# Filebeat Cisco module Nexus fileset dissect\_parsing\_error flag

**URL:** https://discuss.elastic.co/t/filebeat-cisco-module-nexus-fileset-dissect-parsing-error-flag/340548
**Category:** Beats
**Tags:** beats-module, filebeat
**Created:** [August 10, 2023, 10:27am UTC](https://discuss.elastic.co/t/filebeat-cisco-module-nexus-fileset-dissect-parsing-error-flag/340548 "2023-08-10T10:27:52Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![obol89](https://avatars.discourse-cdn.com/v4/letter/o/f0a364/32.png) [@obol89](https://discuss.elastic.co/u/obol89)
#### Post date: [August 10, 2023, 10:27am UTC](https://discuss.elastic.co/t/filebeat-cisco-module-nexus-fileset-dissect-parsing-error-flag/340548/1 "2023-08-10T10:27:52Z")

</div>

I'm trying to use Filebeat with Cisco module and Nexus fileset, but it seems like these logs aren't parsed properly.  
In every document I see - `dissect_parsing_error` in `log.flags`.  
It looks like that:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/5/a59555aede7c904c911844730be4b21443adcafc.png)

filebeat version

```auto
filebeat version 8.4.3 (amd64), libbeat 8.4.3 [c2f2aba479653563dbaabefe0f86f5579708ec94 built 2022-09-27 15:24:56 +0000 UTC]

```

`cisco.yml` module config:

```auto
nexus:
    enabled: true

    # Set which input to use between udp (default), tcp or file.
    var.input: udp
    var.syslog_host: 0.0.0.0
    var.syslog_port: 514

```

Cisco Nexus config:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/a/0ae4d55a7330f2cd3b8705c33b2c1e6ebc296a81.png)

I would say, it is very similar or the same issue as on closed topic here - [Filebeat Cisco Module Nexus dissect\_parsing\_error](https://discuss.elastic.co/t/filebeat-cisco-module-nexus-dissect-parsing-error/265662)

---

<div class="post-metadata">

### Author: ![jamie.hynds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamie.hynds/32/84205_2.png) [@jamie.hynds](https://discuss.elastic.co/u/jamie.hynds)
#### Post date: [August 15, 2023, 10:01am UTC](https://discuss.elastic.co/t/filebeat-cisco-module-nexus-fileset-dissect-parsing-error-flag/340548/2 "2023-08-15T10:01:04Z")

</div>

Hi @obol89 - we recently released an updated integration for Nexus events via Elastic Agent, which will likely resolve the parsing errors you're running into. It also includes improved ECS mappings and several dashboards. Are you in a position to use the Elastic Agent integration rather than the Filebeat module?

> **[Cisco Nexus | Documentation](https://docs.elastic.co/integrations/cisco_nexus)**
>
> Collect logs from Cisco Nexus with Elastic Agent.

---

<div class="post-metadata">

### Author: ![obol89](https://avatars.discourse-cdn.com/v4/letter/o/f0a364/32.png) [@obol89](https://discuss.elastic.co/u/obol89)
#### Post date: [August 15, 2023, 1:45pm UTC](https://discuss.elastic.co/t/filebeat-cisco-module-nexus-fileset-dissect-parsing-error-flag/340548/3 "2023-08-15T13:45:04Z")

</div>

Hi @jamie.hynds,

Thank you for your reply.

Is there any chance these changes will be included in Filebeat Cisco module?

I prefer to use Filebeat, rather than Elastic Agent. We were doing tests with Elastic Agent, and it takes much more resources than Filebeat.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 12, 2023, 3:45pm UTC](https://discuss.elastic.co/t/filebeat-cisco-module-nexus-fileset-dissect-parsing-error-flag/340548/4 "2023-09-12T15:45:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
