# Parsing nested logs

**URL:** <https://discuss.elastic.co/t/parsing-nested-logs/2688>\
**Category:** Logstash\
**Created:** [June 15, 2015, 11:55am UTC](https://discuss.elastic.co/t/parsing-nested-logs/2688 "2015-06-15T11:55:16Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![lladelfa](https://avatars.discourse-cdn.com/v4/letter/l/8491ac/32.png) [@lladelfa](https://discuss.elastic.co/u/lladelfa)\
**Post date:** [June 15, 2015, 11:55am UTC](https://discuss.elastic.co/t/parsing-nested-logs/2688/1 "2015-06-15T11:55:16Z")

</div>

Hello,  
I've been testing the logstash (1.5.0) in order to process a log generated from a fortianalyzer (by fortinet) without being successful. I have to say it's my first try with logstash so I kindly appreciate some help.

here is my .conf file:  
input {  
file {  
path =\> "/var/log/fortisyslog.log"  
type =\> fortisyslog  
}  
}

filter {  
grok {  
match =\> { "message" =\> "(?:%{SYSLOGTIMESTAMP:timestamp}|%{TIMESTAMP\_ISO8601:timestamp8601}) ?%{SYSLOGHOST:logsource} severity=%{WORD:severity} from=MYSOURCE(%{WORD:fazsou  
rce}) trigger=%{WORD:customer}-%{WORD:famprod} log=%{GREEDYDATA:flog}" }  
}  
kv {  
}  
}

output {  
if [type] == "fortisyslog" {  
stdout {  
codec =\> json  
}  
}  
}

the input is the following line:  
2015-06-15T09:13:58.415212+02:00 1.2.2.120 severity=medium from=MYSOURCE(ABCDE0000001) trigger=customer-SLA log="date=2015-06-15 time=09:13:53 itime=1434352437 devname=ASSSDDR44331638 devid=ASSSDDR44331638 logid=18432 type=utm subtype=ips eventtype=anomaly level=alert vd=root severity=critical srcip=1.2.3.48 dstip=1.2.3.55 srcintf="internal1" policyid=N/A identidx=N/A sessionid=0 status=detected proto=17 service=137/udp count=39 attackname="udp\_scan" srcport=137 dstport=137 attackid=285212776 sensor="DoS-policy3" ref="[http://www.fortinet.com/ids/VID285212776](http://www.fortinet.com/ids/VID285212776)" msg="anomaly: udp\_scan, 41 \> threshold 40, repeats 39 times" crscore=3422552114 craction=4096"

the output is:  
{"message":"2015-06-15T09:13:58.415212+02:00 1.2.2.120 severity=medium from=MYSOURCE(ABCDE0000001) trigger=customer-SLA log="date=2015-06-15 time=09:13:53 itime=1434352437 devname=ASSSDDR44331638 devid=ASSSDDR44331638 logid=18432 type=utm subtype=ips eventtype=anomaly level=alert vd=root severity=critical srcip=1.2.3.48 dstip=1.2.3.55 srcintf="internal1" policyid=N/A identidx=N/A sessionid=0 status=detected proto=17 service=137/udp count=39 attackname="udp\_scan" srcport=137 dstport=137 attackid=285212776 sensor="DoS-policy3" ref="[http://www.fortinet.com/ids/VID285212776](http://www.fortinet.com/ids/VID285212776)" msg="anomaly: udp\_scan, 41 \> threshold 40, repeats 39 times" crscore=3422552114 craction=4096" ","@version":"1","@timestamp":"2015-06-15T07:14:04.083Z","type":"fortisyslog","host":"slav4","path":"/var/log/fortisyslog.log","timestamp8601":"2015-06-15T09:13:58.415212+02:00","logsource":"1.2.2.120","severity":"medium","fazsource":"ABCDE0000001","customer":"customer","famprod":"SLA","flog":""date=2015-06-15 time=09:13:53 itime=1434352437 devname=ASSSDDR44331638 devid=ASSSDDR44331638 logid=18432 type=utm subtype=ips eventtype=anomaly level=alert vd=root severity=critical srcip=1.2.3.48 dstip=1.2.3.55 srcintf="internal1" policyid=N/A identidx=N/A sessionid=0 status=detected proto=17 service=137/udp count=39 attackname="udp\_scan" srcport=137 dstport=137 attackid=285212776 sensor="DoS-policy3" ref="[http://www.fortinet.com/ids/VID285212776](http://www.fortinet.com/ids/VID285212776)" msg="anomaly: udp\_scan, 41 \> threshold 40, repeats 39 times" crscore=3422552114 craction=4096" ","from":"MYSOURCE(ABCDE0000001)","trigger":"customer-SLA","log":"date=2015-06-15 time=09:13:53 itime=1434352437 devname=ASSSDDR44331638 devid=ASSSDDR44331638 logid=18432 type=utm subtype=ips eventtype=anomaly level=alert vd=root severity=critical srcip=1.2.3.48 dstip=1.2.3.55 srcintf=","policyid":"N/A","identidx":"N/A","sessionid":"0","status":"detected","proto":"17","service":"137/udp","count":"39","attackname":"udp\_scan","srcport":"137","dstport":"137","attackid":"285212776","sensor":"DoS-policy3","ref":"[http://www.fortinet.com/ids/VID285212776","msg":"anomaly:](http://www.fortinet.com/ids/VID285212776%22,%22msg%22:%22anomaly:) udp\_scan, 41 \> threshold 40, repeats 39 times","crscore":"3422552114","craction":"4096""}

It looks like the field flog is parsed till the second occurence of the character -"- . How can I overcome this problem?

Thanks in advance.

Luciano

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:37am UTC](https://discuss.elastic.co/t/parsing-nested-logs/2688/2 "2017-07-06T05:37:29Z")

</div>


