Q: how do you parse out a word that might have a word space word combo?

Viewed 99

Almost have these logs nailed down but having a hard time with a section of the log that provides the fail2ban action. It is usually a single word, but sometimes it is two words with a space between them. I am not sure how to address this issue and greatly appreciate any assistance. I have done a fair amount of research but not found a definitive answer, even trying various solutions.

In these examples below, you will see Restore Ban, Ban, and Found. This is what I am trying to isolate.

Sample logs:

2021-10-20 19:50:39,638 fail2ban.actions        [31705]: NOTICE  [sshd] Restore Ban 68.183.15.177
2021-10-20 16:08:16,315 fail2ban.actions        [6428]: NOTICE  [sshd] Ban 141.98.10.121
2021-10-20 17:21:23,807 fail2ban.filter         [6428]: INFO    [sshd] Found 159.75.130.111 - 2021-10-20 17:21:23

Current grok:

fail2banRule01 %{date("yyyy-MM-dd HH:mm:ss,SSS"):Datetime}\s+fail2ban.%{word}\s+\[%{number:PID}\]\:\s+%{word:Level}\s+\[%{word:Jail}\]\s+%{word:ActionType}\s+%{ipv4:ClientIP}(\s+-\s+%{date("yyyy-MM-dd HH:mm:ss"):ActionDate})?

NOTE: This will be within Datadog's log processing structure.

1 Answers

Found the answer to the issue. Change from word type to data.

Here is the grok now:

fail2banRule01 %{date("yyyy-MM-dd HH:mm:ss,SSS"):Datetime}\s+fail2ban.%{word}\s+[%{number:PID}]:\s+%{word:Level}\s+[%{word:Jail}]\s+%{data:ActionType}\s+%{ipv4:ClientIP}(\s+-\s+%{date("yyyy-MM-dd HH:mm:ss"):ActionDate})?

Log that was an issue:

2021-10-20 19:50:39,638 fail2ban.actions        [31705]: NOTICE  [sshd] Restore Ban 68.183.15.177

Output using data:

{
  "Datetime": 1634759439638,
  "PID": 31705,
  "Level": "NOTICE",
  "Jail": "sshd",
  "ActionType": "Restore Ban",
  "ClientIP": "68.183.15.177"
}
Related