# I really need help with standard rsyslog parsing

**URL:** <https://discuss.elastic.co/t/i-really-need-help-with-standard-rsyslog-parsing/33622>\
**Category:** Logstash\
**Created:** [November 3, 2015, 11:44am UTC](https://discuss.elastic.co/t/i-really-need-help-with-standard-rsyslog-parsing/33622 "2015-11-03T11:44:14Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![tomas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomas/32/5698_2.png) [@tomas](https://discuss.elastic.co/u/tomas)\
**Post date:** [November 3, 2015, 11:44am UTC](https://discuss.elastic.co/t/i-really-need-help-with-standard-rsyslog-parsing/33622/1 "2015-11-03T11:44:14Z")

</div>

Hi,

env: rsyslog (clients) =\> syslog-ng (server) =\> logstash 1.5 =\> elasticsearch =\> kibana

I'm trying to parse (match) the standard linux rsyslog message format but I always get \_grokparsefailure and are unable to capture the sending hostname instead of the syslog-ng server hostname itself.

## An rsyslog standard msg format seen in kibana:

```
@timestamp	November 3rd 2015, 11:04:02.312
@version	1
_id AVDMza3ZCWCwaLoTIQfe
_index logstash-2015.11.03
_type linux-syslog
host ourCentralSyslog-ngServer
message 2015-11-03T11:04:01+01:00 the.ip.address.of.the.sending.server the-sending-server-hostname sshd[10003]: Connection closed by 10.100.8.44 [preauth]
path /path/to/central/syslog.log
tags our-syslog, _grokparsefailure
type linux-syslog

```

## Filters tried:

```
match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{GREEDYDATA:syslog_message}" }

match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{IPORHOST:ip_address} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }

match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{IPORHOST:ip_address} %{SYSLOGHOST:syslog_hostname} %{GREEDYDATA:syslog_message}" }

```

I have also tried the example here:  
[https://www.elastic.co/guide/en/logstash/current/config-examples.html#\_processing\_syslog\_messages](https://www.elastic.co/guide/en/logstash/current/config-examples.html#_processing_syslog_messages)

I'd be very happy to have some kind soul give me any advice on how to do the matching.

Many thanks in advance  
Tomas

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 3, 2015, 11:51am UTC](https://discuss.elastic.co/t/i-really-need-help-with-standard-rsyslog-parsing/33622/2 "2015-11-03T11:51:28Z")

</div>

The timestamp in your message doesn't match SYSLOGTIMESTAMP. Try TIMESTAMP\_ISO8601 instead.

---

<div class="post-metadata">

**Author:** ![tomas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomas/32/5698_2.png) [@tomas](https://discuss.elastic.co/u/tomas)\
**Post date:** [November 3, 2015, 12:08pm UTC](https://discuss.elastic.co/t/i-really-need-help-with-standard-rsyslog-parsing/33622/3 "2015-11-03T12:08:51Z")

</div>

Thank you very much Magnus, I tested with the below examples on the std message but still no go:

```
match => { "message" => "%{TIMESTAMP_ISO8601:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
match => { "message" => "%{TIMESTAMP_ISO8601:syslog_timestamp} %{IPORHOST:ip_address} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
match => { "message" => "%{TIMESTAMP_ISO8601:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{GREEDYDATA:syslog_message}" }
match => { "message" => "%{TIMESTAMP_ISO8601:syslog_timestamp} %{IPORHOST:ip_address} %{SYSLOGHOST:syslog_hostname} %{GREEDYDATA:syslog_message}" }

```

Do you have any other ideas?

I'm sorry but very new to this, both to ELK itself and syslog formats  
Thanks  
Tomas

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 3, 2015, 12:10pm UTC](https://discuss.elastic.co/t/i-really-need-help-with-standard-rsyslog-parsing/33622/4 "2015-11-03T12:10:49Z")

</div>

Be systematic. Start with `%{TIMESTAMP_ISO8601:syslog_timestamp}.*` to see if at least _that_ matches. If so, add the next part of the expression. And another. When things stop working you've found which part of the expression that's problematic.

---

<div class="post-metadata">

**Author:** ![tomas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomas/32/5698_2.png) [@tomas](https://discuss.elastic.co/u/tomas)\
**Post date:** [November 3, 2015, 12:30pm UTC](https://discuss.elastic.co/t/i-really-need-help-with-standard-rsyslog-parsing/33622/5 "2015-11-03T12:30:23Z")

</div>

Thanks again, but I must have something really wrong somewhere. It does not even match with:

```
match => { "message" => "%{TIMESTAMP_ISO8601:syslog_timestamp}.*" }

```

This is the date/time format we have in the logs from both linux servers and devices:  
2015-11-03T13:28:52+01:00

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 3, 2015, 12:35pm UTC](https://discuss.elastic.co/t/i-really-need-help-with-standard-rsyslog-parsing/33622/6 "2015-11-03T12:35:17Z")

</div>

I can't reproduce:

```
$ cat test.config 
input { stdin { } }
output { stdout { codec => rubydebug } }
filter {
  grok {
    match => {
      "message" => "%{TIMESTAMP_ISO8601:syslog_timestamp}.*"
    }
  }
}
$ echo '2015-11-03T13:28:52+01:00' | /opt/logstash/bin/logstash -f test.config
Logstash startup completed
{
             "message" => "2015-11-03T13:28:52+01:00",
            "@version" => "1",
          "@timestamp" => "2015-11-03T12:33:58.809Z",
                "host" => "lnxolofon",
    "syslog_timestamp" => "2015-11-03T13:28:52+01:00"
}
Logstash shutdown completed
$ /opt/logstash/bin/logstash --version
logstash 1.5.3
```

---

<div class="post-metadata">

**Author:** ![tomas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomas/32/5698_2.png) [@tomas](https://discuss.elastic.co/u/tomas)\
**Post date:** [November 3, 2015, 12:41pm UTC](https://discuss.elastic.co/t/i-really-need-help-with-standard-rsyslog-parsing/33622/7 "2015-11-03T12:41:57Z")

</div>

I'm very sorry I had a little typo. Now it will match so I get the fields "recievd\_at" and "recieved\_from" but I still get the tag:

\_grokparsefailure

Would that be normal anyway, if I don't do a complete match?

This is the input I have right now:

```
input {
  file {
    path => ["/path/to/central/syslog.log"]
    type => "linux-syslog"
    tags => ["our-syslog"]
  }
}

filter {
  if [type] == "linux-syslog" {
    grok {
      
      match => { "message" => "%{TIMESTAMP_ISO8601:syslog_timestamp}.*" }
      add_field => ["received_at", "%{@timestamp}"]
      add_field => ["received_from", "%{host}"]
    }
    syslog_pri { }
    date {
      match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
    }

  }
}

output {
  elasticsearch { host => localhost }
}
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 3, 2015, 12:46pm UTC](https://discuss.elastic.co/t/i-really-need-help-with-standard-rsyslog-parsing/33622/8 "2015-11-03T12:46:09Z")

</div>

I don't see why you should get a `_grokparsefailure` tag in this case. Your configuration should be written so that you don't get that tag under normal circumstances.

Are you sure that's _all_ the configuration you have? How are you invoking Logstash? Any extra files in /etc/logstash/conf.d?

---

<div class="post-metadata">

**Author:** ![tomas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomas/32/5698_2.png) [@tomas](https://discuss.elastic.co/u/tomas)\
**Post date:** [November 3, 2015, 12:49pm UTC](https://discuss.elastic.co/t/i-really-need-help-with-standard-rsyslog-parsing/33622/9 "2015-11-03T12:49:31Z")

</div>

Yes, I have one more configuration in conf.d, for the logstash-forwarder

```
input {
  lumberjack {
    port => 5000
    type => "logs"
    ssl_certificate => "/etc/pki/tls/certs/logstash-forwarder.crt"
    ssl_key => "/etc/pki/tls/private/logstash-forwarder.key"
  }
}

```

That's it?!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 3, 2015, 12:56pm UTC](https://discuss.elastic.co/t/i-really-need-help-with-standard-rsyslog-parsing/33622/10 "2015-11-03T12:56:33Z")

</div>

Well, my minimal example did not result in `_grokparsefailure` (for you either, right?). Start from there and add additional feature, one by one, until you find what's causing this.

---

<div class="post-metadata">

**Author:** ![tomas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomas/32/5698_2.png) [@tomas](https://discuss.elastic.co/u/tomas)\
**Post date:** [November 3, 2015, 1:04pm UTC](https://discuss.elastic.co/t/i-really-need-help-with-standard-rsyslog-parsing/33622/11 "2015-11-03T13:04:15Z")

</div>

Thanks, will do. You have been very helpful 🙂

---

<div class="post-metadata">

**Author:** ![tomas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tomas/32/5698_2.png) [@tomas](https://discuss.elastic.co/u/tomas)\
**Post date:** [November 3, 2015, 1:49pm UTC](https://discuss.elastic.co/t/i-really-need-help-with-standard-rsyslog-parsing/33622/12 "2015-11-03T13:49:09Z")

</div>

Yes, got it now. This is what I ended up with:

```
filter {
  grok {
    match => {
      "message" => "%{TIMESTAMP_ISO8601:origin_timestamp} %{IPORHOST:ip_address} %{SYSLOGHOST:origin_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}"
    }
        add_field => ["received_at", "%{@timestamp}"]
        add_field => ["received_from", "%{host}"]

  }

  syslog_pri { }
    date {
      match => ["origin_timestamp", "ISO8601"]
    }
        mutate {
                replace => ["host", "%{origin_hostname}"]
                replace => ["message", "%{syslog_message}"]
        }

}

```

Thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:24am UTC](https://discuss.elastic.co/t/i-really-need-help-with-standard-rsyslog-parsing/33622/13 "2017-07-06T05:24:17Z")

</div>


