telegraf GROK pattern matching issues

  • I have pfBlocker enabled with GEOIP blocking, and I've been able to get the DNSBL logs to parse and go into InfluxDB. The issue I'm h[0_1564446396094_sanatizedlogsample.csv](Uploading 0%) aving is I can't seem to get this to work for the ip_block.log and was hoping some GROK guru would be willing to give some advice.

    I've used and it says I have a valid GROK pattern, so not sure what I'm missing.

    My telegraf.conf entry is as follows, with sample data ( attached.

      files = ["/var/log/pfblockerng/ip_block.log"]
        measurement = "ipblock_log"
        patterns = ["^%{SYSLOGTIMESTAMP:timestamp},%{GREEDYDATA:tracker_id},%{WORD:interface},%{WORD:interface_name},%{WORD:action},%{WORD:ipversion},%{WORD:protocol_id},%{WORD:protocol},%{GREEDYDATA:src_ip},%{GREEDYDATA:dst_ip},%{GREEDYDATA:src_port>},%{GREEDYDATA:dst_port},%{WORD:dst_port_dir},%{WORD:country_code},%{WORD:alias_name},%{GREEDYDATA:ip_evaluated},%{WORD:feed_name},%{GREEDYDATA:resolved_hostname},%{WORD:client_hostname},%{WORD:asn},%{GREEDYDATA:hitormiss}"]
        timezone = "Local"
          value = "2"

    The target is InfluxDB,not sure if that makes a difference or not.

Log in to reply