Anyone with working pattern for this message
"message" => "<181>Apr 14 2017 23:00:41 ha-fw1 : %ASA-5-304001: src_ip Accessed URL 216.58.203.109:http://accounts.google.com/\n",
thanks in advance ....
have you tried any of the default cisco patterns that come with logstash
https://grokdebug.herokuapp.com/patterns# (firewall)
do you have working config ??
Hi again Eperry
Can you find any pattern for thie message type
%FMANFP-6-IPACCESSLOGP: SIP0: fman_fp_image: list INCOMING-FILTER permitted tcp 142.0.35.80(57821) GigabitEthernet0/0/0-> 202.134.24.106(25),
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.