# Converting Cisco Module

**URL:** <https://discuss.elastic.co/t/converting-cisco-module/206916>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 7, 2019, 7:45am UTC](https://discuss.elastic.co/t/converting-cisco-module/206916 "2019-11-07T07:45:05Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![VamPikmin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vampikmin/32/22367_2.png) [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Post date:** [November 7, 2019, 7:45am UTC](https://discuss.elastic.co/t/converting-cisco-module/206916/1 "2019-11-07T07:45:05Z")

</div>

I'm learning to use filebeat, I was wondering if there is a way to convert the ingest pipeline from elasticsearch to logstash config

I've had a look here  
[https://www.elastic.co/guide/en/logstash/current/ingest-converter.html](https://www.elastic.co/guide/en/logstash/current/ingest-converter.html)  
Can't really find a json for Cisco module in filebeat

Should I be able to copy this to a logstash conf?

```
curl -XGET localhost:9200/_ingest/pipeline?pretty
filebeat-7.4.2-cisco-ftd-asa-ftd-pipeline" : {
    "description" : "Pipeline for Cisco FTD logs",
..truncated

```

I have also tried to send output directly to elasticsearch but for some reason the timestamp is in the future.

Running 7.4.2 on Ubuntu 18.04

Thanks

Is there a reason why I can't install the Cisco ASA dashboard when I install through the linux filebeat from the server

It only works if i Install from a windows version of filebeat???

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [November 7, 2019, 9:36pm UTC](https://discuss.elastic.co/t/converting-cisco-module/206916/2 "2019-11-07T21:36:38Z")

</div>

Hi @VamPikmin,

I don't know much about the ingest converter, but in principle it should be possible to use the ingest pipeline you are getting with `curl`. You cannot find the json pipeline in the filebeat repository because some pipelines, including the Cisco ones are developed in YAML format, for readability and improved maintainability.

> [@VamPikmin](#):
>
> I have also tried to send output directly to elasticsearch but for some reason the timestamp is in the future.

If you are not using UTC this is probably related to an issue with timezones we had in some modules. This will be solved in 7.5.0 (see [Some filebeat modules incorrectly parse timestamps · Issue #13877 · elastic/beats · GitHub](https://github.com/elastic/beats/issues/13877)).

> [@VamPikmin](#):
>
> Is there a reason why I can't install the Cisco ASA dashboard when I install through the linux filebeat from the server
> 
> It only works if i Install from a windows version of filebeat???

It should work the same with Linux or Windows following [these instructions](https://www.elastic.co/guide/en/beats/filebeat/7.4/load-kibana-dashboards.html).

---

<div class="post-metadata">

**Author:** ![VamPikmin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vampikmin/32/22367_2.png) [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Post date:** [November 7, 2019, 10:44pm UTC](https://discuss.elastic.co/t/converting-cisco-module/206916/3 "2019-11-07T22:44:49Z")

</div>

Hi @jsoriano

Thanks for your help, I'm not using UTC so that makes sense now, will look into it  
`08:39:48.249 AEDT Fri Nov 8 2019`

Once I've used the -e switch in filebeat I saw why it wasn't being installed

`2019-11-08T09:25:52.456+1100	ERROR	fileset/modules.go:125	Not loading modules. Module directory not found: /usr/share/filebeat/bin/module`

Once I added --path.home /usr/share/filebeat/ it installed okay

It seems ingest converter doesn't support painless script and I _think_ I see it in the cisco asa pipeline

Thanks for the explanation about the pipelines, do you have any suggestions on how to proceed

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [November 9, 2019, 11:56pm UTC](https://discuss.elastic.co/t/converting-cisco-module/206916/4 "2019-11-09T23:56:57Z")

</div>

> [@VamPikmin](#):
>
> It seems ingest converter doesn't support painless script and I _think_ I see it in the cisco asa pipeline
> 
> Thanks for the explanation about the pipelines, do you have any suggestions on how to proceed

I think that you could try to remove the unsupported parts of the pipeline and manually migrate them after the conversion.

---

<div class="post-metadata">

**Author:** ![VamPikmin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vampikmin/32/22367_2.png) [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Post date:** [November 11, 2019, 1:59am UTC](https://discuss.elastic.co/t/converting-cisco-module/206916/5 "2019-11-11T01:59:42Z")

</div>

Thanks @jsoriano

I've also tried to test the filebeat IIS module and almost every single log was not being parsed correctly, so I've decided to go with logstash again and create my own patterns.

I was hoping it would just work since it's a Windows server 2012 but things are never simple

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [November 11, 2019, 3:53pm UTC](https://discuss.elastic.co/t/converting-cisco-module/206916/6 "2019-11-11T15:53:21Z")

</div>

There are [some issues](https://github.com/elastic/beats/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+IIS+label%3Afilebeat) reported for the IIS module for Filebeat, including one ([#13799](https://github.com/elastic/beats/issues/13799)) about supporting more log formats. It'd be great if you could provide there some of example lines of the logs you see that are not being correctly parsed. Thanks!

---

<div class="post-metadata">

**Author:** ![VamPikmin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vampikmin/32/22367_2.png) [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Post date:** [November 11, 2019, 11:59pm UTC](https://discuss.elastic.co/t/converting-cisco-module/206916/7 "2019-11-11T23:59:46Z")

</div>

Thanks for all your help @jsoriano  
There's some great examples there that will come in handy

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 9, 2019, 11:59pm UTC](https://discuss.elastic.co/t/converting-cisco-module/206916/8 "2019-12-09T23:59:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
