# Syslog additional fields

**URL:** <https://discuss.elastic.co/t/syslog-additional-fields/36389>\
**Category:** Logstash\
**Created:** [December 4, 2015, 1:55pm UTC](https://discuss.elastic.co/t/syslog-additional-fields/36389 "2015-12-04T13:55:16Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![theo.bot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theo.bot/32/5739_2.png) [@theo.bot](https://discuss.elastic.co/u/theo.bot)\
**Post date:** [December 4, 2015, 1:55pm UTC](https://discuss.elastic.co/t/syslog-additional-fields/36389/1 "2015-12-04T13:55:16Z")

</div>

Hi

We use a default filter for syslog messages, so they get parsed properly. However I wondered if it would be possible to match the message against a secondary pattern and extract new fields from the message:  
Dec 4 14:12:46 10.1.1.254,149 338732: 338728: \*Dec 4  
13:13:38.097 GMT: %SEC-6-IPACCESSLOGP: list FILTER\_INTERNET\_IN denied  
tcp 1.2.3.4(53261) -\> 5.6.7.8(5000), 1 packet

In this case i would like to store the 1.2.34 in a new field like offending\_ip

Thanks in advance

Kind regards

Theo

---

<div class="post-metadata">

**Author:** ![Jackal9301](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jackal9301/32/5748_2.png) [@Jackal9301](https://discuss.elastic.co/u/Jackal9301)\
**Post date:** [December 4, 2015, 2:48pm UTC](https://discuss.elastic.co/t/syslog-additional-fields/36389/2 "2015-12-04T14:48:02Z")

</div>

Absolutely you just have to write a grok for it. I did it for you just because I had a minute.

```
grok {   
match => { "message", "%{SYSLOGTIMESTAMP} %{IPV4},%{BASE10NUM} %{BASE10NUM}: {BASE10NUM}: \*%{SYSLOGTIMESTAMP} %{NOTSPACE} %{PROG}: %{WORD} %{PROG} %{WORD} %{WORD} %{IPV4:offending_ip}\(%{BASE10NUM}\) -> %{IPV4}\(%{BASE10NUM}\),%{GREEDYDATA}" }
}

```

That would actually parse the entire log you can take as much of it as you want. I dont know what your initial syslog part config looks like but if you post it I can show you how this would go in your config.

Jack West

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [December 4, 2015, 4:49pm UTC](https://discuss.elastic.co/t/syslog-additional-fields/36389/3 "2015-12-04T16:49:17Z")

</div>

You could also grok in multiple passes. If you have a basic syslog grok pattern, you could use conditionals and regular expressions to test for lines that have IPs in them, and then further grok those fields. You'd just have to use that field name in stead of "message" in subsequent grok blocks.

---

<div class="post-metadata">

**Author:** ![theo.bot](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theo.bot/32/5739_2.png) [@theo.bot](https://discuss.elastic.co/u/theo.bot)\
**Post date:** [December 7, 2015, 10:13am UTC](https://discuss.elastic.co/t/syslog-additional-fields/36389/4 "2015-12-07T10:13:40Z")

</div>

Guys

Thanks a lot, I will test today

Kind regards

Theo

---

<div class="post-metadata">

**Author:** ![mhalatuituia](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)\
**Post date:** [March 28, 2017, 10:51am UTC](https://discuss.elastic.co/t/syslog-additional-fields/36389/5 "2017-03-28T10:51:51Z")

</div>

hi i have been trying for quite some time but i cannot get it to work .... here is my config ..

file \>\>\>\>\>\>\>\> 02-beat-input.conf  
input {  
beats {  
port =\> 5044  
ssl =\> true  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
udp {  
port =\> 5140  
type =\> "syslog"  
}

}  
file \>\>\>\>\>\>\>\>\>\>\>\>\>03-cisco-filter.conf

filter {  
grok {  
match =\> { "message" =\> "%{CISCOFW710001\_710002\_710003\_710005\_710006 %{WORD:protocol} (?:request|access) %{CISCO\_ACTION:action} from %{IP:src\_ip}/%{INT:src\_port} to %{DATA:dst\_interface}:%{IP:dst\_ip}/%{INT:dst\_port}" }  
}  
}  
# Parse the syslog severity and facility  
syslog\_pri { }  
dns {  
reverse =\> ["host"]  
action =\> "replace"  
}  
geoip {  
source =\> "src\_ip"  
target =\> "geoip"  
database =\> "/opt/logstash/GeoLiteCity.dat"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}  
mutate {  
convert =\> ["[geoip][coordinates]", "float"]  
}  
# do GeoIP lookup for the ASN/ISP information.  
geoip {  
database =\> "/opt/logstash/GeoIPASNum.dat"  
source =\> "src\_ip"  
}  
}  
~  
file \>\>\>\>\>\>\>\>\>\>\>\>\>\>10-syslog-filter.conf  
filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
syslog\_pri { }  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}

}  
file \>\>\>\>\>\>\>\>\>\>\>\>\>\> 30-elasticsearch-output.conf

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]

# sniffing =\> true

# manage\_template =\> false

# index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"

# document\_type =\> "%{[@metadata][type]}"

}  
stdout {  
codec =\> rubydebug  
}

}  
.... i have been trying al sort of thing for quite some time but could not make it to work ...  
I have several Cisco Devices which i want to send its log to this elk but i can't . i have this on my kibana which shows log is being shipped but i cant analyse base on source ip, port etc etc ...  
message:\<166\>32926208: ha-ir1: Mar 28 23:50:24: %FMANFP-6-IPACCESSLOGP: SIP0: fman\_fp\_image: list INCOMING-FILTER denied udp 81.221.15.0(45498) GigabitEthernet0/0/0-\> 202.134.25.220(53), 1 packet @version:1 @timestamp:March 28th 2017, 23:50:25.251 type:syslog host:10.254.36.190 tags:\_grokparsefailure syslog\_severity\_code:5 syslog\_facility\_code:1 syslog\_facility:user-level syslog\_severity:notice \_id:AVsUicjuYvvnRQWpC-6b \_type:syslog \_index:logstash-2017.0 .... appreciate someone would help out

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 28, 2017, 10:54am UTC](https://discuss.elastic.co/t/syslog-additional-fields/36389/6 "2017-03-28T10:54:03Z")

</div>

@mhalatuituia, please start a new thread for your issue.

---

<div class="post-metadata">

**Author:** ![mhalatuituia](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)\
**Post date:** [March 28, 2017, 7:47pm UTC](https://discuss.elastic.co/t/syslog-additional-fields/36389/7 "2017-03-28T19:47:22Z")

</div>

> [@Jackal9301](#):
>
> grok {  
> match =\> { "message", "%{SYSLOGTIMESTAMP} %{IPV4},%{BASE10NUM} %{BASE10NUM}: {BASE10NUM}: \*%{SYSLOGTIMESTAMP} %{NOTSPACE} %{PROG}: %{WORD} %{PROG} %{WORD} %{WORD} %{IPV4:offending\_ip}(%{BASE10NUM}) -\> %{IPV4}(%{BASE10NUM}),%{GREEDYDATA}" }  
> }

hi Jack  
i comment on your post with my config and you suggest i should start a new thread. Please share your idea about my idea where i wrong as i really need this to work for my situation ... thanks in advance for your time and support

---

<div class="post-metadata">

**Author:** ![mhalatuituia](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)\
**Post date:** [March 29, 2017, 7:06am UTC](https://discuss.elastic.co/t/syslog-additional-fields/36389/8 "2017-03-29T07:06:35Z")

</div>

@Christian_Dahlqvist any comment on the new thread ....

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:27am UTC](https://discuss.elastic.co/t/syslog-additional-fields/36389/9 "2017-07-06T04:27:29Z")

</div>


