JOIN GRAYLOG FOR OUR

ANNUAL CONFERENCE

Thursday,
October 21, 2021
10am-5pm CT
REGISTER NOW

I need some GROK Assistance

I need some assistance figuring out how to use GROK to separate a Message into it’s pieces.

How do I break this log down? I am newb to GROK and am not even sure where to start.

Remote Desktop Services: Session logon succeeded:

User: Domain\Administrator
Session ID: 289
Source Network Address: 10.0.0.1

Hello,

I would first go to the message you need to create the extractors. at the end of the message there should be am arrow pointing down, I’ve highlight this in a red box below.
image

Then pick Grok Patterns.

image

This way you working with the message need for your Grok patterns.

Start off by using Graylogs default patterns and if they don’t work there is also this site to help create your patterns.

https://grokconstructor.appspot.com/do/match#result

Hope that helps

3 Likes