# Cisco AnyConnect VPN Integration

**URL:** <https://discuss.elastic.co/t/cisco-anyconnect-vpn-integration/327942>\
**Category:** Elastic Agent\
**Tags:** integrations\
**Created:** [March 17, 2023, 2:32pm UTC](https://discuss.elastic.co/t/cisco-anyconnect-vpn-integration/327942 "2023-03-17T14:32:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![MDimsey](https://avatars.discourse-cdn.com/v4/letter/m/e99b99/32.png) [@MDimsey](https://discuss.elastic.co/u/MDimsey)\
**Post date:** [March 17, 2023, 2:32pm UTC](https://discuss.elastic.co/t/cisco-anyconnect-vpn-integration/327942/1 "2023-03-17T14:32:34Z")

</div>

Hello,

My organization is looking to use the Elastic Agent as a replacement for running dedicated winlogbeat.exe agents on hosts. However, through winlogbeat we were able to collect logs from Cisco AnyConnect Security Mobility Client. There does not appear to be an existing integration that collect these logs.

Am I missing something? Is this in the works?

Thanks,  
Matt

---

<div class="post-metadata">

**Author:** ![VamPikmin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vampikmin/32/22367_2.png) [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Post date:** [March 20, 2023, 7:49am UTC](https://discuss.elastic.co/t/cisco-anyconnect-vpn-integration/327942/2 "2023-03-20T07:49:08Z")

</div>

Hi Matt,

So these logs were coming from the Windows Event Viewer log?

What sort of data were you collecting?

Just wondering at this point

---

<div class="post-metadata">

**Author:** ![ebeahan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ebeahan/32/78989_2.png) [@ebeahan](https://discuss.elastic.co/u/ebeahan)\
**Post date:** [March 22, 2023, 4:03pm UTC](https://discuss.elastic.co/t/cisco-anyconnect-vpn-integration/327942/3 "2023-03-22T16:03:33Z")

</div>

For your use of Winlogbeat today, are you collecting the AnyConnect logs through a Windows event log channel? Or some other means?

With Elastic Agent, you should still be able to collect from any custom Windows event log channels using the [Custom Windows Event Logs](https://docs.elastic.co/integrations/winlog) integration.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2023, 4:04pm UTC](https://discuss.elastic.co/t/cisco-anyconnect-vpn-integration/327942/4 "2023-04-19T16:04:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
