# How to parse Syslog messages

**URL:** <https://discuss.elastic.co/t/how-to-parse-syslog-messages/65428>\
**Category:** Logstash\
**Created:** [November 9, 2016, 1:49am UTC](https://discuss.elastic.co/t/how-to-parse-syslog-messages/65428 "2016-11-09T01:49:45Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![blueheart](https://avatars.discourse-cdn.com/v4/letter/b/e19b73/32.png) [@blueheart](https://discuss.elastic.co/u/blueheart)\
**Post date:** [November 9, 2016, 1:49am UTC](https://discuss.elastic.co/t/how-to-parse-syslog-messages/65428/1 "2016-11-09T01:49:46Z")

</div>

Need support in parsing Syslog messages

I want to parse the below syslog message.

\<13\> 172.0.0.2 Nov 9 09:53:53 172.0.0.2 1 2016-11-09T09:57:14.018719Z [interface] [172.0.0.2]  
timestamp=2016-11-09 09:57:14 machine=DDoS pdomain=home in\_pps\_tot=29245

I know we need to use KV filter for parsing. I put lots of effort on making it work but I was unsuccessful. \_grokparsefailure!!  
Looking forward for the help from Elastic community.

The code I am currently working on is below:

input {  
udp {  
port =\> 8000  
type =\> syslog  
}  
}

filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "\<%{POSINT:syslog\_pri"\> %{SYSLOGHOST:syslog\_hostname} %{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:facility} %{SYSLOGTIMESTAMP:syslog\_timestamp2} \[%{DATA:event\_name}\] \[%{SYSLOGHOST:syslog\_hostname}\] %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"] } }}}

syslog\_pri { }  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss", "ISO8601"]  
}  
date {  
match =\> ["syslog\_timestamp2", "yyyy-MM-dd'T'HH:mm:ss.SSSSSSZ", "ISO8601"]  
}

kv{  
source =\> "syslog\_message"  
remove\_field =\> ["syslog\_message"]  
}

output {  
elasticsearch { host =\> localhost  
index =\> "dashboard"  
}  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 9, 2016, 4:52am UTC](https://discuss.elastic.co/t/how-to-parse-syslog-messages/65428/2 "2016-11-09T04:52:23Z")

</div>

- There's an extra double quote right after "syslog\_pri".
- Don't use DATA to capture facility, use a more exact pattern like e.g. NUMBER instead.
- Use TIMESTAMP\_ISO8601 to match the second timestamp.

If it still doesn't work, start building the expression from the beginning, i.e. start with `<%{POSINT:syslog_pri>` and verify that that works, then add piece by piece until it stops working.

---

<div class="post-metadata">

**Author:** ![blueheart](https://avatars.discourse-cdn.com/v4/letter/b/e19b73/32.png) [@blueheart](https://discuss.elastic.co/u/blueheart)\
**Post date:** [November 9, 2016, 9:24am UTC](https://discuss.elastic.co/t/how-to-parse-syslog-messages/65428/3 "2016-11-09T09:24:39Z")

</div>

thank you !!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 7, 2016, 9:24am UTC](https://discuss.elastic.co/t/how-to-parse-syslog-messages/65428/4 "2016-12-07T09:24:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
