# Parsing F5 LTM logs with Logstash

**URL:** <https://discuss.elastic.co/t/parsing-f5-ltm-logs-with-logstash/197392>\
**Category:** Logstash\
**Created:** [August 29, 2019, 6:01pm UTC](https://discuss.elastic.co/t/parsing-f5-ltm-logs-with-logstash/197392 "2019-08-29T18:01:27Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![sarahvo](https://avatars.discourse-cdn.com/v4/letter/s/f04885/32.png) [@sarahvo](https://discuss.elastic.co/u/sarahvo)\
**Post date:** [August 29, 2019, 6:01pm UTC](https://discuss.elastic.co/t/parsing-f5-ltm-logs-with-logstash/197392/1 "2019-08-29T18:01:28Z")

</div>

Hi, I'm trying to parse LTM logs using this example (found in the [official documentation](https://www.elastic.co/guide/en/logstash/current/config-examples.html#_processing_syslog_messages)) below:

> filter {  
> if [type] == "syslog" {  
> grok {  
> match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
> add\_field =\> ["received\_at", "%{@timestamp}"]  
> add\_field =\> ["received\_from", "%{host}"]  
> }  
> date {  
> match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
> }  
> }  
> }

I'm using filebeat to ship the logs to logstash, however the parsing doesn't seem to be working. Any tips or help would be greatly appreciated!

Here's an example of how my logs currently look below:

 ![Capture](https://us1.discourse-cdn.com/elastic/original/3X/a/7/a77dc6178379617fd036d3034b24a7a9c1ffaf98.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 29, 2019, 6:06pm UTC](https://discuss.elastic.co/t/parsing-f5-ltm-logs-with-logstash/197392/2 "2019-08-29T18:06:42Z")

</div>

Please do not post pictures of text, just post the text. What does the [message] field look like?

---

<div class="post-metadata">

**Author:** ![sarahvo](https://avatars.discourse-cdn.com/v4/letter/s/f04885/32.png) [@sarahvo](https://discuss.elastic.co/u/sarahvo)\
**Post date:** [August 29, 2019, 6:08pm UTC](https://discuss.elastic.co/t/parsing-f5-ltm-logs-with-logstash/197392/3 "2019-08-29T18:08:49Z")

</div>

The message field looks like this:

> message 2019-08-29T10:45:01-07:00 devlkfltm02 info CROND[12075]: (root) CMD (nice -n 19 ionice -c 3 /usr/share/ts/bin/asm\_logrotate)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 29, 2019, 6:21pm UTC](https://discuss.elastic.co/t/parsing-f5-ltm-logs-with-logstash/197392/4 "2019-08-29T18:21:15Z")

</div>

The timestamp is nothing like a [SYSLOGTIMESTAMP](https://github.com/logstash-plugins/logstash-patterns-core/blob/66905291fc22947b09b64f0bc7800221c2a853e9/patterns/grok-patterns#L81), which would be something like "Aug 29 12:34:56". Replace SYSLOGTIMESTAMP with TIMESTAMP\_ISO8601.

You also need to modify the date filter to parse the format you have.

```
match => ["syslog_timestamp", "ISO8601"]
```

---

<div class="post-metadata">

**Author:** ![sarahvo](https://avatars.discourse-cdn.com/v4/letter/s/f04885/32.png) [@sarahvo](https://discuss.elastic.co/u/sarahvo)\
**Post date:** [August 29, 2019, 6:23pm UTC](https://discuss.elastic.co/t/parsing-f5-ltm-logs-with-logstash/197392/5 "2019-08-29T18:23:45Z")

</div>

Okay, thanks. Is there any documentation where I can find how to properly format this?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 29, 2019, 6:54pm UTC](https://discuss.elastic.co/t/parsing-f5-ltm-logs-with-logstash/197392/6 "2019-08-29T18:54:20Z")

</div>

The documentation for the patterns pre-defined for grok is really the patterns themselves. On my system they are in a set of files in the directory /usr/share/logstash/vendor/bundle/jruby/2.5.0/gems/logstash-patterns-core-4.1.2/patterns/

---

<div class="post-metadata">

**Author:** ![sarahvo](https://avatars.discourse-cdn.com/v4/letter/s/f04885/32.png) [@sarahvo](https://discuss.elastic.co/u/sarahvo)\
**Post date:** [August 29, 2019, 7:04pm UTC](https://discuss.elastic.co/t/parsing-f5-ltm-logs-with-logstash/197392/7 "2019-08-29T19:04:29Z")

</div>

Okay, I'm going to try and fix the grok patterns. I'm running elasticsearch, logstash, and kibana using docker-compose. Do you know if it's sufficient just to restart the logstash container for the updates on the configuration to take place?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 29, 2019, 7:09pm UTC](https://discuss.elastic.co/t/parsing-f5-ltm-logs-with-logstash/197392/8 "2019-08-29T19:09:34Z")

</div>

> [@sarahvo](#):
>
> Do you know if it's sufficient just to restart the logstash container for the updates on the configuration to take place?

Yes, and if you run with --config.reload.automatic on the command line you do not even need to restart.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 26, 2019, 7:09pm UTC](https://discuss.elastic.co/t/parsing-f5-ltm-logs-with-logstash/197392/9 "2019-09-26T19:09:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
