTO-5-UPDOWN: Line protocol on Interface Ethernet0/0, changed state to up'
    count => 1
  }
}

filter {
  grok {
    match => {
      "message" => [
        '^%{SYSLOGTIMESTAMP:syslog_timestamp} %{HOSTNAME:device_src} %%{CISCO_REASON:facility}-%{INT:severity_level}-%{CISCO_REASON:facility_mnemonic}: %{GREEDYDATA:syslog_message}'
      ]
    }
  }
}

output {
  stdout { codec => rubydebug }
}

```

Result:

```auto
{
             "facility" => "LINEPROTO",
                 "host" => "Elastics-MacBook-Pro.local",
     "syslog_timestamp" => "Sep 19 03:53:51",
             "@version" => "1",
           "@timestamp" => 2018-09-26T08:31:21.756Z,
           "device_src" => "DHCP-CA-DNS",
             "sequence" => 0,
       "syslog_message" => "Line protocol on Interface Ethernet0/0, changed state to up",
              "message" => "Sep 19 03:53:51 DHCP-CA-DNS %LINEPROTO-5-UPDOWN: Line protocol on Interface Ethernet0/0, changed state to up",
       "severity_level" => "5",
    "facility_mnemonic" => "UPDOWN"
}

```

---

<div class="post-metadata">

**Author:** ![ramindia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramindia/32/32459_2.png) [@ramindia](https://discuss.elastic.co/u/ramindia)\
**Post date:** [September 26, 2018, 9:10pm UTC](https://discuss.elastic.co/t/how-do-i-grok-this-cisco-log/149049/6 "2018-09-26T21:10:28Z")

</div>

Thank you let me try and get back to you.

may be i gave some information wrong, in the grok, i have 3 or 4 match patterns, is this still works ?

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [September 27, 2018, 10:25am UTC](https://discuss.elastic.co/t/how-do-i-grok-this-cisco-log/149049/7 "2018-09-27T10:25:10Z")

</div>

Yes, multiple patterns are OK, have a look at the `break_on_match` setting in the docs.

---

<div class="post-metadata">

**Author:** ![ramindia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramindia/32/32459_2.png) [@ramindia](https://discuss.elastic.co/u/ramindia)\
**Post date:** [September 27, 2018, 9:50pm UTC](https://discuss.elastic.co/t/how-do-i-grok-this-cisco-log/149049/8 "2018-09-27T21:50:51Z")

</div>

`break_on_match` setting - if i understand correctly, once it matches then it will not proceed to next match and send the output to ES.

correct me if iam wrong please.

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [September 28, 2018, 1:09pm UTC](https://discuss.elastic.co/t/how-do-i-grok-this-cisco-log/149049/9 "2018-09-28T13:09:44Z")

</div>

Correct

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 26, 2018, 1:09pm UTC](https://discuss.elastic.co/t/how-do-i-grok-this-cisco-log/149049/10 "2018-10-26T13:09:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
