# Parsing syslogs using Grok

**URL:** <https://discuss.elastic.co/t/parsing-syslogs-using-grok/252673>\
**Category:** Elasticsearch\
**Created:** [October 20, 2020, 11:59am UTC](https://discuss.elastic.co/t/parsing-syslogs-using-grok/252673 "2020-10-20T11:59:57Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![pacy1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pacy1/32/76910_2.png) [@pacy1](https://discuss.elastic.co/u/pacy1)\
**Post date:** [October 20, 2020, 11:59am UTC](https://discuss.elastic.co/t/parsing-syslogs-using-grok/252673/1 "2020-10-20T11:59:57Z")

</div>

Hi All,  
Hope you are good!!  
I need your help on how syslog configuration with the following raw event that is unstructured, how to parsing using grok filter:

2020-10-05T00:00:00+02:00 x.x.x.x 3 `0` 1 `1` 229eb9 `1020` 20201005 `00:00:00` 1 `6` Allow\_All `y.y.y.y` 49120 `t.t.t.t` 8098 `eth0` eth1 `S```2`N/A`4```` 2020-10-05T00:00:00+02:00 x.x.x.x 3`0`1`1`229eb9`1020`20201005`00:00:00`3`6`Allow_All`y.y.y.y`49120`t.t.t.t`8098`eth0`eth1````40`1`40`1`2`2`S ra`2`N/A`4```` 2020-10-05T00:00:00+02:00 x.x.x.x 3`0`1`1`229eb9`1020`20201005`00:00:00`3`6`Allow_All`y.y.y.y`14024`t.t.t.t`443`eth0`eth1````2358`23`21250`21``31`0``S sa A / fa A+`2`N/A`4` 2020-10-05T00:00:00+02:00 x.x.x.x 3`0`1`1`229eb9`1020`20201005`00:00:00`3`17`Allow_All`y.y.y.y`51106`t.t.t.t`53`eth1`eth0`73`1`114`1``1`0`````2`N/A`4` 2020-10-05T00:00:00+02:00 x.x.x.x 3`0`1`1`229eb9`1021`20201005`00:00:00`2`6`UTM_DEFAULT`y.y.y.y`40443`t.t.t.t`16492`eth5`none`40`1```````S```0``4```` 2020-10-05T00:00:00+02:00 x.x.x.x 3`0`1`1`229eb9`1020`20201005`00:00:00`1`6`Allow_All`y.y.y.y`46733`t.t.t.t`443`eth0`eth1` RA `2`N/A`4```` 2020-10-05T00:00:00+02:00 x.x.x.x 3`0`1`1`229eb9`1020`20201005`00:00:00`3`6`Allow_All`y.y.y.y`46733`t.t.t.t`443`eth0`eth1````52`1`0`0`32`0`RA`2`N/A` 4````  
2020-10-05T00:00:00+02:00 x.x.x.x  
etc....

from the above information, this is the raw event from IPS( Ihave modified the IP information)

where you find: x.x.x.x is the IP of security device(log source IP/host IP)

y.y.y.y is the source IP information and t.t.t.t is the destination IP information  
all these are the Traffic from the device(IPS).  
On the above raw events there are other information that we will need their fields and this is how it looks:

time: yyyy-mm-dd hh-mm-ss  
host=x.x.x.x  
host\_name=xname  
src\_ip: y.y.y.y  
dest\_ip:t.t.t.t  
src\_port:49120  
dest\_port:8098  
action: allow (here the value can be either allow or block or teardown)  
signature: jjjjjj  
signature eg:http\_method or DoS ,etc...(here this is the signature information that will be also included in the fields)

Here I give an example of how it looks but the value are all dynamic/changing everytime.  
from this information above I want the configuration that will allow me to receive logs from device(IPS). Kindly help on how to do parsing for the above raw events data from IPS. Thank you in advance.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 17, 2020, 12:00pm UTC](https://discuss.elastic.co/t/parsing-syslogs-using-grok/252673/2 "2020-11-17T12:00:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
