# Parse Vsftp log (Filebeat + Logstash)

**URL:** <https://discuss.elastic.co/t/parse-vsftp-log-filebeat-logstash/288040>\
**Category:** Logstash\
**Created:** [October 29, 2021, 9:40pm UTC](https://discuss.elastic.co/t/parse-vsftp-log-filebeat-logstash/288040 "2021-10-29T21:40:09Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 29, 2021, 10:42pm UTC](https://discuss.elastic.co/t/parse-vsftp-log-filebeat-logstash/288040/2 "2021-10-29T22:42:05Z")

</div>

Use dissect to parse the fixed prefix and grok with an array of patterns for the variable part. An example is [here](https://discuss.elastic.co/t/metatrader-how-parse-such-logs/248406/2).

---

_[View the full topic](https://discuss.elastic.co/t/parse-vsftp-log-filebeat-logstash/288040)._
