# Parsing USG Pro Firewall logs using GROK

**URL:** <https://discuss.elastic.co/t/parsing-usg-pro-firewall-logs-using-grok/264078>\
**Category:** Logstash\
**Created:** [February 12, 2021, 3:20am UTC](https://discuss.elastic.co/t/parsing-usg-pro-firewall-logs-using-grok/264078 "2021-02-12T03:20:31Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 12, 2021, 3:53am UTC](https://discuss.elastic.co/t/parsing-usg-pro-firewall-logs-using-grok/264078/2 "2021-02-12T03:53:13Z")

</div>

Do not start with grok. Think about using dissect and kv. [Here](https://discuss.elastic.co/t/grok-filter-extracting-fields-from-message/238298/8) is an example.

grok is massively overused because it is extremely powerful and one of the earliest options. That does not make it a good solution.

---

_[View the full topic](https://discuss.elastic.co/t/parsing-usg-pro-firewall-logs-using-grok/264078)._
