# Cisco FTD message extractor

**URL:** <https://community.graylog.org/t/cisco-ftd-message-extractor/33424>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules, cisco\
**Created:** [September 4, 2024, 10:33am UTC](https://community.graylog.org/t/cisco-ftd-message-extractor/33424 "2024-09-04T10:33:42Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![jonas\_ibk](https://avatars.discourse-cdn.com/v4/letter/j/a183cd/32.png) [@jonas\_ibk](https://community.graylog.org/u/jonas_ibk)\
**Post date:** [September 4, 2024, 10:33am UTC](https://community.graylog.org/t/cisco-ftd-message-extractor/33424/1 "2024-09-04T10:33:43Z")

</div>

Hey Guys,  
im trying to split following Cisco FTD message with grok extractors:

> %FTD-4-430003: EventPriority: Low, DeviceUUID: bawezh38-d5ewf-113c-8a08-adwde6ac, InstanceID: 3, FirstPacketSecond: 2024-09-04T10:06:25Z, ConnectionID: 21556, AccessControlRuleAction: Block, AccessControlRuleReason: SSL Block, SrcIP: 161.23.161.5, DstIP: 30.193.157.68, SrcPort: 62123, DstPort: 123, Protocol: tcp, IngressInterface: inside, EgressInterface: outside, IngressZone: inside, EgressZone: outside, IngressVRF: Global, EgressVRF: Global, ACPolicy: HDL, AccessControlRuleName: Web, Prefilter Policy: PreFilter\_Std, Client: SSL client, ApplicationProtocol: HTTPS, WebApplication: Azure Authentication Service, ConnectionDuration: 0, InitiatorPackets: 3, ResponderPackets: 3, InitiatorBytes: 462, ResponderBytes: 2934, NAPPolicy: Balanced Security and Connectivity, SSLPolicy: SSL\_Std, SSLRuleName: Block\_unwanted, SSLFlowStatus: Success, SSLCipherSuite: TLS\_ECDHE\_RSA\_WITH\_AES\_256\_GCM\_SHA384, SSLCertificate: 7b85lk085abc854ecdd16d8ea2813658bbee187b, SSLVersion: TLSv1.2, SSLServerCertStatus: Valid, SSLActualAction: Block, SSLExpectedAction: Block, SSLSessionID: fbe30bca1387f700aa03865d4da8bc7836f571ed850ecda01e8e03931cf63cfc, URL: [https://login.live.com](https://login.live.com), NAT\_InitiatorPort: 62453, NAT\_ResponderPort: 441, NAT\_InitiatorIP: 154.78.20.232, NAT\_ResponderIP: 31.195.194.68, EVE\_Process: zscaler tunnel, EVE\_ProcessConfidencePct: 44, EVE\_ThreatConfidencePct: 0, EVE\_ThreatConfidenceIndex: 1, ClientAppDetector: AppID

**3. What steps have you already taken to try and solve the problem?**

My Problem are not the grok patterns, i use Grok Debugger and the splitting works perfectly, even in the simulation in graylog, it works. But as soon as i save the extractor, the message stops apearing in my Stream. Even more confusing is, when i only extract the SrcIP with grok, it works, but as soon as i try to extract more from the message, new messages stop coming in.

I already tried old extractors, from old posts, but they are all 5-8 years old and dont work for me.

I also tried this Pipeline rule:  
https://community.graylog.org/t/creating-a-log-extractor-for-key-value-key-value-logs/20820/2  
it’s also not working, i can see that the messages are being put through the pipeline, but dont appear in the Stream.

**4. How can the community help?**

how do you guys extract cisco logs, do you have working pipeline Rules? Or are you using Extractors? I am having the same problems with splitting my Netscaler messages. It’s obviously some step i am missing, please help 😃

---

<div class="post-metadata">

**Author:** ![Wine\_Merchant](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/wine_merchant/32/14596_2.png) [@Wine\_Merchant](https://community.graylog.org/u/Wine_Merchant)\
**Post date:** [September 4, 2024, 11:04am UTC](https://community.graylog.org/t/cisco-ftd-message-extractor/33424/2 "2024-09-04T11:04:39Z")

</div>

Hello @jonas_ibk,

Best to stick with pipelines rules.

The below rule appears to work on the message you provided, do you see any parsing errors within your /var/log/graylog/server.log file?

```auto
rule "Key Value"
when
true
then

set_fields(
   fields:key_value(
   value: to_string($message.message),
   delimiters:",",
   kv_delimiters:":"
)
);

```

---

<div class="post-metadata">

**Author:** ![jonas\_ibk](https://avatars.discourse-cdn.com/v4/letter/j/a183cd/32.png) [@jonas\_ibk](https://community.graylog.org/u/jonas_ibk)\
**Post date:** [September 5, 2024, 9:34am UTC](https://community.graylog.org/t/cisco-ftd-message-extractor/33424/3 "2024-09-05T09:34:36Z")

</div>

Hey, firstly thanks for your reply @Wine_Merchant ,

i tried pipeline rules and they all work in the simulation, i tried your rule and the same problem arised, it split the message like i want but the messages stop showing up in the Stream.

I looked into the server file and found an errorr:

 ![error1](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/b/b/bb7e9fb15c4cb8bc6c6a1fa194611e4b8e98022c.jpeg)

It was the same type of message from cisco ftd.

i was just trying to extract the DstIP with Grok pattern (DstIP: %{IPV4:Dst\_IP}), im not sure how to fix the wrong date format, do you know how?

Edit: I just turned on your pipeline rule and the same error occurred.

---

<div class="post-metadata">

**Author:** ![Wine\_Merchant](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/wine_merchant/32/14596_2.png) [@Wine\_Merchant](https://community.graylog.org/u/Wine_Merchant)\
**Post date:** [September 5, 2024, 10:14am UTC](https://community.graylog.org/t/cisco-ftd-message-extractor/33424/4 "2024-09-05T10:14:40Z")

</div>

The error point to an issue with the date failing to process, are these messages arriving on a raw input and if no extractors or pipelines are enabled do you still see the error in the logs?

---

<div class="post-metadata">

**Author:** ![jonas\_ibk](https://avatars.discourse-cdn.com/v4/letter/j/a183cd/32.png) [@jonas\_ibk](https://community.graylog.org/u/jonas_ibk)\
**Post date:** [September 5, 2024, 10:24am UTC](https://community.graylog.org/t/cisco-ftd-message-extractor/33424/5 "2024-09-05T10:24:52Z")

</div>

these messages are coming through a Linux-Syslog Input and without anything enabled the error does not occurr

---

<div class="post-metadata">

**Author:** ![Wine\_Merchant](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/wine_merchant/32/14596_2.png) [@Wine\_Merchant](https://community.graylog.org/u/Wine_Merchant)\
**Post date:** [September 5, 2024, 10:42am UTC](https://community.graylog.org/t/cisco-ftd-message-extractor/33424/6 "2024-09-05T10:42:38Z")

</div>

Just ran through a quick test sending your provided message to a syslog TCP input via the below

`echo -e "%FTD-4-430003: EventPriority: Low, DeviceUUID: bawezh38-d5ewf-113c-8a08-adwde6ac, InstanceID: 3, FirstPacketSecond: 2024-09-04T10:06:25Z, ConnectionID: 21556, AccessControlRuleAction: Block, AccessControlRuleReason: SSL Block, SrcIP: 161.23.161.5, DstIP: 30.193.157.68, SrcPort: 62123, DstPort: 123, Protocol: tcp, IngressInterface: inside, EgressInterface: outside, IngressZone: inside, EgressZone: outside, IngressVRF: Global, EgressVRF: Global, ACPolicy: HDL, AccessControlRuleName: Web, Prefilter Policy: PreFilter_Std, Client: SSL client, ApplicationProtocol: HTTPS, WebApplication: Azure Authentication Service, ConnectionDuration: 0, InitiatorPackets: 3, ResponderPackets: 3, InitiatorBytes: 462, ResponderBytes: 2934, NAPPolicy: Balanced Security and Connectivity, SSLPolicy: SSL_Std, SSLRuleName: Block_unwanted, SSLFlowStatus: Success, SSLCipherSuite: TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, SSLCertificate: 7b85lk085abc854ecdd16d8ea2813658bbee187b, SSLVersion: TLSv1.2, SSLServerCertStatus: Valid, SSLActualAction: Block, SSLExpectedAction: Block, SSLSessionID: fbe30bca1387f700aa03865d4da8bc7836f571ed850ecda01e8e03931cf63cfc, URL: https://login.live.com, NAT_InitiatorPort: 62453, NAT_ResponderPort: 441, NAT_InitiatorIP: 154.78.20.232, NAT_ResponderIP: 31.195.194.68, EVE_Process: zscaler tunnel, EVE_ProcessConfidencePct: 44, EVE_ThreatConfidencePct: 0, EVE_ThreatConfidenceIndex: 1, ClientAppDetector: AppID" | nc -w 1 192.168.69.3 2020`

I have one pipeline with the rule provided earlier attached to the stream

 ![Screenshot 2024-09-05 at 11.39.31](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/f/9/f992616ee8e5953be051a6795235d7714685ec8b.png)

And with this the messages are split into key values

 ![Screenshot 2024-09-05 at 11.38.59](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/7/e/7e19d4ebaf1396d4ad74b5bc623689425586defd.png)

Is this setup the same as what you are working with?

---

<div class="post-metadata">

**Author:** ![jonas\_ibk](https://avatars.discourse-cdn.com/v4/letter/j/a183cd/32.png) [@jonas\_ibk](https://community.graylog.org/u/jonas_ibk)\
**Post date:** [September 5, 2024, 10:46am UTC](https://community.graylog.org/t/cisco-ftd-message-extractor/33424/7 "2024-09-05T10:46:16Z")

</div>

its syslog UDP sorry if i left that out, but other than that, yes

---

<div class="post-metadata">

**Author:** ![Wine\_Merchant](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/wine_merchant/32/14596_2.png) [@Wine\_Merchant](https://community.graylog.org/u/Wine_Merchant)\
**Post date:** [September 5, 2024, 11:50am UTC](https://community.graylog.org/t/cisco-ftd-message-extractor/33424/8 "2024-09-05T11:50:03Z")

</div>

Gave it a run through with a syslog UDP input just in case but appears the same, what if you try using a raw UDP on the same port and then implementing the pipelines?

---

<div class="post-metadata">

**Author:** ![jonas\_ibk](https://avatars.discourse-cdn.com/v4/letter/j/a183cd/32.png) [@jonas\_ibk](https://community.graylog.org/u/jonas_ibk)\
**Post date:** [September 5, 2024, 11:53am UTC](https://community.graylog.org/t/cisco-ftd-message-extractor/33424/9 "2024-09-05T11:53:57Z")

</div>

i have to run it by some coworkers, but i will try that 😃 , will probably get back to you

---

<div class="post-metadata">

**Author:** ![jonas\_ibk](https://avatars.discourse-cdn.com/v4/letter/j/a183cd/32.png) [@jonas\_ibk](https://community.graylog.org/u/jonas_ibk)\
**Post date:** [September 12, 2024, 10:29am UTC](https://community.graylog.org/t/cisco-ftd-message-extractor/33424/10 "2024-09-12T10:29:22Z")

</div>

So changing the Input did not change anything, the messages still do not appear in the stream after applying the rule to the pipeline. But in the simulation the message is splitted perfectly in key value pairs. it seems like the messages are not routed back into the stream.

i even made a new rule for the latest stage, saying “Route message to stream” and sending it to the same or another stream, both didnt work.

Any more ideas on how to slove this?

---

<div class="post-metadata">

**Author:** ![Wine\_Merchant](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/wine_merchant/32/14596_2.png) [@Wine\_Merchant](https://community.graylog.org/u/Wine_Merchant)\
**Post date:** [September 12, 2024, 10:40am UTC](https://community.graylog.org/t/cisco-ftd-message-extractor/33424/11 "2024-09-12T10:40:32Z")

</div>

What does the processing order look like with your system, reference below

 ![Screenshot 2024-09-12 at 11.34.46](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/7/5/75034720b3d550cc5ed156a3e3fd82bf1ff87b03.png)

Are you still only seeing errors in the server log when you have the stream connected to a pipeline?

There are no rules within the pipeline that attempt to format the date?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [September 26, 2024, 10:40am UTC](https://community.graylog.org/t/cisco-ftd-message-extractor/33424/12 "2024-09-26T10:40:45Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
