# Cisco Module arbitrary parse error with nearly identical messages

**URL:** <https://discuss.elastic.co/t/cisco-module-arbitrary-parse-error-with-nearly-identical-messages/214884>\
**Category:** Beats\
**Tags:** beats-module, filebeat\
**Created:** [January 13, 2020, 5:51pm UTC](https://discuss.elastic.co/t/cisco-module-arbitrary-parse-error-with-nearly-identical-messages/214884 "2020-01-13T17:51:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![arnau\_K](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arnau_k/32/45945_2.png) [@arnau\_K](https://discuss.elastic.co/u/arnau_K)\
**Post date:** [January 13, 2020, 5:51pm UTC](https://discuss.elastic.co/t/cisco-module-arbitrary-parse-error-with-nearly-identical-messages/214884/1 "2020-01-13T17:51:27Z")

</div>

Hello,

I want to use Filebeat to import directly into elasticsearch the logs from a cisco router, these logs were first stored via syslog in an Ubuntu 16.04 server.

However, I get this error message in the field `error.message` in aprox half of the events:

```auto
GoError: failed in processor.convert: conversion of field [event.sequence] to type [long] failed: unable to convert value [022084]: strconv.ParseInt: parsing "022084": invalid syntax

```

The weird part of this behavior is that the log lines are almost identical, for example:

This line produces the mentioned error:

```auto
Jan 13 18:12:31 RO-ROM-VPN-KYOSA 022084: Jan 13 18:12:35.141 LCY: %SEC-6-IPACCESSLOGP: list 101 denied tcp 120.131.176.111(7133) -> 170.257.123.53(7547), 1 packet  

```

This other line gets parsed well:

```auto
Jan 13 17:12:30 RO-ROM-VPN-KYOSA 021176: Jan 13 17:12:33.168 LCY: %SEC-6-IPACCESSLOGP: list 101 denied tcp 191.128.99.50(43651) -> 170.257.123.53(9943), 1 packet

```

These are the contents of the file `cisco.yml`.

```auto
- module: cisco
  ios:
    enabled: true
    var.input: file
    var.paths: ["/var/log/logs_cisco/RO-ROM-VPN-KYOSA/*.log"]

```

Have anyone else experimented the same behavior? Is this a known bug?

Best regards

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [January 13, 2020, 8:19pm UTC](https://discuss.elastic.co/t/cisco-module-arbitrary-parse-error-with-nearly-identical-messages/214884/2 "2020-01-13T20:19:26Z")

</div>

Hi @arnau_K, welcome to the Elastic community forums!

**Summary:** It looks like you've uncovered a bug. Thanks! I've created [https://github.com/elastic/beats/issues/15513](https://github.com/elastic/beats/issues/15513) to track it.

**Explanation:**  
Looking at the Cisco module source code, I believe this is where the failure is coming from:

> <https://github.com/elastic/beats/blob/43eb364aa32bbd9d8b44685432d4be26eb3a0a62/x-pack/filebeat/module/cisco/ios/config/pipeline.js#L98-L103>

Specifically, that bit of code tries to parse the sequence number string as an integer. It sees the leading `0` and tries to parse the string that follows as an octal (base 8) number. Since base 8 numbers can only have digits 0-7 in them, parsing of `022084` fails but parsing of `021176` succeeds.

I think the _intent_ here is to parse the sequence number as a decimal (base 10) number. So I believe this is a bug you've found. I've created [https://github.com/elastic/beats/issues/15513](https://github.com/elastic/beats/issues/15513) to track it.

Thanks,

Shaunak

---

<div class="post-metadata">

**Author:** ![arnau\_K](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arnau_k/32/45945_2.png) [@arnau\_K](https://discuss.elastic.co/u/arnau_K)\
**Post date:** [January 14, 2020, 8:51am UTC](https://discuss.elastic.co/t/cisco-module-arbitrary-parse-error-with-nearly-identical-messages/214884/3 "2020-01-14T08:51:24Z")

</div>

Hello @shaunak !

Thank you for the quick response. Do you think there is any work around to this problem? We were really interested in this functionality.

Best regards,

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 11, 2020, 8:51am UTC](https://discuss.elastic.co/t/cisco-module-arbitrary-parse-error-with-nearly-identical-messages/214884/4 "2020-02-11T08:51:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
