# Logstash filter for firewall packet drops

**URL:** <https://discuss.elastic.co/t/logstash-filter-for-firewall-packet-drops/258042>\
**Category:** Logstash\
**Created:** [December 8, 2020, 7:35pm UTC](https://discuss.elastic.co/t/logstash-filter-for-firewall-packet-drops/258042 "2020-12-08T19:35:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![hassan.rana](https://avatars.discourse-cdn.com/v4/letter/h/b9e5f3/32.png) [@hassan.rana](https://discuss.elastic.co/u/hassan.rana)\
**Post date:** [December 8, 2020, 7:35pm UTC](https://discuss.elastic.co/t/logstash-filter-for-firewall-packet-drops/258042/1 "2020-12-08T19:35:26Z")

</div>

I am trying to parse logs from an aggregate syslog server to logstash. I have been successful in shipping the logs from the syslog server to logstash. I can see multiple fields from the log that are being setup like (host.id, host.os, message ..etc..) but I want to convert the message into fields.  
The syntax of firewall logs is: " 2020-12-08T13:34:33-08:00 fw2.abc.xyz kernel: [9394231.861125] [toLocal-default-D]IN=eth0 OUT= MAC=00:00:00:00:00:21:10:16:20:09:17:41:08:00 SRC=192.168.0.0 DST=192.168.0.0 LEN=40 TOS=0x08 PREC=0x20 TTL=241 ID=236 PROTO=TCP SPT=40006 DPT=7370 WINDOW=1024 RES=0x00 SYN URGP=0 "  
The screen shot is of my logstash input, filter and output.

 ![Screen Shot 2020-12-08 at 2.32.43 PM](https://us1.discourse-cdn.com/elastic/original/3X/e/d/edceb5e4aaa6bb258a3608a9023fc1f8d5a0f5c6.jpeg)  
Can anyone help me create fields of all? Or just the time, firewall name , source IP and Destination IP. Thank you.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 8, 2020, 7:54pm UTC](https://discuss.elastic.co/t/logstash-filter-for-firewall-packet-drops/258042/2 "2020-12-08T19:54:03Z")

</div>

Your dissect filter does not match your log file format. Try

```
    dissect { mapping => { "message" => "%{[@metadata][timestamp]} %{host} %{loglevel}: [%{someNumbers}] [%{someString}]%{[@metadata][restOfLine]}" } }
    date { match => ["[@metadata][timestamp]", "YYYY-MM-dd'T'HH:mm:ssZ" ] }
    kv { source => "[@metadata][restOfLine]" }
```

---

<div class="post-metadata">

**Author:** ![hassan.rana](https://avatars.discourse-cdn.com/v4/letter/h/b9e5f3/32.png) [@hassan.rana](https://discuss.elastic.co/u/hassan.rana)\
**Post date:** [December 8, 2020, 8:48pm UTC](https://discuss.elastic.co/t/logstash-filter-for-firewall-packet-drops/258042/3 "2020-12-08T20:48:03Z")

</div>

Thank you for getting back.

 ![Screen Shot 2020-12-08 at 3.43.02 PM](https://us1.discourse-cdn.com/elastic/original/3X/8/2/829a065755845b5b2a2cb02c00a17f016c0aaa28.jpeg) I have changed the filter to match the one you suggested and still can't see the fields on kibana. ![Screen Shot 2020-12-08 at 3.47.39 PM](https://us1.discourse-cdn.com/elastic/original/3X/6/f/6f57cf3f989f5a38082d212ba0a50d9dba94fff7.png) Can you recommend anything else? Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 5, 2021, 8:48pm UTC](https://discuss.elastic.co/t/logstash-filter-for-firewall-packet-drops/258042/4 "2021-01-05T20:48:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
