Cisco asa module Drop events - help required

Hi Team ,

We are currently using Cisco asa module for capturing firewall logs. Is there any option in Cisco asa module to capture only logs with specific severity (eg: log.level: informational) and drop all other events.

Beats and Elasticsearch version : 7.9.0

Hi,
I think you can do it using the Drop event processor and not operator in condition section.

Thanks Talebi, i ill check this option and update here

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.