# Parsing USG Pro Firewall logs using GROK

**URL:** <https://discuss.elastic.co/t/parsing-usg-pro-firewall-logs-using-grok/264078>\
**Category:** Logstash\
**Created:** [February 12, 2021, 3:20am UTC](https://discuss.elastic.co/t/parsing-usg-pro-firewall-logs-using-grok/264078 "2021-02-12T03:20:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jaysbeekay](https://avatars.discourse-cdn.com/v4/letter/j/ecb155/32.png) [@jaysbeekay](https://discuss.elastic.co/u/jaysbeekay)\
**Post date:** [February 12, 2021, 3:20am UTC](https://discuss.elastic.co/t/parsing-usg-pro-firewall-logs-using-grok/264078/1 "2021-02-12T03:20:31Z")

</div>

I have managed to stand up an ELK stack on an Ubuntu host to bring in my NGINX logs, which is all working well.

I have now tried to expand this to bring in firewall logs from my USG Pro Firewall and am running into some issues when trying to formulate a GROK formula!

Example log:

`Feb 12 10:08:12 USG-Pro-4 kernel: [WAN_OUT-2000-D]IN=eth0.20 OUT=eth2 MAC=fc:ec:da:48:75:63:d8:0d:17:f0:2f:cd:08:00:45:00:00:2c SRC=192.168.20.69 DST=13.200.17.13 LEN=44 TOS=0x00 PREC=0x00 TTL=63 ID=58512 PROTO=TCP SPT=59296 DPT=443 WINDOW=8192 RES=0x00 SYN URGP=0`

Using GROK Debug, I have managed to construct the following grok formula which parses everything from `[WAN_OUT-2000]` onwards correctly:

`\[%{WORD:interface}-%{WORD:ruleindex}-%{WORD:action}\]IN=%{NOTSPACE:IN}%{SPACE}OUT=%{NOTSPACE:OUT}%{SPACE}MAC=%{NOTSPACE:MAC}%{SPACE}SRC=%{NOTSPACE:SRCIP}%{SPACE}DST=%{NOTSPACE:DSTIP}%{SPACE}LEN=%{WORD:LEN}%{SPACE}TOS=%{WORD:TOS}%{SPACE}PREC=%{WORD:PREC}%{SPACE}TTL=%{WORD:TTL}%{SPACE}ID=%{WORD:ID}%{SPACE}(%{NOTSPACE:PROTO}| DF PROTO)=%{WORD:DF}%{SPACE}SPT=%{WORD:SPT}%{SPACE}DPT=%{WORD:DPT}`

Any ideas on how to parse the date, hostname and source would be greatly appreciated!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 12, 2021, 3:53am UTC](https://discuss.elastic.co/t/parsing-usg-pro-firewall-logs-using-grok/264078/2 "2021-02-12T03:53:13Z")

</div>

Do not start with grok. Think about using dissect and kv. [Here](https://discuss.elastic.co/t/grok-filter-extracting-fields-from-message/238298/8) is an example.

grok is massively overused because it is extremely powerful and one of the earliest options. That does not make it a good solution.

---

<div class="post-metadata">

**Author:** ![jaysbeekay](https://avatars.discourse-cdn.com/v4/letter/j/ecb155/32.png) [@jaysbeekay](https://discuss.elastic.co/u/jaysbeekay)\
**Post date:** [February 12, 2021, 4:36am UTC](https://discuss.elastic.co/t/parsing-usg-pro-firewall-logs-using-grok/264078/3 "2021-02-12T04:36:31Z")

</div>

Thanks Badger, I'm sooo close with Grok was hoping it was something simple that I needed to add.

If I can't figure it out by the end of this week will have to investigate dissect.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 12, 2021, 4:37am UTC](https://discuss.elastic.co/t/parsing-usg-pro-firewall-logs-using-grok/264078/4 "2021-03-12T04:37:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
