# Logstash parsing ECS

**URL:** <https://discuss.elastic.co/t/logstash-parsing-ecs/247108>\
**Category:** Logstash\
**Tags:** ecs-elastic-common-schema\
**Created:** [September 1, 2020, 2:40pm UTC](https://discuss.elastic.co/t/logstash-parsing-ecs/247108 "2020-09-01T14:40:49Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Abdelhalim](https://avatars.discourse-cdn.com/v4/letter/a/838e76/32.png) [@Abdelhalim](https://discuss.elastic.co/u/Abdelhalim)\
**Post date:** [September 1, 2020, 2:40pm UTC](https://discuss.elastic.co/t/logstash-parsing-ecs/247108/1 "2020-09-01T14:40:49Z")

</div>

Hello everybody,

I am using logstash to parse my firewall logs, and some logs contain these information :

```auto
src=x.x.x.x srcport=YYY dst=x.x.x.x modsrc=x.x.x.x origdst=x.x.x.x dst= x.x.x.x srcport=YY modsrcport= YY origdstport= YY

```

Where:  
**src =** IP address of the source host  
**dst =** IP address of the destination host  
**modsrc =** Translated IP address of the source host.  
**origdst =** Original IP address of the destination host (before translation or the application of a virtual connection).  
**srcport =** source TCP/UDP port number  
**modesrcport =** Translated TCP/UDP source port number  
**dstport =** Destination TCP/UDP port number  
**origdstport =** Original port number of the destination TCP/UDP port (before translation or the application of a virtual connection).

I wanna know how can I name these fields to respect ECS !

Thanks for your help

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [September 1, 2020, 3:11pm UTC](https://discuss.elastic.co/t/logstash-parsing-ecs/247108/2 "2020-09-01T15:11:15Z")

</div>

You can refer to ECS fields in this [link](https://www.elastic.co/guide/en/ecs/current/ecs-field-reference.html) for version 1.6.0  
Then you can use mutate filter to rename fields and map them into ECS fields

Example for [source](https://www.elastic.co/guide/en/ecs/current/ecs-source.html) and [destination](https://www.elastic.co/guide/en/ecs/current/ecs-destination.html) informations

```
filter {
    mutate {
        rename => ["src", "[source][ip]" ]
        rename => ["dst", "[destination][ip]" ]
        ....
    }
}

```

More détails are [here](https://github.com/elastic/ecs/blob/master/generated/beats/fields.ecs.yml)

---

<div class="post-metadata">

**Author:** ![Abdelhalim](https://avatars.discourse-cdn.com/v4/letter/a/838e76/32.png) [@Abdelhalim](https://discuss.elastic.co/u/Abdelhalim)\
**Post date:** [September 1, 2020, 3:17pm UTC](https://discuss.elastic.co/t/logstash-parsing-ecs/247108/3 "2020-09-01T15:17:37Z")

</div>

Thanks for yours answer @ylasri,

The problem is what IP source should I name source.ip as there is 2 source IP (before and after address translation ), and then second one, what should I name it by respecting the ECS !

---

<div class="post-metadata">

**Author:** ![ylasri](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ylasri/32/86120_2.png) [@ylasri](https://discuss.elastic.co/u/ylasri)\
**Post date:** [September 1, 2020, 3:21pm UTC](https://discuss.elastic.co/t/logstash-parsing-ecs/247108/4 "2020-09-01T15:21:23Z")

</div>

All informations required for source IPs are [here](https://www.elastic.co/guide/en/ecs/current/ecs-source.html) for example

source.ip =\> IP address of the source (IPv4 or IPv6).  
source.nat.ip =\> Translated ip of source based NAT sessions (e.g. internal client to internet)

```
filter {
    mutate {
        rename => ["src", "[source][ip]" ]
        rename => ["modsrc", "[source][nat][ip]" ]
        ....
    }
}
```

---

<div class="post-metadata">

**Author:** ![Abdelhalim](https://avatars.discourse-cdn.com/v4/letter/a/838e76/32.png) [@Abdelhalim](https://discuss.elastic.co/u/Abdelhalim)\
**Post date:** [September 1, 2020, 3:27pm UTC](https://discuss.elastic.co/t/logstash-parsing-ecs/247108/5 "2020-09-01T15:27:33Z")

</div>

Thanks a lot for your help ^ ^

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 29, 2020, 3:27pm UTC](https://discuss.elastic.co/t/logstash-parsing-ecs/247108/6 "2020-09-29T15:27:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
