# Crowdstrike logs parsing

**URL:** <https://community.graylog.org/t/crowdstrike-logs-parsing/12074>\
**Category:** Graylog Central (peer support)\
**Created:** [September 23, 2019, 1:59pm UTC](https://community.graylog.org/t/crowdstrike-logs-parsing/12074 "2019-09-23T13:59:37Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sevil](https://avatars.discourse-cdn.com/v4/letter/s/0ea827/32.png) [@Sevil](https://community.graylog.org/u/Sevil)\
**Post date:** [September 23, 2019, 1:59pm UTC](https://community.graylog.org/t/crowdstrike-logs-parsing/12074/1 "2019-09-23T13:59:37Z")

</div>

Hello Everyone,

I am working on parsing crowdstrike logs. I haven’t worked with graylog but I know how pipeline, grok patterns workes with graylog.  
Now I’m working with key-value, the following is the sample raw log from crowdstrike. IT would be a great help if you guys assist me to start with parsing.

CEF:0|CrowdStrike|FalconHost|1.0|validateEntitlementsHmac|validateEntitlementsHmac|1| cat=AuthActivityAuditEvent destinationTranslatedAddress=0.0.0.0 duser=Customer deviceProcessName=CrowdStrike Authentication cn3Label=Offset cn3=1118760 outcome=false deviceCustomDate1Label=Timestamp deviceCustomDate1=Sep 23 2019 09:52:59 rt=1569202779111

CEF:0|CrowdStrike|FalconHost|1.0|validateEntitlementsHmac|validateEntitlementsHmac|1| cat=AuthActivityAuditEvent destinationTranslatedAddress=1.1.1.1 duser=Customer deviceProcessName=CrowdStrike Authentication cn3Label=Offset cn3=1117240 outcome=false deviceCustomDate1Label=Timestamp deviceCustomDate1=Sep 22 2019 22:52:45 rt=1569211165063

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [September 23, 2019, 2:01pm UTC](https://community.graylog.org/t/crowdstrike-logs-parsing/12074/2 "2019-09-23T14:01:42Z")

</div>

that is a CEF message - you can use the CEF parsing rule plus a key-value rule to get all of that parsed.

---

<div class="post-metadata">

**Author:** ![Sevil](https://avatars.discourse-cdn.com/v4/letter/s/0ea827/32.png) [@Sevil](https://community.graylog.org/u/Sevil)\
**Post date:** [September 23, 2019, 2:14pm UTC](https://community.graylog.org/t/crowdstrike-logs-parsing/12074/3 "2019-09-23T14:14:42Z")

</div>

Thanks a lot Jan, Could you please advise any documentation or syntax to get start with.

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [September 23, 2019, 3:14pm UTC](https://community.graylog.org/t/crowdstrike-logs-parsing/12074/4 "2019-09-23T15:14:06Z")

</div>

I guess you try to fool me, right?

> I haven’t worked with graylog _ **but I know how pipeline, grok patterns workes with graylog** _.

> Could you please advise any documentation or syntax to get start with.

---

<div class="post-metadata">

**Author:** ![Sevil](https://avatars.discourse-cdn.com/v4/letter/s/0ea827/32.png) [@Sevil](https://community.graylog.org/u/Sevil)\
**Post date:** [September 23, 2019, 3:27pm UTC](https://community.graylog.org/t/crowdstrike-logs-parsing/12074/5 "2019-09-23T15:27:46Z")

</div>

My Apologies Jan. I mean to say documentation with examples will help me understand where I am going wrong.  
I new to graylog, whatever I know about pipelines, grok patterns i have learned in past few days.

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [September 24, 2019, 6:28am UTC](https://community.graylog.org/t/crowdstrike-logs-parsing/12074/6 "2019-09-24T06:28:37Z")

</div>

use the CEF function:

 ![grafik](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/1/1a1465f964f2b4119c9b56d39b21d599524de2e1.png)

plus a KV extractor like:

```auto
rule "extract message kv"
when
    has_field("message")
then
    // extract all key-value from "message" 
    set_fields(
                fields: 
                        key_value(
                            value: to_string($message.message), 
                            trim_value_chars: "\"",
                            trim_key_chars: "\"",
                            delimiters: " ",
                            kv_delimiters: "="
                            ),
            );

end

```

and you should write where you have problems with …

---

<div class="post-metadata">

**Author:** ![Sevil](https://avatars.discourse-cdn.com/v4/letter/s/0ea827/32.png) [@Sevil](https://community.graylog.org/u/Sevil)\
**Post date:** [October 2, 2019, 8:15pm UTC](https://community.graylog.org/t/crowdstrike-logs-parsing/12074/7 "2019-10-02T20:15:06Z")

</div>

Thanks a lot, Jan it worked for me.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [October 16, 2019, 8:15pm UTC](https://community.graylog.org/t/crowdstrike-logs-parsing/12074/8 "2019-10-16T20:15:06Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
