# Provided expression do not match field value filebeat 8.15.0 fortinet module

**URL:** <https://discuss.elastic.co/t/provided-expression-do-not-match-field-value-filebeat-8-15-0-fortinet-module/365612>\
**Category:** Beats\
**Tags:** beats-module, filebeat\
**Created:** [August 27, 2024, 10:59am UTC](https://discuss.elastic.co/t/provided-expression-do-not-match-field-value-filebeat-8-15-0-fortinet-module/365612 "2024-08-27T10:59:16Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![fracorbas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fracorbas/32/133601_2.png) [@fracorbas](https://discuss.elastic.co/u/fracorbas)\
**Post date:** [August 27, 2024, 10:59am UTC](https://discuss.elastic.co/t/provided-expression-do-not-match-field-value-filebeat-8-15-0-fortinet-module/365612/1 "2024-08-27T10:59:16Z")

</div>

I'm trying to analyze Fortinet FortiGate logs with the filebeat module "Fortinet". The only informations and solutions I found about this was Topics from 2019-2020 with a filebeat version 7.5 which was way too long ago.

I get the logs via syslog and send all the log into a specific file with rsyslog :

```auto
if ($fromhost-ip == '10.10.10.10') then {
    action(type="omfile" file="/var/log/fortinet.log")
    stop
}

```

And it works well.

In the Fortinet module I did :

```yml
- module: fortinet
  firewall:
    enabled: true
    var.input: "file"

    var.paths: ["/var/log/fortinet.log"]
    var.tags: [fortinet-firewall, forwarded]

```

Which is working, I have no issue with the service and no error is showing up.

The thing is that in the documentation, both the module and integration for elastic are saying :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/5/753b7057401dc4248abe3838e3f7c9620c4c44a0.png)  
But my FortiGate is in version 7.2.x

Does anyone have an issue with the module and is there any modification needed to make this error disappear ?

Currently, I recieve the logs, the logs are treated by filebeat but he doesn't do anything he's not adding the data into the designated fields. He's just adding a "error.message" field with the sentence "Provided expression do not match field value".

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/4/0498419d1974a9bf93d7de3e3554cbafd32c0918.png)

just after there is the whole line of log _which I'm not showing because of the information it contains_

Hope someone can help.

---

<div class="post-metadata">

**Author:** ![fracorbas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fracorbas/32/133601_2.png) [@fracorbas](https://discuss.elastic.co/u/fracorbas)\
**Post date:** [August 29, 2024, 2:21pm UTC](https://discuss.elastic.co/t/provided-expression-do-not-match-field-value-filebeat-8-15-0-fortinet-module/365612/2 "2024-08-29T14:21:56Z")

</div>

I see that there has been a lot of questions about this like these ones : [[Filebeat][Fortinet Module] Failed to parse field - Elastic Stack / Beats - Discuss the Elastic Stack](https://discuss.elastic.co/t/filebeat-fortinet-module-failed-to-parse-field/273437#!)  
[Filebeat Fortinet have error message - Elastic Stack / Beats - Discuss the Elastic Stack](https://discuss.elastic.co/t/filebeat-fortinet-have-error-message/258261#!)

They all are way out of date. So has there been any update on the module since then ?

And yes, I tried using the pattenrs they gave here [[Filebeat Fortinet Module] Include more Grok Pattern · Issue #23246 · elastic/beats · GitHub](https://github.com/elastic/beats/issues/23246)

But it dit not work.
