# Fetching Cisco , Firewall logs from syslog-ng server

**URL:** <https://discuss.elastic.co/t/fetching-cisco-firewall-logs-from-syslog-ng-server/233951>\
**Category:** SIEM\
**Created:** [May 22, 2020, 6:59pm UTC](https://discuss.elastic.co/t/fetching-cisco-firewall-logs-from-syslog-ng-server/233951 "2020-05-22T18:59:24Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ajay\_Singh2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ajay_singh2/32/68920_2.png) [@Ajay\_Singh2](https://discuss.elastic.co/u/Ajay_Singh2)\
**Post date:** [May 22, 2020, 6:59pm UTC](https://discuss.elastic.co/t/fetching-cisco-firewall-logs-from-syslog-ng-server/233951/1 "2020-05-22T18:59:24Z")

</div>

I have a syslog-ng server which gathers data from Cisco Router, switches, netflow data and firewall related data .

The data is stored as flat files. Now, i am looking to send those to ELK SIEM .

I see that i can use filebeat and but no idea how can i set it up to fetch from a particular location and how to parse the data to make it SIEM compatible.

Also, do i need logstash to make the data SIEM compatible.

Thanks,

---

<div class="post-metadata">

**Author:** ![jamie.hynds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamie.hynds/32/84205_2.png) [@jamie.hynds](https://discuss.elastic.co/u/jamie.hynds)\
**Post date:** [May 25, 2020, 8:45am UTC](https://discuss.elastic.co/t/fetching-cisco-firewall-logs-from-syslog-ng-server/233951/2 "2020-05-25T08:45:52Z")

</div>

Hi @Ajay_Singh2, you can install Filebeat on your syslog-ng server to ship the data to Elastic SIEM in Elastic Common Schema format.

Once you install [Filebeat](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-installation.html) you can simply enable the [Cisco module](https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-module-cisco.html) to ship the data to Elastic. The module can be configured to read from a file path, e.g. /var/log/cisco-asa.

Logstash is not required to make the data SIEM compatible. Filebeat can ship the data directly, for use within Elastic SIEM.

---

<div class="post-metadata">

**Author:** ![Ajay\_Singh2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ajay_singh2/32/68920_2.png) [@Ajay\_Singh2](https://discuss.elastic.co/u/Ajay_Singh2)\
**Post date:** [May 25, 2020, 9:25am UTC](https://discuss.elastic.co/t/fetching-cisco-firewall-logs-from-syslog-ng-server/233951/3 "2020-05-25T09:25:21Z")

</div>

> [@jamie.hynds](#):
>
> nfigured to read from a fi

Hi @jamie.hynds

That makes sense, but i have lot of devices logging to the syslog-ng servers .  
Two questions i have here:

1. can i define the path separated by commas, or i can define line by line.
2. how will ELK get the hostname of the cisco device ?

Currently, folders generated are in below format:  
`/opt/syslog/<hostname>/<date>.log`

Thanks in Advance !!!!!!

---

<div class="post-metadata">

**Author:** ![jamie.hynds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamie.hynds/32/84205_2.png) [@jamie.hynds](https://discuss.elastic.co/u/jamie.hynds)\
**Post date:** [May 26, 2020, 8:44am UTC](https://discuss.elastic.co/t/fetching-cisco-firewall-logs-from-syslog-ng-server/233951/4 "2020-05-26T08:44:41Z")

</div>

1. You can define the paths line by line and wildcards are also supported (e.g. /ops/syslog/_/_.log). You can view some examples of filebeat.yml configs [here](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-configuration.html).

2. The Filebeat module will only parse the origin IP address within the Cisco syslog. A [DNS processor](https://www.elastic.co/guide/en/beats/filebeat/current/processor-dns.html) is available to perform DNS requests for hostnames, however this is not enabled by default.

---

<div class="post-metadata">

**Author:** ![tudor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tudor/32/3753_2.png) [@tudor](https://discuss.elastic.co/u/tudor)\
**Post date:** [May 26, 2020, 9:01am UTC](https://discuss.elastic.co/t/fetching-cisco-firewall-logs-from-syslog-ng-server/233951/5 "2020-05-26T09:01:05Z")

</div>

To add a suggestion for your second question, if the hostname is in the file path, Filebeat puts the path in the `log.file.path` field, and you can use the dissect processor in an Ingest Node pipeline to extract it from there.

---

<div class="post-metadata">

**Author:** ![Ajay\_Singh2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ajay_singh2/32/68920_2.png) [@Ajay\_Singh2](https://discuss.elastic.co/u/Ajay_Singh2)\
**Post date:** [May 29, 2020, 5:24am UTC](https://discuss.elastic.co/t/fetching-cisco-firewall-logs-from-syslog-ng-server/233951/6 "2020-05-29T05:24:32Z")

</div>

Thanks you @tudor @jamie.hynds,

I am waiting for my cisco admin to enable syslog and then i will test the solution out.

Another quick question regarding fortinet firewall. I have fortinet sending to syslog-ng , where Filebeat is installed. I see fortinet filebeat module is a x-pack and is not free.  
Is there any alternative way to use filebeat to ingest and parse fortinet firewall logs and make it SIEM comptiable. (also i dont have a logstash)

Thanks in Advance !!!!

---

<div class="post-metadata">

**Author:** ![jamie.hynds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamie.hynds/32/84205_2.png) [@jamie.hynds](https://discuss.elastic.co/u/jamie.hynds)\
**Post date:** [May 29, 2020, 2:48pm UTC](https://discuss.elastic.co/t/fetching-cisco-firewall-logs-from-syslog-ng-server/233951/7 "2020-05-29T14:48:11Z")

</div>

Fortinet is included under the Elastic Basic license, which is free. SIEM is included in this license also. You can view all the available Subscriptions [here](https://www.elastic.co/subscriptions). The out-of-the-box integrations are listed under the Data Ingest section of that doc.

---

<div class="post-metadata">

**Author:** ![Ajay\_Singh2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ajay_singh2/32/68920_2.png) [@Ajay\_Singh2](https://discuss.elastic.co/u/Ajay_Singh2)\
**Post date:** [May 31, 2020, 7:02am UTC](https://discuss.elastic.co/t/fetching-cisco-firewall-logs-from-syslog-ng-server/233951/9 "2020-05-31T07:02:48Z")

</div>

@jamie.hynds I have enabled x-pack on elasticSearch. How to translate that to Filebeat so that it can display x-pack modules ?

I have a standard SAAS subscription.

---

<div class="post-metadata">

**Author:** ![Ajay\_Singh2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ajay_singh2/32/68920_2.png) [@Ajay\_Singh2](https://discuss.elastic.co/u/Ajay_Singh2)\
**Post date:** [June 1, 2020, 9:04am UTC](https://discuss.elastic.co/t/fetching-cisco-firewall-logs-from-syslog-ng-server/233951/10 "2020-06-01T09:04:52Z")

</div>

@jamie.hynds I have downloaded fortinet module from GitHub. After ingestion, fields are not getting poplutated (fields mentioned in filebeat docs) and timestamp is not getting extracted.

Logs Sample:  
2019-09-11T07:11:08-04:00 10.201.31.3 date=2019-09-11 time=14:08:52 devname=test devid=abcd logid=0000000013 type=traffic subtype=forward ....

Do i need to add grok filters to extract timestamp and key value pair fields?

Sorry for silly questions, i am a splunk admin where add-on parse data ☹

Is there a way I can parse data without logstash ?

---

<div class="post-metadata">

**Author:** ![Ajay\_Singh2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ajay_singh2/32/68920_2.png) [@Ajay\_Singh2](https://discuss.elastic.co/u/Ajay_Singh2)\
**Post date:** [June 8, 2020, 10:49am UTC](https://discuss.elastic.co/t/fetching-cisco-firewall-logs-from-syslog-ng-server/233951/11 "2020-06-08T10:49:23Z")

</div>

> [@tudor](#):
>
> dissect processor in an Ingest Node pipeli

@tudor  
can you help me with the syntax , here is what i have:

```auto
PUT _ingest/pipeline/my_pipeline_id
{
  "description" : "describe pipeline",
  "processors" : [
    {
      "dissect" : {
        "tokenizer": "/opt/%{host.name}/",
        "field": "log.file.path"
      }
    }
  ]
}

```

I still see the localhost in host.name instead of the one it processes from log.file.path

I have ran this through Kibanna UI

---

<div class="post-metadata">

**Author:** ![Ajay\_Singh2](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ajay_singh2/32/68920_2.png) [@Ajay\_Singh2](https://discuss.elastic.co/u/Ajay_Singh2)\
**Post date:** [June 8, 2020, 1:18pm UTC](https://discuss.elastic.co/t/fetching-cisco-firewall-logs-from-syslog-ng-server/233951/12 "2020-06-08T13:18:31Z")

</div>

@tudor i finally got it:

```auto
PUT _ingest/pipeline/testpipeline
{
  "description" : "describe pipeline",
  "processors" : [
    {
      "dissect" : {
        "pattern": "/opt/%{host.name}/",
        "field": "log.file.path"
      }
    }
  ]
}

```

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2020, 1:18pm UTC](https://discuss.elastic.co/t/fetching-cisco-firewall-logs-from-syslog-ng-server/233951/13 "2020-07-06T13:18:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
