# How to parse log in “message” fieled cisco-ise

**URL:** <https://discuss.elastic.co/t/how-to-parse-log-in-message-fieled-cisco-ise/337492>\
**Category:** Logstash\
**Created:** [July 3, 2023, 7:29pm UTC](https://discuss.elastic.co/t/how-to-parse-log-in-message-fieled-cisco-ise/337492 "2023-07-03T19:29:16Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mbrezzy](https://avatars.discourse-cdn.com/v4/letter/m/439d5e/32.png) [@Mbrezzy](https://discuss.elastic.co/u/Mbrezzy)\
**Post date:** [July 3, 2023, 7:29pm UTC](https://discuss.elastic.co/t/how-to-parse-log-in-message-fieled-cisco-ise/337492/1 "2023-07-03T19:29:16Z")

</div>

How to parsing this log logstash

Hey everyone i am facing a problem with logstash. I want to parse log that are coming from cisco-ise but all information i want is inside message fields :

 ![IMG_2175](https://us1.discourse-cdn.com/elastic/original/3X/f/9/f9911ceffc1bf05a090f5c311eab0d7cfbdf882d.jpeg)

I want parsing like  
NetworkDeviceName  
User  
Device IP Address  
Etc …

Can someone help me

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 3, 2023, 7:55pm UTC](https://discuss.elastic.co/t/how-to-parse-log-in-message-fieled-cisco-ise/337492/2 "2023-07-03T19:55:54Z")

</div>

Use a [kv](https://www.elastic.co/guide/en/logstash/current/plugins-filters-kv.html) filter.

---

<div class="post-metadata">

**Author:** ![Mbrezzy](https://avatars.discourse-cdn.com/v4/letter/m/439d5e/32.png) [@Mbrezzy](https://discuss.elastic.co/u/Mbrezzy)\
**Post date:** [July 3, 2023, 8:26pm UTC](https://discuss.elastic.co/t/how-to-parse-log-in-message-fieled-cisco-ise/337492/3 "2023-07-03T20:26:18Z")

</div>

Can you guide me how to use it because itry this  
filter {  
kv {  
source =\> "message"  
field\_split =\> "\n"  
value\_split =\> "="  
}  
}  
But didnt work for me

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 3, 2023, 8:38pm UTC](https://discuss.elastic.co/t/how-to-parse-log-in-message-fieled-cisco-ise/337492/4 "2023-07-03T20:38:25Z")

</div>

You will need a kv like this:

```auto
        kv {
            source => "[message]"
            field_split => ", "
            value_split => "="
            target => "kv"
            whitespace => "strict"
        }

```

My recomendation is that you first isolate the KV part of the message using `grok` or `dissect`, in the example you shared the KV part of the message starts in `ConfigVersionId`, unfortunately I can not try to parse it because you didn't share the message as plain text.

Anothe thing is, you need to configure your Cisco ISE to use message lenght of `8192` if it isn't already.

I recommend that you check how Elastic parse these messages in the [Elastic Agent integration](https://github.com/elastic/integrations/tree/main/packages/cisco_ise/data_stream/log/elasticsearch/ingest_pipeline) and try to replicate the filters in Logstash, most of them are pretty simple to replicate.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 3, 2023, 8:38pm UTC](https://discuss.elastic.co/t/how-to-parse-log-in-message-fieled-cisco-ise/337492/5 "2023-07-03T20:38:34Z")

</div>

> [@Mbrezzy](#):
>
> But didnt work for me

That is not a useful response. You need to tell us what you do not like about the results.

You could try `kv { field_split_pattern => ", " }`.

---

<div class="post-metadata">

**Author:** ![davidkov](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/davidkov/32/124961_2.png) [@davidkov](https://discuss.elastic.co/u/davidkov)\
**Post date:** [July 3, 2023, 10:05pm UTC](https://discuss.elastic.co/t/how-to-parse-log-in-message-fieled-cisco-ise/337492/6 "2023-07-03T22:05:57Z")

</div>

as @leandrojmp pointed out first isolate the KV part.

Here one of my configs for inspiration

```auto
input {
  pipeline {
    address => "pl-ise"
  }
}

# example data
# CISE_Passed_Authentications 0042561386 2 1 NetworkDeviceGroups=Location#All Locations#T-22#LSU1
# CISE_Passed_Authentications 0042561387 2 0 2023-05-08 22:44:59.153 +02:00 0633546920 5203 NOTICE Device-Administration: Session Authorization succeeded
# CISE_Passed_Authentications 0042561387 2 1 SelectedAuthenticationIdentityStores=Internal Users
# CISE_Passed_Authentications 0042561388 3 0 2023-05-08 22:44:59.213 +02:00 0633546942 5201 NOTICE Passed-Authentication: Authentication succeeded
# CISE_Passed_Authentications 0042561388 3 1 Step=24210
# CISE_Passed_Authentications 0042561388 3 2 IPSEC=IPSEC#Is IPSEC Device#No
# CISE_Passed_Authentications 0042561389 3 0 2023-05-08 22:44:59.274 +02:00 0633546954 5201 NOTICE Passed-Authentication: Authentication succeeded

filter {

  grok {
    match => { "message" => "%{NOTSPACE:CategoryName} %{NUMBER:MgsID} %{NUMBER:SeqTotal:int} %{INT:SegNumber:int} %{GREEDYDATA:kv_data}" }
  }

  kv {
    source => "kv_data"
    trim_value => "<>\[\],"
    remove_field => "kv_data"
  }

  mutate {
      add_field => { "[@metadata][index]" => "ise-%{+YYYY.MM}" } 
  }

}

output {
  pipeline {
      send_to => "pl-splunk-out"
  }
  pipeline {
      send_to => "pl-elastic-out"
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 31, 2023, 10:06pm UTC](https://discuss.elastic.co/t/how-to-parse-log-in-message-fieled-cisco-ise/337492/7 "2023-07-31T22:06:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
