# Cisco Duo Integration not working

**URL:** <https://discuss.elastic.co/t/cisco-duo-integration-not-working/292746>\
**Category:** Beats\
**Tags:** beats-module, elastic-agent\
**Created:** [December 22, 2021, 11:31pm UTC](https://discuss.elastic.co/t/cisco-duo-integration-not-working/292746 "2021-12-22T23:31:35Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![bm11100](https://avatars.discourse-cdn.com/v4/letter/b/b3f665/32.png) [@bm11100](https://discuss.elastic.co/u/bm11100)\
**Post date:** [December 22, 2021, 11:31pm UTC](https://discuss.elastic.co/t/cisco-duo-integration-not-working/292746/1 "2021-12-22T23:31:35Z")

</div>

Hello,

I'm looking to ingest Cisco Duo logs, I signed up for a trial of Duo to test this out, but when adding the information to the Fleet integration, no logs are coming through to Elastic. I've followed the instructions in the policy and attached my Duo Admin API with the correct permissions enabled as well as a screenshot of the Fleet policy.

My test is using Core Authentication Service: D231.3 and Admin Panel: D231.2, which is a bit newer than the versions used in the sample Fleet policy. Has anything changed with the Duo API integration that would prevent logs coming through?

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/f/effac8de7c33b371e5113d18acd19e6c2922f20a.png)

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/2/d25a985cd6b4a73ae7e53c4bb7a2046aa11595c3.png)

---

<div class="post-metadata">

**Author:** ![robert.gleaden](https://avatars.discourse-cdn.com/v4/letter/r/f6c823/32.png) [@robert.gleaden](https://discuss.elastic.co/u/robert.gleaden)\
**Post date:** [December 23, 2021, 1:31pm UTC](https://discuss.elastic.co/t/cisco-duo-integration-not-working/292746/2 "2021-12-23T13:31:03Z")

</div>

Having the same problem aswell!

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [December 23, 2021, 2:08pm UTC](https://discuss.elastic.co/t/cisco-duo-integration-not-working/292746/3 "2021-12-23T14:08:31Z")

</div>

Can u share any filebeat logs from the agent? I would put the agent in debug mode and retry the integration and see what shows up.

---

<div class="post-metadata">

**Author:** ![bm11100](https://avatars.discourse-cdn.com/v4/letter/b/b3f665/32.png) [@bm11100](https://discuss.elastic.co/u/bm11100)\
**Post date:** [December 23, 2021, 3:45pm UTC](https://discuss.elastic.co/t/cisco-duo-integration-not-working/292746/4 "2021-12-23T15:45:13Z")

</div>

Yeah here's a snip from the debug log

> Error creating runner from config: fail to unpack the set configuration

```auto
{"log.level":"debug","@timestamp":"2021-12-23T08:38:40.139-0700","log.logger":"processors","log.origin":{"file.name":"processors/processor.go","file.line":120},"message":"Generated new processors: add_fields={\"data_stream\":{\"dataset\":\"cisco_duo.auth\",\"namespace\":\"default\",\"type\":\"logs\"}}, add_fields={\"event\":{\"dataset\":\"cisco_duo.auth\"}}, add_fields={\"elastic_agent\":{\"id\":\"xxxx\",\"snapshot\":false,\"version\":\"7.15.2\"}}, add_fields={\"agent\":{\"id\":\"xxxx\"}}","service.name":"filebeat","ecs.version":"1.6.0"}
{"log.level":"error","@timestamp":"2021-12-23T08:38:40.139-0700","log.logger":"centralmgmt","log.origin":{"file.name":"cfgfile/list.go","file.line":99},"message":"Error creating runner from config: fail to unpack the set configuration: template: :1: function \"sprintf\" not defined accessing 'request.transforms.5.set.value' accessing 'request'","service.name":"filebeat","ecs.version":"1.6.0"}
{"log.level":"debug","@timestamp":"2021-12-23T08:38:40.139-0700","log.logger":"processors","log.origin":{"file.name":"processors/processor.go","file.line":120},"message":"Generated new processors: add_fields={\"data_stream\":{\"dataset\":\"cisco_duo.offline_enrollment\",\"namespace\":\"default\",\"type\":\"logs\"}}, add_fields={\"event\":{\"dataset\":\"cisco_duo.offline_enrollment\"}}, add_fields={\"elastic_agent\":{\"id\":\"xxxx\",\"snapshot\":false,\"version\":\"7.15.2\"}}, add_fields={\"agent\":{\"id\":\"xxxx\"}}","service.name":"filebeat","ecs.version":"1.6.0"}
{"log.level":"error","@timestamp":"2021-12-23T08:38:40.139-0700","log.logger":"centralmgmt","log.origin":{"file.name":"cfgfile/list.go","file.line":99},"message":"Error creating runner from config: fail to unpack the set configuration: template: :1: function \"sprintf\" not defined accessing 'request.transforms.2.set.value' accessing 'request'","service.name":"filebeat","ecs.version":"1.6.0"}
{"log.level":"debug","@timestamp":"2021-12-23T08:38:40.145-0700","log.logger":"processors","log.origin":{"file.name":"processors/processor.go","file.line":120},"message":"Generated new processors: add_fields={\"data_stream\":{\"dataset\":\"cisco_duo.summary\",\"namespace\":\"default\",\"type\":\"logs\"}}, add_fields={\"event\":{\"dataset\":\"cisco_duo.summary\"}}, add_fields={\"elastic_agent\":{\"id\":\"xxxx\",\"snapshot\":false,\"version\":\"7.15.2\"}}, add_fields={\"agent\":{\"id\":\"xxxx\"}}","service.name":"filebeat","ecs.version":"1.6.0"}
{"log.level":"error","@timestamp":"2021-12-23T08:38:40.145-0700","log.logger":"centralmgmt","log.origin":{"file.name":"cfgfile/list.go","file.line":99},"message":"Error creating runner from config: fail to unpack the set configuration: template: :1: function \"sprintf\" not defined accessing 'request.transforms.1.set.value' accessing 'request'","service.name":"filebeat","ecs.version":"1.6.0"}
{"log.level":"debug","@timestamp":"2021-12-23T08:38:40.145-0700","log.logger":"processors","log.origin":{"file.name":"processors/processor.go","file.line":120},"message":"Generated new processors: add_fields={\"data_stream\":{\"dataset\":\"cisco_duo.admin\",\"namespace\":\"default\",\"type\":\"logs\"}}, add_fields={\"event\":{\"dataset\":\"cisco_duo.admin\"}}, add_fields={\"elastic_agent\":{\"id\":\"xxxx\",\"snapshot\":false,\"version\":\"7.15.2\"}}, add_fields={\"agent\":{\"id\":\"xxxx\"}}","service.name":"filebeat","ecs.version":"1.6.0"}
{"log.level":"error","@timestamp":"2021-12-23T08:38:40.145-0700","log.logger":"centralmgmt","log.origin":{"file.name":"cfgfile/list.go","file.line":99},"message":"Error creating runner from config: fail to unpack the set configuration: template: :1: function \"sprintf\" not defined accessing 'request.transforms.2.set.value' accessing 'request'","service.name":"filebeat","ecs.version":"1.6.0"}

```

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [December 24, 2021, 5:51pm UTC](https://discuss.elastic.co/t/cisco-duo-integration-not-working/292746/5 "2021-12-24T17:51:01Z")

</div>

What version of Elasticsearch, kibana and agent are u using?

---

<div class="post-metadata">

**Author:** ![bm11100](https://avatars.discourse-cdn.com/v4/letter/b/b3f665/32.png) [@bm11100](https://discuss.elastic.co/u/bm11100)\
**Post date:** [December 26, 2021, 3:17pm UTC](https://discuss.elastic.co/t/cisco-duo-integration-not-working/292746/6 "2021-12-26T15:17:36Z")

</div>

Using v7.16.2 of ES and Kibana.

The agent is on 7.15.2.

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [December 26, 2021, 4:38pm UTC](https://discuss.elastic.co/t/cisco-duo-integration-not-working/292746/7 "2021-12-26T16:38:45Z")

</div>

That is your problem. The Cisco Duo integration requires 7.16.0+. You're in a loophole situation because kibana and Elasticsearch are at that version which is what it checks.

---

<div class="post-metadata">

**Author:** ![bm11100](https://avatars.discourse-cdn.com/v4/letter/b/b3f665/32.png) [@bm11100](https://discuss.elastic.co/u/bm11100)\
**Post date:** [December 27, 2021, 4:36pm UTC](https://discuss.elastic.co/t/cisco-duo-integration-not-working/292746/8 "2021-12-27T16:36:03Z")

</div>

Thanks! That worked.

It would be nice to specify the minimum agent version in the description or a pre-reqs section, and/or not allow the integration to be enabled with a version of agent it is not compatible with.

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [December 27, 2021, 5:23pm UTC](https://discuss.elastic.co/t/cisco-duo-integration-not-working/292746/9 "2021-12-27T17:23:46Z")

</div>

Its kinda expected that the version of the agent matches Elasticsearch/kibana which is why fleet server checks the version of kibana. Perhaps they could add additional checks when applying the policy to the agent as well.

---

<div class="post-metadata">

**Author:** ![robert.gleaden](https://avatars.discourse-cdn.com/v4/letter/r/f6c823/32.png) [@robert.gleaden](https://discuss.elastic.co/u/robert.gleaden)\
**Post date:** [December 30, 2021, 11:46am UTC](https://discuss.elastic.co/t/cisco-duo-integration-not-working/292746/10 "2021-12-30T11:46:24Z")

</div>

+1 Updating to 7.16.2 Agent & Elastic stack seems to be working now

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 27, 2022, 1:47pm UTC](https://discuss.elastic.co/t/cisco-duo-integration-not-working/292746/11 "2022-01-27T13:47:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
