# Parsing firewall logs in logstash

**URL:** <https://discuss.elastic.co/t/parsing-firewall-logs-in-logstash/338405>\
**Category:** Logstash\
**Created:** [July 14, 2023, 10:45am UTC](https://discuss.elastic.co/t/parsing-firewall-logs-in-logstash/338405 "2023-07-14T10:45:30Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![secsec](https://avatars.discourse-cdn.com/v4/letter/s/73ab20/32.png) [@secsec](https://discuss.elastic.co/u/secsec)\
**Post date:** [July 14, 2023, 10:45am UTC](https://discuss.elastic.co/t/parsing-firewall-logs-in-logstash/338405/1 "2023-07-14T10:45:30Z")

</div>

Hello,

our sophos firewall are sending logs to filebeat, then filebeat send to logstash. In logstash im trying to separate field called "action" to be able to filter it under elasticsearch. So far no luck. I managed to create new field "event.action" that , but the value what is shown for this event.action is "%{action}". So it is not getting value real "action" value. Code is below. Also please see the image below from elasticsearch:

ctrl.vi/i/M-7pR2uI1

Does please anyone know how i can get "action" value from syslog message? Im struggling with this at least 3 days.

Many thanks for all of your answers.

filter {  
grok {  
match =\> { "message" =\> '\<%{POSINT}\>%{TIMESTAMP\_ISO8601:timestamp} %{WORD:hostname} %{WORD:process}[%{POSINT:pid}]: id="%{INT:id}" severity="%{WORD:severity}" sys="%{WORD:sys}" sub="%{WORD:sub}" name="%{DATA:name}" action="%{WORD:action}" fwrule="%{INT:fwrule}" initf="%{DATA:initf}" srcmac="%{DATA:srcmac}" dstmac="%{DATA:dstmac}" srcip="%{IP:srcip}" dstip="%{IP:dstip}" proto="%{INT:proto}" length="%{INT:length}" tos="%{DATA:tos}" prec="%{DATA:prec}" ttl="%{INT:ttl}"' }  
}

mutate {  
add\_field =\> {  
"[event][action]" =\> "%{action}"  
}  
remove\_field =\> ["action"]  
}  
}

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 14, 2023, 1:31pm UTC](https://discuss.elastic.co/t/parsing-firewall-logs-in-logstash/338405/2 "2023-07-14T13:31:25Z")

</div>

Can you share a sample message of your logs?

From what you shared a big part of your message is a key-value message which you can easily parse using the `kv` filter instead of using `grok`.

Also, your mutate is wrong, you need the order of the operations to be preserved, so you need to use two mutate blocks, if you have `add_field` and then `remove_field` with the same field, it may remove the field before it creates the new one.

This is in the documentation:

> Each mutation must be in its own code block if the sequence of operations needs to be preserved.

Try this:

```auto
mutate {
    add_field => {
        "[event][action]" => "%{action}"
    }
}
mutate {
    remove_field => ["action"]
}

```

Or you can just use a rename

```auto
mutate {
    rename => {
        "action" => "[event][action]"
    }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 11, 2023, 1:32pm UTC](https://discuss.elastic.co/t/parsing-firewall-logs-in-logstash/338405/3 "2023-08-11T13:32:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
