Hi,
I'm on my way to parse Cisco PIX 515 Log. In the log file, there is 3 kind of line I would like to parse. My grok filters are working individually. I tested them with the grokdebugger. But as soon as I put them together in my config file, nothing is sent to elasticsearch. I'm using logstash 1.4.2, on ubuntu 14.04, with java version "1.7.0_79.
Below is my config file :
CISCO_NAT_OUTGOING_TCP and CISCO_NAT_INCOMING_TCP are defined in the pattern file.
input {
file {
path => "/var/log/pix-*.log"
type => "Pix"
}
}
filter {
if [type] == "Pix"{
grok {
match => ["message", "%{CISCO_NAT_OUTGOING_TCP}"]
add_tag => ["main-firewall", "Pix"]
patterns_dir => ["/opt/logstash/patterns/pix"]
}
}
if [type] == "Pix"{
grok {
match => ["message", "%{CISCO_NAT_INCOMING_DETAIL}"]
add_tag => ["main-firewall", "Pix-input"]
patterns_dir => ["/opt/logstash/patterns/pix"]
}
if [type] == "Pix"{
grok {
match => ["message", "%{CISCO_NAT_OUTGOING_DETAIL}"]
add_tag => ["main-firewall", "Pix-output"]
patterns_dir => ["/opt/logstash/patterns/pix"]
}
}
if "_grokparsefailure" in [tags] {
drop { }
}
}
output {
stdout { }
elasticsearch {
cluster => "elasticsearch-cluster-name"
}
}
Any idea ?