Dear All,
I installed ELK to use it to log F5 big ip , it is receiving logs successfully and I can search within logs in kibana,search is working very fast compared to any syslog I worked with it.
however, I cannot parse the logs to get any statics from them using grok.I need statistics like which ip addresses are visiting our website, statistics about the http response codes.
any help is highly appreciated.
kindly find my logstash.conf
input {
tcp {
type => "f5-access"
port => 5045
}
}
output {
elasticsearch {
hosts => ["localhost:9200"]
}
}
kindly find sample of logs
<134>Mar 20 13:07:30 F5.aast.edu ASM:unit_hostname="F5.aast.edu",management_ip_address="10.0.0.1",http_class_name="/Common/www.aast.edu",web_application_name="/Common/www.aast.edu",policy_name="/Common/www.aast.edu",policy_apply_date="2017-02-20 07:52:02",violations="",support_id="1017117902917082439",request_status="passed",response_code="200",ip_client="185.144.40.100",route_domain="0",method="GET",protocol="HTTP",query_string="",x_forwarded_for_header_value="185.144.40.100",sig_ids="",sig_names="",date_time="2017-03-20 13:07:29",severity="Informational",attack_type="",geo_location="NL",ip_address_intelligence="N/A",username="N/A",session_id="8af3fbb94d9848bd",src_port="56374",dest_port="80",dest_ip="172.20.38.11",sub_violations="",virus_name="N/A",violation_rating="0",websocket_direction="N/A",websocket_message_type="N/A",device_id="N/A",uri="/en/images/home/5.jpg",request="GET /en/images/home/5.jpg HTTP/1.1\r\nHost: www.aast.edu\r\nUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:47.0) Gecko/20100101 Firefox/47.0\r\nAccept: /\r\nAccept-Language: en-US\r\nAccept-Encoding: gzip, deflate\r\nReferer: http://www.aast.edu/en/\r\nCookie: f5avrbbbbbbbbbbbbbbbb=DBFEAJOPBJELFDAKEBJCCBFOELKCMNMEHKMOJEPJPEAFGAJFMOFBHLGLHIANLLEMHOIDAFJBHHDMOFBAHHBANMDBILPBEEECHLGAPGJOKJDAKMCKOOJGJABBIBPEMDPA; f5_cspm=1234; __utma=59762365.1779799469.1409206989.1433332267.1444386902.3; _ga=GA1.2.1779799469.1409206989; f5avrbbbbbbbbbbbbbbbb=MOPPNHHBFNHONHICDCABIHGFPJBCPMHJKLPNBCEEBNLNJMLMLNBKKEELMNEKNKFDHDIDANOFEHMPGDGPINLABDKAILPIHBKBGIEHKJLMGGJPCENOIIPCMDNIBCDONJAI; TS01ff0351=01ab6d262aeba8dba7ba167b17936a7e2c634b34d4dfd3f1b1da96c4ba2fbd6814f09180ecfee14cc7836f48e96db51a1f383e648e697c004c712ca5d2114010b0128da8c5561b238333f31b9938133941c73fd109; _gat=1\r\nConnection: keep-alive\r\nX-Forwarded-For: 185.144.40.100\r\n\r\n"