Skip to content

Instantly share code, notes, and snippets.

Embed
What would you like to do?
Fortigate Firewall Logstash Grok filter
input {
syslog {
type => "fortigate"
port => 5001
}
}
filter {
if [type] == "fortigate" {
grok {
match => [ "message", "<(?<ruleID>.*)>(?<msg>.*)" ]
}
kv { source => "msg" }
geoip { source => "dst" }
}
}
output {
elasticsearch {
embedded => false
}
#stdout { codec => rubydebug }
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.