# Syslog firewall filter

**URL:** <https://discuss.elastic.co/t/syslog-firewall-filter/290220>\
**Category:** Logstash\
**Created:** [November 25, 2021, 9:55pm UTC](https://discuss.elastic.co/t/syslog-firewall-filter/290220 "2021-11-25T21:55:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![algira37](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/algira37/32/88482_2.png) [@algira37](https://discuss.elastic.co/u/algira37)\
**Post date:** [November 25, 2021, 9:55pm UTC](https://discuss.elastic.co/t/syslog-firewall-filter/290220/1 "2021-11-25T21:55:10Z")

</div>

Hello guys,

I'm very new in this field, I would like to filter this log from raspberry pi syslog firewall:  
`Nov 25 22:21:22 raspberrypi kernel: [26172.577441] DROP UNMATCHED IN-world:IN=eth0 OUT= MAC=01:00:5e:00:00:fb:aa:e7:68:57:d7:dc:08:00 SRC=192.168.100.9 DST=224.0.0.251 LEN=89 TOS=0x00 PREC=0x00 TTL=2 ID=31930 PROTO=UDP SPT=5353 DPT=5353 LEN=69`  
With gork. Unfortunately I don't know how to.  
But I would like to get this kind of json:  
{  
timestamp: xxxx.xx.xx  
source\_ip: x.x.x.x  
destination\_ip: x.x.x.x  
source\_port: xx  
destination\_port: xx  
action: DROP  
}  
I also would like to create a reverse DNS lookup for source\_ip .  
Please help!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 26, 2021, 1:12am UTC](https://discuss.elastic.co/t/syslog-firewall-filter/290220/2 "2021-11-26T01:12:25Z")

</div>

You could try

```
    grok {
        match => { "message" => "%{SYSLOGTIMESTAMP:[@metadata][ts]} %{WORD} %{WORD:level}: \[%{NUMBER:something:float}\] %{DATA:msg}:%{GREEDYDATA:[@metadata][restOfLine]}" }
    }
    date { match => ["[@metadata][ts]", "MMM dd HH:mm:ss" ] }
    kv { source => "[@metadata][restOfLine]" whitespace => strict }

```

which will produce

```
       "TTL" => "2",
       "DPT" => "5353",
        "ID" => "31930",
       "DST" => "224.0.0.251",
     "level" => "kernel",
       "SRC" => "192.168.100.9",
       "TOS" => "0x00",
      "PREC" => "0x00",
     "PROTO" => "UDP",
       "SPT" => "5353",
       "LEN" => [
    [0] "89",
    [1] "69"
],
       "msg" => "DROP UNMATCHED IN-world",
        "IN" => "eth0",
 "something" => 26172.577441,
       "MAC" => "01:00:5e:00:00:fb:aa:e7:68:57:d7:dc:08:00",

```

whitespace =\> strict is needed to correctly interpret the OUT= with no value.

You can use a [dns](https://www.elastic.co/guide/en/logstash/current/plugins-filters-dns.html) filter to do the PTR lookup.

---

<div class="post-metadata">

**Author:** ![algira37](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/algira37/32/88482_2.png) [@algira37](https://discuss.elastic.co/u/algira37)\
**Post date:** [November 26, 2021, 5:04pm UTC](https://discuss.elastic.co/t/syslog-firewall-filter/290220/3 "2021-11-26T17:04:48Z")

</div>

Thank you very much Badger! It's more than perfect.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 24, 2021, 5:05pm UTC](https://discuss.elastic.co/t/syslog-firewall-filter/290220/4 "2021-12-24T17:05:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
