# Reverse\_mapping for cef input codec not working

**URL:** <https://discuss.elastic.co/t/reverse-mapping-for-cef-input-codec-not-working/169184>\
**Category:** Logstash\
**Created:** [February 20, 2019, 10:51am UTC](https://discuss.elastic.co/t/reverse-mapping-for-cef-input-codec-not-working/169184 "2019-02-20T10:51:43Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![FreddyFernando](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/freddyfernando/32/37298_2.png) [@FreddyFernando](https://discuss.elastic.co/u/FreddyFernando)\
**Post date:** [February 20, 2019, 10:51am UTC](https://discuss.elastic.co/t/reverse-mapping-for-cef-input-codec-not-working/169184/1 "2019-02-20T10:51:43Z")

</div>

Cef reverse\_mapping does not work.  
I am expecting logstash to give me short form of cef, instead it gives me the long form.

- Version: Logstash 6.5.0 (cef codec version 5.0.6)
- Operating System: Ubuntu 16.04
- Config File (if you have sensitive info, please remove it):

```auto
input
{
   tcp {
    port => 1234
    codec => cef {
        reverse_mapping => true
    }
   }
}
filter { }
output {
stdout { codec => rubydebug }
}

```

- Sample Data: CEF:0|XXXXX|XXXXX||SEC:xxxxxxxx:denied|denied|Low| eventId=9999 externalId=9999 msg=list xxxx-xxxxxx denied 10.0.0.0 1 packet categorySignificance=/Informational/Warning categoryBehavior=/Access categoryDeviceGroup=/Firewall catdt=Router categoryOutcome=/Failure categoryObject=/Host/Application/Service art=99999 deviceSeverity=6 act=denied rt=999999 src=10.1.100.17 sourceZoneURI=/All Zones/ArcSight System/Private Address Space Zones/RFC1918: 10.0.0.0-10.255.255.255 cs2=SEC cs3=xxxx cs5=SEC-6-xxxxxxxx cs6=xxxx-xxxxx cn2=1 cs1Label=Slot/Card cs2Label=XXXXX cs3Label=xxxxxx cs4Label=ICMP Type cs5Label=CiscoAlertCode cs6Label=ACL Number cn2Label=Packets [ahost=xxx-xx-xxx.xxx.xxx.com](http://ahost=xxx-xx-xxx.xxx.xxx.com) agt=10.0.0.0 agentZoneURI=/All Zones/xxx xxxx/Private Address Space Zones/RFC1918: 10.0.0.0-10.255.255.255 amac=00-00-00-00-00-00 av=7.6.0.8009.0 atz=Asia/xxxx at=syslog dvc=10.0.0.0 deviceZoneURI=/All Zones/xxx xxx/Private Address xxx xx/RFC999: 10.0.0.0-10.255.255.255 dtz=xxx/xxxx \_cefVer=0.1 ad.Message=%Sxxx-6-xxxxxxxx: list xx-xx denied 10.0.0.0 1 packet ad.mnemonic=SEC-6-xxxxxxxx ad.message=list xx-xx denied 10.0.0.0 1 packet aid=xxx-xxxxxxxxxxxx+xxx==

- Steps to Reproduce: Start logstash as process, run `/usr/share/logstash/bin/logstash -r -f cef.conf`

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 20, 2019, 12:50pm UTC](https://discuss.elastic.co/t/reverse-mapping-for-cef-input-codec-not-working/169184/2 "2019-02-20T12:50:59Z")

</div>

The reverse\_mapping option is for output. So

```
   output { stdout { codec => cef { reverse_mapping => false fields => ["sourceAddress", "deviceCustomString4Label"] } } }

```

will get you

```
CEF:0|Elasticsearch|Logstash|1.0|Logstash|Logstash|6|sourceAddress=10.1.100.17 deviceCustomString4Label=ICMP Type

```

and if you flip that to true you get

```
CEF:0|Elasticsearch|Logstash|1.0|Logstash|Logstash|6|src=10.1.100.17 cs4Label=ICMP Type
```

---

<div class="post-metadata">

**Author:** ![FreddyFernando](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/freddyfernando/32/37298_2.png) [@FreddyFernando](https://discuss.elastic.co/u/FreddyFernando)\
**Post date:** [March 6, 2019, 8:42am UTC](https://discuss.elastic.co/t/reverse-mapping-for-cef-input-codec-not-working/169184/3 "2019-03-06T08:42:53Z")

</div>

According to this, I can see that it should work on input plugin too.

[https://www.elastic.co/guide/en/logstash/current/plugins-codecs-cef.html](https://www.elastic.co/guide/en/logstash/current/plugins-codecs-cef.html)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 6, 2019, 12:41pm UTC](https://discuss.elastic.co/t/reverse-mapping-for-cef-input-codec-not-working/169184/4 "2019-03-06T12:41:19Z")

</div>

No, that says it will " encode using the CEF key name". Encoding is only done on output.

You can check the [source](https://github.com/logstash-plugins/logstash-codec-cef/blob/6e8f756c6f04f3645c12376c35addbe67776202b/lib/logstash/codecs/cef.rb#L399). @reverse\_mapping is only tested in get\_value, and get\_value is only called in the encode function that is used for output.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 3, 2019, 12:41pm UTC](https://discuss.elastic.co/t/reverse-mapping-for-cef-input-codec-not-working/169184/5 "2019-04-03T12:41:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
