# Firewall cisco ASA and beats

**URL:** <https://discuss.elastic.co/t/firewall-cisco-asa-and-beats/239612>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 2, 2020, 10:36am UTC](https://discuss.elastic.co/t/firewall-cisco-asa-and-beats/239612 "2020-07-02T10:36:54Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Feriel\_Mufti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/feriel_mufti/32/71531_2.png) [@Feriel\_Mufti](https://discuss.elastic.co/u/Feriel_Mufti)\
**Post date:** [July 2, 2020, 10:36am UTC](https://discuss.elastic.co/t/firewall-cisco-asa-and-beats/239612/1 "2020-07-02T10:36:54Z")

</div>

Hello , i am using elasticsearch and kibana on server centos 7 , i have configured beats directly sent to elasticsearch ( without need to configure logstash) and it works perfectly from both centos agents and windows agents , now i have to configure beats from Firewall cisco ASA next generation , do i have to configure logstash or i can do the same work as i did for both centos and windows ?  
i am working on elasticsearch 6.8  
Thank you

---

<div class="post-metadata">

**Author:** ![fadjar340](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fadjar340/32/43610_2.png) [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Post date:** [July 2, 2020, 10:44am UTC](https://discuss.elastic.co/t/firewall-cisco-asa-and-beats/239612/2 "2020-07-02T10:44:56Z")

</div>

I saw in the elasticsearch 6.8 documentation, there's no information about direct ingestion using filebeat from Cisco ASA firewall.  
If you want still use elasticsearch 6.8, I suggest using logstash that read from Cisco ASA log file.  
You can send the Cisco ASA syslog to specific centralized syslog, then use logstash and build specific filter for Cisco ASA log format.

> <https://gist.github.com/mrlesmithjr/791dc72d3c92ac21342f>

Regards,  
Fadjar Tandabawana

---

<div class="post-metadata">

**Author:** ![Feriel\_Mufti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/feriel_mufti/32/71531_2.png) [@Feriel\_Mufti](https://discuss.elastic.co/u/Feriel_Mufti)\
**Post date:** [July 2, 2020, 10:50am UTC](https://discuss.elastic.co/t/firewall-cisco-asa-and-beats/239612/3 "2020-07-02T10:50:37Z")

</div>

this configuration should be on /etc/logstash/conf.d/10-syslog-filter.conf ?  
posted as it is ? and on firewall should i do anything there ?  
sorry for my questions but i didn't use logstash and configure firewall before this will be the first time !

---

<div class="post-metadata">

**Author:** ![fadjar340](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fadjar340/32/43610_2.png) [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Post date:** [July 2, 2020, 10:55am UTC](https://discuss.elastic.co/t/firewall-cisco-asa-and-beats/239612/4 "2020-07-02T10:55:18Z")

</div>

1. Build centralized syslog as follow:  
[https://www.tecmint.com/create-centralized-log-server-with-rsyslog-in-centos-7/](https://www.tecmint.com/create-centralized-log-server-with-rsyslog-in-centos-7/)

2. Set your Cisco ASA firewall syslog, point to syslog on point 1.

3. Check the log file format

4. Build complete logstash configuration in /etc/logstash/conf.d/ and follow the documentation  
[https://www.elastic.co/guide/en/logstash/current/getting-started-with-logstash.html](https://www.elastic.co/guide/en/logstash/current/getting-started-with-logstash.html)

If you have error message for the filter processing, you can ask help here...

If you don't want use logstash, upgrade the elasticsearch to the latest, because there's plugin for filebeat that direct read of Cisco devices.  
[https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-module-cisco.html](https://www.elastic.co/guide/en/beats/filebeat/master/filebeat-module-cisco.html)

Regards,  
Fadjar Tandabawana

---

<div class="post-metadata">

**Author:** ![Feriel\_Mufti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/feriel_mufti/32/71531_2.png) [@Feriel\_Mufti](https://discuss.elastic.co/u/Feriel_Mufti)\
**Post date:** [July 2, 2020, 4:11pm UTC](https://discuss.elastic.co/t/firewall-cisco-asa-and-beats/239612/5 "2020-07-02T16:11:47Z")

</div>

Thank you i will try it

---

<div class="post-metadata">

**Author:** ![francescouk](https://avatars.discourse-cdn.com/v4/letter/f/7feea3/32.png) [@francescouk](https://discuss.elastic.co/u/francescouk)\
**Post date:** [July 8, 2020, 4:28pm UTC](https://discuss.elastic.co/t/firewall-cisco-asa-and-beats/239612/6 "2020-07-08T16:28:51Z")

</div>

I'm sending all Cisco asa firewall to filebeat without any issue. But you may need to update your elk stack. I'm using the latest version 7.8  
Using both modules:  
1 - Cisco  
2 - Netflow

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 5, 2020, 6:29pm UTC](https://discuss.elastic.co/t/firewall-cisco-asa-and-beats/239612/7 "2020-08-05T18:29:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
