# Parser for LDAP logs - ECS format

**URL:** <https://discuss.elastic.co/t/parser-for-ldap-logs-ecs-format/262115>\
**Category:** Elasticsearch\
**Created:** [January 25, 2021, 1:48pm UTC](https://discuss.elastic.co/t/parser-for-ldap-logs-ecs-format/262115 "2021-01-25T13:48:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Logsman](https://avatars.discourse-cdn.com/v4/letter/l/9de053/32.png) [@Logsman](https://discuss.elastic.co/u/Logsman)\
**Post date:** [January 25, 2021, 1:48pm UTC](https://discuss.elastic.co/t/parser-for-ldap-logs-ecs-format/262115/1 "2021-01-25T13:48:14Z")

</div>

Hi there !

I'm currently collecting LDAP logs (RHDS) with filebeat.  
As you know, there isn't any module for these type of logs. However, I would like to be able to create alert on Elastic security based on these logs.  
This mean I need to parse this logs with ECS format.

What is the best way to do it ? Directly in Filebeat or through Elastic or Logstash ?  
What the configuration should look like ?

Any idea would be welcome.  
Cheers

---

<div class="post-metadata">

**Author:** ![Logsman](https://avatars.discourse-cdn.com/v4/letter/l/9de053/32.png) [@Logsman](https://discuss.elastic.co/u/Logsman)\
**Post date:** [February 2, 2021, 9:22am UTC](https://discuss.elastic.co/t/parser-for-ldap-logs-ecs-format/262115/2 "2021-02-02T09:22:43Z")

</div>

Hi all,

Any help would be appreciated 🙂

I don't know where to start and how to do it. I found some info there : [GitHub - ltb-project/openldap-elk: ELK configuration to parse OpenLDAP logs](https://github.com/ltb-project/openldap-elk)  
I tried it but it's not working. Moreover this is not parsed to the ECS format.

I send my logs directly to Elasticsearch, so I imagine that I need to write a grok function in an ingest node pipeline. Correct me if I'm wrong.

Cheers

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 2, 2021, 9:22am UTC](https://discuss.elastic.co/t/parser-for-ldap-logs-ecs-format/262115/3 "2021-03-02T09:22:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
