# Filebeat - Cisco Module doesn't accept logs from other sources that itsself

**URL:** <https://discuss.elastic.co/t/filebeat-cisco-module-doesnt-accept-logs-from-other-sources-that-itsself/232779>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 15, 2020, 9:21am UTC](https://discuss.elastic.co/t/filebeat-cisco-module-doesnt-accept-logs-from-other-sources-that-itsself/232779 "2020-05-15T09:21:14Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Moritz\_Kiesewetter](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/moritz_kiesewetter/32/51243_2.png) [@Moritz\_Kiesewetter](https://discuss.elastic.co/u/Moritz_Kiesewetter)\
**Post date:** [May 15, 2020, 9:21am UTC](https://discuss.elastic.co/t/filebeat-cisco-module-doesnt-accept-logs-from-other-sources-that-itsself/232779/1 "2020-05-15T09:21:14Z")

</div>

Hey Guys,

i've installed Filebeat on the 2 Data-Nodes in my Elk-Cluster.  
Some Information on my Cluster:  
Cluster Version: 7.6  
Filebeat Version: 7.7  
Hosts: CentOS 7

Now i want to send logs from Cisco Switches to this Cluster - i've activated the Cisco Plugin in Filebeat - and configured the cisco.yml file in /modules.d/:

```
- module: cisco
 #asa:
  # enabled: true

    # Set which input to use between syslog (default) or file.
    #var.input: syslog

    # The interface to listen to UDP based syslog traffic. Defaults to
    # localhost. Set to 0.0.0.0 to bind to all available interfaces.
    #var.syslog_host: localhost

    # The UDP port to listen for syslog traffic. Defaults to 9001.
    #var.syslog_port: 9001

    # Set the log level from 1 (alerts only) to 7 (include all messages).
    # Messages with a log level higher than the specified will be dropped.
    # See https://www.cisco.com/c/en/us/td/docs/security/asa/syslog/b_syslog/syslogs-sev-level.html
    #var.log_level: 7

 # ftd:
  # enabled: true

    # Set which input to use between syslog (default) or file.
    #var.input: syslog

    # The interface to listen to UDP based syslog traffic. Defaults to
    # localhost. Set to 0.0.0.0 to bind to all available interfaces.
    #var.syslog_host: localhost

    # The UDP port to listen for syslog traffic. Defaults to 9003.
    #var.syslog_port: 9003

    # Set the log level from 1 (alerts only) to 7 (include all messages).
    # Messages with a log level higher than the specified will be dropped.
    # See https://www.cisco.com/c/en/us/td/docs/security/firepower/Syslogs/b_fptd_syslog_guide/syslogs-sev-level.html
    #var.log_level: 7

  ios:
    enabled: true

    # Set which input to use between syslog (default) or file.
    var.input: syslog

    # The interface to listen to UDP based syslog traffic. Defaults to
    # localhost. Set to 0.0.0.0 to bind to all available interfaces.
    var.syslog_host: 0.0.0.0

    # The UDP port to listen for syslog traffic. Defaults to 9002.
    var.syslog_port: 9002

    # Set custom paths for the log files when using file input. If left empty,
    # Filebeat will choose the paths depending on your OS.
    #var.paths:

```

Now if i check with

> netstat -tulnp

I can see that the Port 9002 is bind to 0.0.0.0:

> udp6 0 0 :::9002 :::\*

If i check with TCP-Dump i can see that there are incoming connections on this port - but i cannot see any files in the Index.  
Now if i send an Error log via nc:

> nc X.X.X.X 9002 \< cisco.snip

from the host X.X.X.X itsself it works - but not from any other Server from the network?  
What did i do wrong?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 12, 2020, 9:21am UTC](https://discuss.elastic.co/t/filebeat-cisco-module-doesnt-accept-logs-from-other-sources-that-itsself/232779/2 "2020-06-12T09:21:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
