# Logstash syslog help

**URL:** <https://discuss.elastic.co/t/logstash-syslog-help/211186>\
**Category:** Logstash\
**Created:** [December 9, 2019, 8:08pm UTC](https://discuss.elastic.co/t/logstash-syslog-help/211186 "2019-12-09T20:08:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![f1wing](https://avatars.discourse-cdn.com/v4/letter/f/4491bb/32.png) [@f1wing](https://discuss.elastic.co/u/f1wing)\
**Post date:** [December 9, 2019, 8:08pm UTC](https://discuss.elastic.co/t/logstash-syslog-help/211186/1 "2019-12-09T20:08:56Z")

</div>

Hi All,

I am having problem with logstash with grok. I am successfully to use the NetScreen firewall logs %{NETSCREENSESSIONLOG} in grok debugger. But when I run it, I get grokpasefailure. I notice the log is different between rsyslog and the output from logstash.  
Rsyslog:  
Dec 8 21:20:15 gateway RWING-FW: NetScreen device\_id=RWING-FW [Root]system-notification-00257(traffic): start\_time="2019-12-08 21:25:14" duration=2 policy\_id=1 service=dns proto=17 src zone=Trust dst zone=Untrust action=Permit sent=85 rcvd=97 src=10.10.10.86 dst=66.33.205.230 src\_port=61003 dst\_port=53 src-xlated ip=135.23.196.241 port=9387 dst-xlated ip=66.33.205.230 port=53 session\_id=31695 reason=Close - RESP

Logstatsh:  
"message" =\> "\<133\>RWING-FW: NetScreen device\_id=RWING-FW [Root]system-notification-00257(traffic): start\_time="2019-12-09 14:55:27" duration=0 policy\_id=320001 service=proto:88/port:0 proto=88 src zone=Null dst zone=self action=Deny sent=0 rcvd=66 src=10.10.10.251 dst=224.0.0.10 session\_id=0\u0000",  
"type" =\> "syslog"

Where the \<133\> come from?

Thanks in advance

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 9, 2019, 10:53pm UTC](https://discuss.elastic.co/t/logstash-syslog-help/211186/2 "2019-12-09T22:53:15Z")

</div>

> [@f1wing](#):
>
> Where the \<133\> come from?

That is the PRI from an [RFC3164](https://www.ietf.org/rfc/rfc3164.txt) syslog message.

---

<div class="post-metadata">

**Author:** ![f1wing](https://avatars.discourse-cdn.com/v4/letter/f/4491bb/32.png) [@f1wing](https://discuss.elastic.co/u/f1wing)\
**Post date:** [December 10, 2019, 4:02pm UTC](https://discuss.elastic.co/t/logstash-syslog-help/211186/3 "2019-12-10T16:02:18Z")

</div>

Thanks Badger. I'll look into the RFC3164.

I guess the timestamp that I see in rsyslog is a timestamp from the rsyslog and not from the log send by the firewall, right? That is why logstash do not see a timestamp?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 7, 2020, 4:02pm UTC](https://discuss.elastic.co/t/logstash-syslog-help/211186/4 "2020-01-07T16:02:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
