# Syslog filter for IP

**URL:** <https://discuss.elastic.co/t/syslog-filter-for-ip/263512>\
**Category:** Logstash\
**Created:** [February 7, 2021, 1:21am UTC](https://discuss.elastic.co/t/syslog-filter-for-ip/263512 "2021-02-07T01:21:33Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dandotwalker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dandotwalker/32/77517_2.png) [@dandotwalker](https://discuss.elastic.co/u/dandotwalker)\
**Post date:** [February 7, 2021, 1:21am UTC](https://discuss.elastic.co/t/syslog-filter-for-ip/263512/1 "2021-02-07T01:21:33Z")

</div>

Hi,

I am learning Elastic so I have set it up in my home to prepare for when we start designing it at work.

I have a simple set up where logstash is listening for syslog messages. It works great with most hosts but my router seems to not be sending syslog in the correct format at I get \_grokparsefailure from that host.

My router is 192.168.0.1 and I am trying to get anything that has that IP and not apply a filter like I do other things.

This is an example of what is output:

```auto
    {
    "@timestamp" => 2021-02-07T01:09:42.229Z,
          "host" => "192.168.0.1",
      "@version" => "1",
          "type" => "syslog",
       "message" => "<13> DHCPD: Recv REQUEST from 7A:1C:A2:5C:EF:54"
}

```

This is my config for this pipeline. I have commented out the normal filter and added a new filter as I am trying to get just 192.168.0.1. Please can you spot what I am doing wrong?

```auto
input {
  udp {
    port => 514
    type => syslog
  }
  tcp {
    port => 514
    type => syslog
  }
}

filter {
  if '%{host}' == "192.168.0.1" {
    grok{
      add_field => ['received_at', '%{@timestamp}']
      add_field => ['received_from', '%{host}']
      add_field => ['filter_used', 'only gw']
    }
    date {
      match => ['syslog_timestamp', 'MMM d HH:mm:ss', 'MMM dd HH:mm:ss']
    }
  }
# if [type] == 'syslog' and ['host'] != "192.168.0.1" {
# grok {
# match => { 'message' => '%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}' }
# add_field => ['received_at', '%{@timestamp}']
# add_field => ['received_from', '%{host}']
# }
# date {
# match => ['syslog_timestamp', 'MMM d HH:mm:ss', 'MMM dd HH:mm:ss']
# }
# }
}

output {
  elasticsearch { hosts => ['elasticsearch:9200'] }
  stdout { codec => rubydebug }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 7, 2021, 1:25am UTC](https://discuss.elastic.co/t/syslog-filter-for-ip/263512/2 "2021-02-07T01:25:43Z")

</div>

> [@dandotwalker](#):
>
> `if '%{host}' == "192.168.0.1" {`

That should be `if [host] == "192.168.0.1" {`

---

<div class="post-metadata">

**Author:** ![dandotwalker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dandotwalker/32/77517_2.png) [@dandotwalker](https://discuss.elastic.co/u/dandotwalker)\
**Post date:** [February 7, 2021, 9:28am UTC](https://discuss.elastic.co/t/syslog-filter-for-ip/263512/3 "2021-02-07T09:28:42Z")

</div>

Hi Badger,

Originally I had exactly that and it did not work either.

Thanks

---

<div class="post-metadata">

**Author:** ![dandotwalker](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dandotwalker/32/77517_2.png) [@dandotwalker](https://discuss.elastic.co/u/dandotwalker)\
**Post date:** [February 7, 2021, 9:57am UTC](https://discuss.elastic.co/t/syslog-filter-for-ip/263512/4 "2021-02-07T09:57:01Z")

</div>

Hi again,

It turns out my issue was the use of double quotes. This works for me...

```auto
filter {
  if [type] == 'syslog' and [host] != '192.168.0.1' {
    grok {
      match => { 'message' => '%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}' }
      add_field => ['received_at', '%{@timestamp}']
      add_field => ['received_from', '%{host}']
    }
    date {
      match => ['syslog_timestamp', 'MMM d HH:mm:ss', 'MMM dd HH:mm:ss']
    }
  }
}

```

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 7, 2021, 9:57am UTC](https://discuss.elastic.co/t/syslog-filter-for-ip/263512/5 "2021-03-07T09:57:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
