# Filebeat cisco module not parsing ASA logs

**URL:** <https://discuss.elastic.co/t/filebeat-cisco-module-not-parsing-asa-logs/202871>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [October 9, 2019, 3:45pm UTC](https://discuss.elastic.co/t/filebeat-cisco-module-not-parsing-asa-logs/202871 "2019-10-09T15:45:35Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![JayK](https://avatars.discourse-cdn.com/v4/letter/j/e47774/32.png) [@JayK](https://discuss.elastic.co/u/JayK)\
**Post date:** [October 9, 2019, 3:45pm UTC](https://discuss.elastic.co/t/filebeat-cisco-module-not-parsing-asa-logs/202871/1 "2019-10-09T15:45:35Z")

</div>

Our ASA sends its logs to a server where they handled by rsyslog and placed in the necessary directories. FIlebeat, running on the same server, then sends them to Elasticsearch using the cisco module. It looks like everything is coming across correctly but Filebeat is not parsing the actual message part of the ASA log entry. So I will see all the fields that Filebeat adds and then at the end will be (IP and ports replaced with X's):

`Oct 9 11:20:30 XX.XX.XX.X %ASA-6-305011: Built dynamic TCP translation from inside:XX.XX.XX.XX/XXXXX to outside:XXX.XXX.XX.XXX/XXXXX`

I can't seem to figure out how to get it to work. Any help would be greatly appreciated.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 6, 2019, 3:45pm UTC](https://discuss.elastic.co/t/filebeat-cisco-module-not-parsing-asa-logs/202871/2 "2019-11-06T15:45:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
