# Closer than Before ... WoW .. Cisco Log Processing

**URL:** <https://discuss.elastic.co/t/closer-than-before-wow-cisco-log-processing/81726>\
**Category:** Logstash\
**Created:** [April 9, 2017, 8:20pm UTC](https://discuss.elastic.co/t/closer-than-before-wow-cisco-log-processing/81726 "2017-04-09T20:20:33Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![mhalatuituia](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)\
**Post date:** [April 9, 2017, 8:20pm UTC](https://discuss.elastic.co/t/closer-than-before-wow-cisco-log-processing/81726/1 "2017-04-09T20:20:33Z")

</div>

I got this on my logstash.stdout but still No result found on Kibana ... Please anyone with a hint what still i miss i would really appreciate.  
Thanks in advance.

"message" =\> "\<183\>Apr 10 2017 09:41:01 ha-fw1 : %ASA-7-710005: TCP request discarded from 52.24.32.4/80 to outside:202.134.31.158/37391\n",  
"@version" =\> "1",  
"@timestamp" =\> "2017-04-09T20:41:01.000Z",  
"type" =\> "syslog",  
"host" =\> "10.254.36.252",  
"syslog\_pri" =\> "183",  
"timestamp" =\> "Apr 10 2017 09:41:01",  
"sysloghost" =\> "ha-fw1",  
"ciscotag" =\> "ASA-7-710005",  
"cisco\_message" =\> "TCP request discarded from 52.24.32.4/80 to outside:202.134.31.158/37391\n",  
"protocol" =\> "TCP",  
"action" =\> "discarded",  
"src\_ip" =\> "52.24.32.4",  
"src\_port" =\> "80",  
"dst\_interface" =\> "outside",  
"dst\_ip" =\> "202.134.31.158",  
"dst\_port" =\> "37391",  
"syslog\_severity\_code" =\> 7,  
"syslog\_facility\_code" =\> 22,  
"syslog\_facility" =\> "local6",  
"syslog\_severity" =\> "debug",  
"geoip" =\> {  
"ip" =\> "52.24.32.4",  
"country\_code2" =\> "US",  
"country\_code3" =\> "USA",  
"country\_name" =\> "United States",  
"continent\_code" =\> "NA",  
"region\_name" =\> "OR",  
"city\_name" =\> "Boardman",  
"postal\_code" =\> "97818",  
"latitude" =\> 45.86959999999999,  
"longitude" =\> -119.688,  
"dma\_code" =\> 810,  
"area\_code" =\> 541,  
"timezone" =\> "America/Los\_Angeles",  
"real\_region\_name" =\> "Oregon",  
"location" =\> [  
[0] -119.688,  
[1] 45.86959999999999  
],  
"number" =\> "AS16509",  
"asn" =\> "[Amazon.com](http://Amazon.com), Inc."  
},  
"tags" =\> [  
[0] "GeoIP",  
[1] "Whois"  
]  
}  
{  
"message" =\> "\<182\>Apr 10 2017 09:41:01 ha-fw1 : %ASA-6-305012: Teardown dynamic TCP translation from any:10.20.6.56/55043 to outside:202.134.31.158/52810 duration 0:00:00\n",  
"@version" =\> "1",  
"@timestamp" =\> "2017-04-09T20:41:01.000Z",  
"type" =\> "syslog",  
"host" =\> "10.254.36.252",  
"syslog\_pri" =\> "182",  
"timestamp" =\> "Apr 10 2017 09:41:01",  
"sysloghost" =\> "ha-fw1",  
"ciscotag" =\> "ASA-6-305012",  
"cisco\_message" =\> "Teardown dynamic TCP translation from any:10.20.6.56/55043 to outside:202.134.31.158/52810 duration 0:00:00\n",  
"action" =\> "Teardown",  
"xlate\_type" =\> "dynamic",  
"protocol" =\> "TCP",  
"src\_interface" =\> "any",  
"src\_ip" =\> "10.20.6.56",  
"src\_port" =\> "55043",  
"src\_xlated\_interface" =\> "outside",  
"src\_xlated\_ip" =\> "202.134.31.158",  
"syslog\_severity\_code" =\> 6,  
"syslog\_facility\_code" =\> 22,  
"syslog\_facility" =\> "local6",  
"syslog\_severity" =\> "informational"  
}  
^C  
root@fg-elk:/var/log/logstash#

---

<div class="post-metadata">

**Author:** ![mhalatuituia](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)\
**Post date:** [April 9, 2017, 9:34pm UTC](https://discuss.elastic.co/t/closer-than-before-wow-cisco-log-processing/81726/2 "2017-04-09T21:34:35Z")

</div>

FYI  
This is show when i set output to  
stdout { codec =\> rubydebug }

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 10, 2017, 3:34am UTC](https://discuss.elastic.co/t/closer-than-before-wow-cisco-log-processing/81726/3 "2017-04-10T03:34:51Z")

</div>

What does the rest of your config look like?

---

<div class="post-metadata">

**Author:** ![mhalatuituia](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)\
**Post date:** [April 10, 2017, 3:49am UTC](https://discuss.elastic.co/t/closer-than-before-wow-cisco-log-processing/81726/4 "2017-04-10T03:49:50Z")

</div>

i have only one file named logstash.conf. Here is its content

input {  
udp {  
port =\> 5140  
type =\> "cisco-fw"  
}  
}

filter {  
grok {  
match =\> ["message", "%{CISCO\_TAGGED\_SYSLOG} %{GREEDYDATA:cisco\_message}"]  
}

```
    # Extract fields from the each of the detailed message types
    # The patterns provided below are included in core of LogStash 1.4.2.
    grok {
            match => [
                    "cisco_message", "%{CISCOFW106001}",
                    "cisco_message", "%{CISCOFW106006_106007_106010}",
                    "cisco_message", "%{CISCOFW106014}",
                    "cisco_message", "%{CISCOFW106015}",
                    "cisco_message", "%{CISCOFW106021}",
                    "cisco_message", "%{CISCOFW106023}",
                    "cisco_message", "%{CISCOFW106100}",
                    "cisco_message", "%{CISCOFW110002}",
                    "cisco_message", "%{CISCOFW302010}",
                    "cisco_message", "%{CISCOFW302013_302014_302015_302016}",
                    "cisco_message", "%{CISCOFW302020_302021}",
                    "cisco_message", "%{CISCOFW305011}",
                    "cisco_message", "%{CISCOFW313001_313004_313008}",
                    "cisco_message", "%{CISCOFW313005}",
                    "cisco_message", "%{CISCOFW402117}",
                    "cisco_message", "%{CISCOFW402119}",
                    "cisco_message", "%{CISCOFW419001}",
                    "cisco_message", "%{CISCOFW419002}",
                    "cisco_message", "%{CISCOFW500004}",
                    "cisco_message", "%{CISCOFW602303_602304}",
                    "cisco_message", "%{CISCOFW710001_710002_710003_710005_710006}",
                    "cisco_message", "%{CISCOFW713172}",
                    "cisco_message", "%{CISCOFW733100}"
            ]
    }
   # Parse the syslog severity and facility
    syslog_pri { }

    geoip {
            add_tag => ["GeoIP"]
            database => "/opt/logstash/GeoLiteCity.dat"
            source => "src_ip"
    }

    if [geoip][city_name] == "" { mutate { remove_field => "[geoip][city_name]" } }
    if [geoip][continent_code] == "" { mutate { remove_field => "[geoip][continent_code]" } }
    if [geoip][country_code2] == "" { mutate { remove_field => "[geoip][country_code2]" } }
    if [geoip][country_code3] == "" { mutate { remove_field => "[geoip][country_code3]" } }
    if [geoip][country_name] == "" { mutate { remove_field => "[geoip][country_name]" } }
    if [geoip][latitude] == "" { mutate { remove_field => "[geoip][latitude]" } }
    if [geoip][longitude] == "" { mutate { remove_field => "[geoip][longitude]" } }
    if [geoip][postal_code] == "" { mutate { remove_field => "[geoip][postal_code]" } }
    if [geoip][region_name] == "" { mutate { remove_field => "[geoip][region_name]" } }
    if [geoip][time_zone] == "" { mutate { remove_field => "[geoip][time_zone]" } }

    # Gets the source IP whois information from the GeoIPASNum.dat flat file database
    geoip {
            add_tag => ["Whois"]
            database => "/opt/logstash/GeoIPASNum.dat"
            source => "src_ip"
    }

    # Parse the date
    date {
            match => ["timestamp",
                    "MMM dd HH:mm:ss",
                    "MMM d HH:mm:ss",
                    "MMM dd yyyy HH:mm:ss",
                    "MMM d yyyy HH:mm:ss"
            ]
    }

```

}  
output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
flush\_size =\> 1  
}  
stdout {  
codec =\> json  
}  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![bubba198](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bubba198/32/15866_2.png) [@bubba198](https://discuss.elastic.co/u/bubba198)\
**Post date:** [April 10, 2017, 4:31am UTC](https://discuss.elastic.co/t/closer-than-before-wow-cisco-log-processing/81726/5 "2017-04-10T04:31:33Z")

</div>

So just to be sure this comes out of an ASA via syslog yes? (Logging command in iOS)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 10, 2017, 5:31am UTC](https://discuss.elastic.co/t/closer-than-before-wow-cisco-log-processing/81726/6 "2017-04-10T05:31:57Z")

</div>

> [@mhalatuituia](#):
>
> index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}" document\_type =\> "%{[@metadata][type]}"

That won't work because you aren't creating those fields.

---

<div class="post-metadata">

**Author:** ![mhalatuituia](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)\
**Post date:** [April 10, 2017, 6:40am UTC](https://discuss.elastic.co/t/closer-than-before-wow-cisco-log-processing/81726/7 "2017-04-10T06:40:54Z")

</div>

Hi Boyan

Yes you right.

Thanks

---

<div class="post-metadata">

**Author:** ![mhalatuituia](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)\
**Post date:** [April 10, 2017, 6:41am UTC](https://discuss.elastic.co/t/closer-than-before-wow-cisco-log-processing/81726/8 "2017-04-10T06:41:29Z")

</div>

?Can you propose a working set

---

<div class="post-metadata">

**Author:** ![mhalatuituia](https://avatars.discourse-cdn.com/v4/letter/m/8c91f0/32.png) [@mhalatuituia](https://discuss.elastic.co/u/mhalatuituia)\
**Post date:** [April 10, 2017, 6:32pm UTC](https://discuss.elastic.co/t/closer-than-before-wow-cisco-log-processing/81726/9 "2017-04-10T18:32:23Z")

</div>

now i got this  
Field data loading is forbidden on [src\_fwuser

---

<div class="post-metadata">

**Author:** ![bubba198](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bubba198/32/15866_2.png) [@bubba198](https://discuss.elastic.co/u/bubba198)\
**Post date:** [April 20, 2017, 9:43pm UTC](https://discuss.elastic.co/t/closer-than-before-wow-cisco-log-processing/81726/10 "2017-04-20T21:43:17Z")

</div>

@mhalatuituia I don't have one; I figured some time ago that Splunk does a better job when it comes to ASA syslog and also ASA netflow exports; of course there's a price to pay there...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 18, 2017, 9:52pm UTC](https://discuss.elastic.co/t/closer-than-before-wow-cisco-log-processing/81726/11 "2017-05-18T21:52:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
