# Iptables module unable to parse some logs from UDM-Pro device

**URL:** <https://discuss.elastic.co/t/iptables-module-unable-to-parse-some-logs-from-udm-pro-device/272335>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 6, 2021, 7:49pm UTC](https://discuss.elastic.co/t/iptables-module-unable-to-parse-some-logs-from-udm-pro-device/272335 "2021-05-06T19:49:23Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![JAndritsch](https://avatars.discourse-cdn.com/v4/letter/j/ec9cab/32.png) [@JAndritsch](https://discuss.elastic.co/u/JAndritsch)\
**Post date:** [May 6, 2021, 7:49pm UTC](https://discuss.elastic.co/t/iptables-module-unable-to-parse-some-logs-from-udm-pro-device/272335/1 "2021-05-06T19:49:23Z")

</div>

I'm using the Iptables module of Filebeat (`master` branch on Github, commit `ddcf8f1aa`) to receive and parse logs from a Unifi Dream Machine Pro over UDP. My module configuration looks like this:

```
- module: iptables
  log:
    enabled: true

```

The data is sent from the beat to a Logstash pipeline. That pipeline does no processing/parsing of the message itself. It just sends the incoming data into the appropriate Elasticsearch index. All of the message processing happens using the ingest pipeline provided by the Iptables module.

Most of the sample log data I've tested parses fine, however there are a handful of logs (about 70 out of 3800) that fail to parse properly by the module.

Here's a few logs that fail to parse:

```
May 5 20:46:45 My-Office-Gateway user.info kernel: TTL=126 ID=15317 DF PROTO=TCP SPT=59344 DPT=443 WINDOW=8212 RES=0x00 ACK PSH URGP=0
May 5 20:46:46 My-Office-Gateway user.info kernel: TTL=126 ID=51392 DF PROTO=TCP SPT=51653 DPT=7914 WINDOW=1024 RES=0x00 ACK PSH URGP=0
May 5 20:46:46 My-Office-Gateway user.info kernel: L=126 ID=8698 DF PROTO=TCP SPT=88 DPT=51179 WINDOW=2053 RES=0x00 ACK URGP=0
May 5 20:47:09 My-Office-Gateway user.info kernel: 0 TTL=126 ID=15461 DF PROTO=TCP SPT=59289 DPT=443 WINDOW=8208 RES=0x00 ACK PSH URGP=0
May 5 20:46:56 My-Office-Gateway user.info kernel: L=126 ID=8702 DF PROTO=TCP SPT=88 DPT=51182 WINDOW=2053 RES=0x00 ACK URGP=0
May 5 20:45:44 My-Office-Gateway user.info kernel: TL=126 ID=4622 DF PROTO=TCP SPT=389 DPT=49209 WINDOW=8192 RES=0x00 ECE ACK SYN URGP=0
```

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [May 7, 2021, 9:29am UTC](https://discuss.elastic.co/t/iptables-module-unable-to-parse-some-logs-from-udm-pro-device/272335/2 "2021-05-07T09:29:56Z")

</div>

Ya it doesn't match the grok pattern. If u create a issue on GitHub, I'll update the module to add this grok pattern to the list.

---

<div class="post-metadata">

**Author:** ![JAndritsch](https://avatars.discourse-cdn.com/v4/letter/j/ec9cab/32.png) [@JAndritsch](https://discuss.elastic.co/u/JAndritsch)\
**Post date:** [May 7, 2021, 2:11pm UTC](https://discuss.elastic.co/t/iptables-module-unable-to-parse-some-logs-from-udm-pro-device/272335/3 "2021-05-07T14:11:50Z")

</div>

Ok, I just opened an issue: [Iptables module unable to parse some logs from UDM-Pro device · Issue #25615 · elastic/beats · GitHub](https://github.com/elastic/beats/issues/25615)

Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 4, 2021, 4:12pm UTC](https://discuss.elastic.co/t/iptables-module-unable-to-parse-some-logs-from-udm-pro-device/272335/4 "2021-06-04T16:12:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
