# Parse Vsftp log (Filebeat + Logstash)

**URL:** <https://discuss.elastic.co/t/parse-vsftp-log-filebeat-logstash/288040>\
**Category:** Logstash\
**Created:** [October 29, 2021, 9:40pm UTC](https://discuss.elastic.co/t/parse-vsftp-log-filebeat-logstash/288040 "2021-10-29T21:40:09Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hecha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hecha/32/87119_2.png) [@Hecha](https://discuss.elastic.co/u/Hecha)\
**Post date:** [October 29, 2021, 9:40pm UTC](https://discuss.elastic.co/t/parse-vsftp-log-filebeat-logstash/288040/1 "2021-10-29T21:40:09Z")

</div>

Hello guys! I am trying to parse the logs of my FTP server (Vsftpd) with logstash but I am having trouble.  
The logs follow the following format

```auto
Fri Oct 29 17:16:17 2021 [pid 22947] CONNECT: Client "::ffff:10.0.1.6"
Fri Oct 29 17:16:26 2021 [pid 22940] [test] FAIL LOGIN: Client "::ffff:10.0.1.6"
Fri Oct 29 17:16:51 2021 [pid 22954] CONNECT: Client "::ffff:10.0.1.6"
Fri Oct 29 17:16:59 2021 [pid 22953] [user] OK LOGIN: Client "::ffff:10.0.1.6"
Fri Oct 29 17:17:31 2021 [pid 22955] [user] OK DOWNLOAD: Client "::ffff:10.0.1.6", "/home/user/credentials.txt", 64 bytes, 24.33Kbyte/sec

```

I have not found any filebeat or logstash modules to help me achieve this

I tried using grok filter but the problem is that the lines are not all the same

I hope some of you can help me 🙂

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 29, 2021, 10:42pm UTC](https://discuss.elastic.co/t/parse-vsftp-log-filebeat-logstash/288040/2 "2021-10-29T22:42:05Z")

</div>

Use dissect to parse the fixed prefix and grok with an array of patterns for the variable part. An example is [here](https://discuss.elastic.co/t/metatrader-how-parse-such-logs/248406/2).

---

<div class="post-metadata">

**Author:** ![Hecha](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hecha/32/87119_2.png) [@Hecha](https://discuss.elastic.co/u/Hecha)\
**Post date:** [November 9, 2021, 8:21pm UTC](https://discuss.elastic.co/t/parse-vsftp-log-filebeat-logstash/288040/3 "2021-11-09T20:21:12Z")

</div>

Hey guys, i write a script to clean vsftpd log and convert it into ndjson.  
You can find it on this repo : [Vsftpd Parser](https://github.com/ettoreciarcia/ParsingVsftpd)  
I hope you find it useful!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 7, 2021, 8:22pm UTC](https://discuss.elastic.co/t/parse-vsftp-log-filebeat-logstash/288040/4 "2021-12-07T20:22:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
