# Syslog events from Watchguard firewall not appearing

**URL:** <https://discuss.elastic.co/t/syslog-events-from-watchguard-firewall-not-appearing/247097>\
**Category:** Elastic Security\
**Created:** [September 1, 2020, 1:16pm UTC](https://discuss.elastic.co/t/syslog-events-from-watchguard-firewall-not-appearing/247097 "2020-09-01T13:16:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![finbarr996](https://avatars.discourse-cdn.com/v4/letter/f/db5fbb/32.png) [@finbarr996](https://discuss.elastic.co/u/finbarr996)\
**Post date:** [September 1, 2020, 1:16pm UTC](https://discuss.elastic.co/t/syslog-events-from-watchguard-firewall-not-appearing/247097/1 "2020-09-01T13:16:19Z")

</div>

Hi there,  
I have upgraded to 7.9 across the board and syslog events aren't showing up in security as they previously did in SEIM.

I am bringing these in via Logstash with a config file that reformats them, and I can see these records imported succesfully in Elastic - I have added a Kibana index for the appropriate data and I have added that index to the Security setting for Elastic indices, but no data turns up in the Security Overview pane. I have also enabled all the detection rules, except the ML ones (basic license).

When I go to Detections, I get the following error:

```auto
   Your visualisation has error(s)
   Data Fetch Failure
   Invalid regular expression: /\/: \ at end of pattern

```

I've not created any visualisations - everything is as it comes out of the box.  
I'm sure I'm not giving you enough information to assist me, so what else can I provide that will help us resolve this issue?

Thank you!  
John.

---

<div class="post-metadata">

**Author:** ![Frank\_Hassanabad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/frank_hassanabad/32/49255_2.png) [@Frank\_Hassanabad](https://discuss.elastic.co/u/Frank_Hassanabad)\
**Post date:** [September 1, 2020, 5:39pm UTC](https://discuss.elastic.co/t/syslog-events-from-watchguard-firewall-not-appearing/247097/2 "2020-09-01T17:39:01Z")

</div>

Hi @finbarr996,

What I think is going on is if you go to:

Stack management / Advanced settings

And look for the defaultIndex pattern for security solutions like below:

 ![Screen Shot 2020-09-01 at 11.33.31 AM](https://us1.discourse-cdn.com/elastic/original/3X/0/0/0017e894fa70fb5f4ebddf66fd2a73d86ebcc321.png)

Check to see if you have an extra `\` somewhere like my replicated version. In my replicated version I end up with the same type of errors you are seeing:

 ![Screen Shot 2020-09-01 at 11.33.37 AM](https://us1.discourse-cdn.com/elastic/original/3X/b/d/bd105a818c385a29c4a51eba98c47c4f912babe0.png)

---

<div class="post-metadata">

**Author:** ![finbarr996](https://avatars.discourse-cdn.com/v4/letter/f/db5fbb/32.png) [@finbarr996](https://discuss.elastic.co/u/finbarr996)\
**Post date:** [September 1, 2020, 6:50pm UTC](https://discuss.elastic.co/t/syslog-events-from-watchguard-firewall-not-appearing/247097/3 "2020-09-01T18:50:58Z")

</div>

Nicely spotted - there was an additional trailing comma, which when removed solved the problem - Thank you! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:12am UTC](https://discuss.elastic.co/t/syslog-events-from-watchguard-firewall-not-appearing/247097/4 "2022-11-04T08:12:07Z")

</div>


