# Loading snort alerts into logstash (GROK PATTERN)

**URL:** <https://discuss.elastic.co/t/loading-snort-alerts-into-logstash-grok-pattern/203889>\
**Category:** Logstash\
**Created:** [October 16, 2019, 4:58pm UTC](https://discuss.elastic.co/t/loading-snort-alerts-into-logstash-grok-pattern/203889 "2019-10-16T16:58:36Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![cottoncandyy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cottoncandyy/32/52975_2.png) [@cottoncandyy](https://discuss.elastic.co/u/cottoncandyy)\
**Post date:** [October 16, 2019, 4:58pm UTC](https://discuss.elastic.co/t/loading-snort-alerts-into-logstash-grok-pattern/203889/1 "2019-10-16T16:58:36Z")

</div>

hi I am new to the elk stack and im trying to load snort event log into logstash for analysis but i cant seem to figure out the grok pattern. This is a sample data of how the snort alert log looks like, can someone help me out with the script n grok pattern to load this data into logstash

```
[**] [129:12:1] Consecutive TCP small segments exceeding threshold [**]
[Classification: Potentially Bad Traffic] [Priority: 2] 
07/11-14:18:47.086495 192.168.62.5:443 -> 192.168.62.3:59936
TCP TTL:64 TOS:0x0 ID:6180 IpLen:20 DgmLen:168 DF
***AP*** Seq: 0x4573C100 Ack: 0x3A0B3D67 Win: 0x5AC TcpLen: 20
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 13, 2019, 4:58pm UTC](https://discuss.elastic.co/t/loading-snort-alerts-into-logstash-grok-pattern/203889/2 "2019-11-13T16:58:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
