# VMWare NSX Parsing

**URL:** <https://discuss.elastic.co/t/vmware-nsx-parsing/315054>\
**Category:** Logstash\
**Created:** [September 23, 2022, 8:16pm UTC](https://discuss.elastic.co/t/vmware-nsx-parsing/315054 "2022-09-23T20:16:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![groth](https://avatars.discourse-cdn.com/v4/letter/g/b487fb/32.png) [@groth](https://discuss.elastic.co/u/groth)\
**Post date:** [September 23, 2022, 8:16pm UTC](https://discuss.elastic.co/t/vmware-nsx-parsing/315054/1 "2022-09-23T20:16:43Z")

</div>

I'm currently working on a Logstash pipeline for VMWare NSX firewall logs coming in over syslog forwarding. Some of the ICMP logs have a couple numbers between the protocol name and the source and destination IPs that VMWare's documentation doesn't reference that I can see. My organization's VMWare guy has been less than helpful to say the least.

Example:

\<6\>1 2022-09-01T16:28:16.920Z redacted\_esx\_server\_name FIREWALL\_PKTLOG - - - INET match PASS 4133 IN 80 ICMP 11 0 10.128.251.19-\>10.20.128.109

4133 is the rule id and 80 is the packet length. Would anyone know what the 11 and 0 are?

I'd like to be able to make an intelligent decision on whether to map them to fields or not rather than just dropping them.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 23, 2022, 8:57pm UTC](https://discuss.elastic.co/t/vmware-nsx-parsing/315054/2 "2022-09-23T20:57:32Z")

</div>

> [@groth](#):
>
> ICMP 11 0

This means ICMP Type 11 Code 0 [[reference](https://www.iana.org/assignments/icmp-parameters/icmp-parameters.xhtml#icmp-parameters-codes-11)].

And from [VMWare documentation](https://docs.vmware.com/en/VMware-NSX-Data-Center-for-vSphere/6.4/com.vmware.nsx.logging.doc/GUID-6F9DC53E-222D-464B-8613-AB2D517CE5E3.html#GUID-6F9DC53E-222D-464B-8613-AB2D517CE5E3)

> For non-TCP connections (UDP, ICMP or other protocols), the reason for terminating a connection is only TIMEOUT.

I would say that you probably can ignore those fields.

---

<div class="post-metadata">

**Author:** ![groth](https://avatars.discourse-cdn.com/v4/letter/g/b487fb/32.png) [@groth](https://discuss.elastic.co/u/groth)\
**Post date:** [September 23, 2022, 9:18pm UTC](https://discuss.elastic.co/t/vmware-nsx-parsing/315054/3 "2022-09-23T21:18:42Z")

</div>

Thank you. Not all of the NSX logs that are being sent to me had them (... ICMP source\_ip...) so I didn't want to make any assumptions.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 21, 2022, 9:19pm UTC](https://discuss.elastic.co/t/vmware-nsx-parsing/315054/4 "2022-10-21T21:19:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
