# Trying to grok a watchguard

**URL:** <https://discuss.elastic.co/t/trying-to-grok-a-watchguard/141733>\
**Category:** Logstash\
**Created:** [July 26, 2018, 10:17am UTC](https://discuss.elastic.co/t/trying-to-grok-a-watchguard/141733 "2018-07-26T10:17:31Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![L33T](https://avatars.discourse-cdn.com/v4/letter/l/dbc845/32.png) [@L33T](https://discuss.elastic.co/u/L33T)\
**Post date:** [July 26, 2018, 10:17am UTC](https://discuss.elastic.co/t/trying-to-grok-a-watchguard/141733/1 "2018-07-26T10:17:32Z")

</div>

Hi,

I`m trying to make sense when grokking syslog output from a watchguard. I`d like it to split into more fields than i`m actually getting e.g. port, source ip, destination ip etc etc etc... At present in my logstash conf i`m using:

input {  
tcp {  
port =\> 5140  
type =\> syslog  
}  
udp {  
port =\> 5140  
type =\> syslog  
}  
}  
filter {  
if [type] == "syslog" {  
syslog\_pri { }  
}

if [type] == "syslog"{  
mutate {  
gsub =\> [  
"message", "^(\<\b(?:[1-9][0-9]\*)\b\>\b(?:Jan(?:uary)?|Feb(?:ruary)?|Mar(?:ch)?|Apr(?:il)?|May|Jun(?:e)?|Jul(?:y)?|Aug(?:ust)?|Sep(?:tember)?|Oct(?:ober)?|Nov(?:ember)?|Dec(?:ember)?$  
]  
}  
}  
if [type] == "syslog" and [message] =~ "RT\_FLOW" {  
grok {  
match =\> { "message" =\> "\<%{POSINT:priority}\>(?:%{SYSLOGTIMESTAMP:timestamp}|%{TIMESTAMP\_ISO8601:timestamp8601}) (?:%{SYSLOGFACILITY} )?(?:%{SYSLOGHOST:logsource} )?%{SYSLOGPROG}: %{$  
overwrite =\> ["message"]  
}  
}  
else if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "\<%{POSINT:priority}\>(?:%{SYSLOGTIMESTAMP:timestamp}|%{TIMESTAMP\_ISO8601:timestamp8601}) +(?:%{SYSLOGFACILITY} )?(?:%{SYSLOGHOST:logsource} )?(?:afeb0 )?(?:%{$  
overwrite =\> ["message"]  
}  
}  
if [program] == "cron" {  
grok {  
match =\> { "message" =\> "(%{USER:user}) %{CRON\_ACTION:action} ( \*%{DATA:command})" }  
}  
}  
else if ([program] == "PFE\_FW\_SYSLOG\_IP" or ([program] == "/kernel" and [message] =~ "^FW: ")) {  
grok {  
match =\> { "message" =\> "FW: %{NOTSPACE:interface\_name} \*%{WORD:action} \*%{WORD:protocol\_name} %{IPV4:source\_address} %{IPV4:destination\_address} \*%{WORD:source\_port\_or\_type} \*%{WORD$  
}  
}  
}  
output {  
elasticsearch {  
hosts =\> ["elastic1:9201"]  
sniffing =\> true  
manage\_template =\> false  
}  
if [type] == "syslog" and "\_grokparsefailure" in [tags] {  
file { path =\> "/var/log/logstash/failed\_syslog\_events-%{+YYYY-MM-dd}" }  
}  
}

Any help would be great 🙂

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 26, 2018, 12:57pm UTC](https://discuss.elastic.co/t/trying-to-grok-a-watchguard/141733/2 "2018-07-26T12:57:46Z")

</div>

What does an input event look like?

---

<div class="post-metadata">

**Author:** ![L33T](https://avatars.discourse-cdn.com/v4/letter/l/dbc845/32.png) [@L33T](https://discuss.elastic.co/u/L33T)\
**Post date:** [July 26, 2018, 1:04pm UTC](https://discuss.elastic.co/t/trying-to-grok-a-watchguard/141733/3 "2018-07-26T13:04:03Z")

</div>

Sorry to sound daft, how do i gather one to add here?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2018, 1:04pm UTC](https://discuss.elastic.co/t/trying-to-grok-a-watchguard/141733/4 "2018-08-23T13:04:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
