# Graylog v3.3 - simple search with numbers (usually) fail

**URL:** <https://community.graylog.org/t/graylog-v3-3-simple-search-with-numbers-usually-fail/17263>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules\
**Created:** [September 23, 2020, 9:46am UTC](https://community.graylog.org/t/graylog-v3-3-simple-search-with-numbers-usually-fail/17263 "2020-09-23T09:46:16Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![TansecMika](https://avatars.discourse-cdn.com/v4/letter/t/f4b2a3/32.png) [@TansecMika](https://community.graylog.org/u/TansecMika)\
**Post date:** [September 23, 2020, 9:46am UTC](https://community.graylog.org/t/graylog-v3-3-simple-search-with-numbers-usually-fail/17263/1 "2020-09-23T09:46:16Z")

</div>

I send logs from pfsense to graylog and am trying to find lines which block access to certain port, for example.

Log entries I have look like this:

full\_message  
\<134\>Sep 23 12:16:51 filterlog: 5,1000103483,em0,match,block,in,4,0x0,241,54321,0,none,6,tcp,40,[src ip],[dst ip],54615,80,0,SA,1245964053,2966902018,65535,

message  
filterlog: 5,1000103483,em0,match,block,in,4,0x0,241,54321,0,none,6,tcp,40,[src ip],[dst ip],54615,80,0,SA,1245964053,2966902018,65535,

But if I try to search for certain things, most of my searches simply don’t return anything. For example:

these work:  
source:“filterlog:” AND full\_message:(block AND “Sep 23 12:16:51” AND “1000103483”)  
source:“filterlog:” AND full\_message:(block AND “Sep 23 12:16:51” AND “SA”)

but these don’t work:  
source:“filterlog:” AND full\_message:(block AND “Sep 23 12:16:51” AND “80”)  
source:“filterlog:” AND full\_message:(block AND “445”)  
source:“filterlog:” AND full\_message:(block AND “241”)  
source:“filterlog:” AND full\_message:(block AND “0x0”)

So if I wanted to search for lines where access to port 445 was blocked, it doesn’t work.

I can’t understand what I’m doing wrong?? I even just updated to v3.3.5 to see if it was a bug that was fixed recently, but no help.

And secondary question related to same entries:  
I am sending those logs from pfsense using “remote rsyslog”. Does anybody know what I need to do to fix the “source” from one pfsense to something like “pfsense1” instead of (very annoying) “pfsense-module:”, which doesn’t even show which pfsense is actually sending them?

Thanks!

.mika

---

<div class="post-metadata">

**Author:** ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)\
**Post date:** [September 23, 2020, 12:29pm UTC](https://community.graylog.org/t/graylog-v3-3-simple-search-with-numbers-usually-fail/17263/2 "2020-09-23T12:29:40Z")

</div>

Best way if you want to search for values like port number and so on is to extract fields from message and search in extracted fields, like dst\_port:80

Check this nice article:

> **[No More Secrets: Logging Made Easy Through Graylog Part 7 - VDA Labs](https://vdalabs.com/2020/03/25/graylog-firewall-syslog/)**
>
> No More Secrets: Logging Made Easy Through Graylog Part 7 Logging is a important but often overlooked part of an organization’s security posture. Logging without organization, searchability, or reporting leads to data being missed. This a...

To fix source you can you this little pipeline rule, which replace `filterlog:` to ip address of sending device (uses graylog internal field `gl2_remote_ip`):

```auto
rule "Pfsense replace source by ip"
when
  has_field("source") and contains(to_string($message.source), "filterlog")
then
  set_field("source", to_string($message.gl2_remote_ip));
end

```

---

<div class="post-metadata">

**Author:** ![TansecMika](https://avatars.discourse-cdn.com/v4/letter/t/f4b2a3/32.png) [@TansecMika](https://community.graylog.org/u/TansecMika)\
**Post date:** [October 1, 2020, 5:27am UTC](https://community.graylog.org/t/graylog-v3-3-simple-search-with-numbers-usually-fail/17263/3 "2020-10-01T05:27:09Z")

</div>

Ah, thank you! And sorry for delay, your reply is appreciated. I shall read that article, probably useful in other cases as well… 🙂

I ended up setting up individual inputs for pfsenses and overriding the source there. That way I don’t have to update the rules if/when I enable new logging options there…

---

<div class="post-metadata">

**Author:** ![TansecMika](https://avatars.discourse-cdn.com/v4/letter/t/f4b2a3/32.png) [@TansecMika](https://community.graylog.org/u/TansecMika)\
**Post date:** [October 2, 2020, 11:26am UTC](https://community.graylog.org/t/graylog-v3-3-simple-search-with-numbers-usually-fail/17263/4 "2020-10-02T11:26:24Z")

</div>

But the original problem remains: if full\_message and message are in fact text strings, why searching for numeric values fail?

Is this one of those “it is what it is”-things?? 🙂

---

<div class="post-metadata">

**Author:** ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)\
**Post date:** [October 2, 2020, 12:46pm UTC](https://community.graylog.org/t/graylog-v3-3-simple-search-with-numbers-usually-fail/17263/5 "2020-10-02T12:46:50Z")

</div>

Graylog uses Elastic search’s standard analyzer to index words, it creates terms by which you can search. I doesn’t mean that all numbers and phases are analyzed as in original text. Analyzer and tokenizer in ES try to simplify them to terms to quick search. So your message with words/numbers separated by , is not analyzed as you expect, so you can’t search in it. For example, if values would be separated by space, it should by searchable easily.

> **[Analysis | Elasticsearch Reference \[6.8\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/6.8/analysis.html)**

  

> **[Standard Analyzer | Elasticsearch Reference \[6.8\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/6.8/analysis-standard-analyzer.html)**

  

> **[Index model — Graylog 3.3.5 documentation](https://docs.graylog.org/en/3.3/pages/configuration/index_model.html#index-set-configuration)**

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [October 16, 2020, 12:46pm UTC](https://community.graylog.org/t/graylog-v3-3-simple-search-with-numbers-usually-fail/17263/6 "2020-10-16T12:46:57Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
