# Grok failure with Cisco ASA using built-in plugin

**URL:** <https://discuss.elastic.co/t/grok-failure-with-cisco-asa-using-built-in-plugin/138679>\
**Category:** Logstash\
**Created:** [July 5, 2018, 9:46am UTC](https://discuss.elastic.co/t/grok-failure-with-cisco-asa-using-built-in-plugin/138679 "2018-07-05T09:46:25Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![victor.nilsson](https://avatars.discourse-cdn.com/v4/letter/v/eb8c5e/32.png) [@victor.nilsson](https://discuss.elastic.co/u/victor.nilsson)\
**Post date:** [July 5, 2018, 9:46am UTC](https://discuss.elastic.co/t/grok-failure-with-cisco-asa-using-built-in-plugin/138679/1 "2018-07-05T09:46:25Z")

</div>

So we have huge number of documents with the tag "\_grokparsefailure" and i think i figured out why.

We have Cisco ASA and we are using the following filter:

```
filter {
  if "syslog" in [tags] and "pre-processed" not in [tags] {
    if "%ASA-" in [message] {
      mutate {
        add_tag => ["pre-processed", "Firewall", "ASA"]
      }
      grok {
        match => ["message", "%{CISCO_TAGGED_SYSLOG} %{GREEDYDATA:cisco_message}"]
      }
      syslog_pri { }

        if "_grokparsefailure" not in [tags] {
          mutate {
          rename => ["cisco_message", "message"]
          remove_field => ["timestamp"]
          }
        }

 grok {
      match => [
        "message", "%{CISCOFW106001}",
        "message", "%{CISCOFW106006_106007_106010}",
        "message", "%{CISCOFW106014}",
        "message", "%{CISCOFW106015}",
        "message", "%{CISCOFW106021}",
        "message", "%{CISCOFW106023}",
        "message", "%{CISCOFW106100}",
        "message", "%{CISCOFW110002}",
        "message", "%{CISCOFW302010}",
        "message", "%{CISCOFW302013_302014_302015_302016}",
        "message", "%{CISCOFW302020_302021}",
        "message", "%{CISCOFW305011}",
        "message", "%{CISCOFW313001_313004_313008}",
        "message", "%{CISCOFW313005}",
        "message", "%{CISCOFW402117}",
        "message", "%{CISCOFW402119}",
        "message", "%{CISCOFW419001}",
        "message", "%{CISCOFW419002}",
        "message", "%{CISCOFW500004}",
        "message", "%{CISCOFW602303_602304}",
        "message", "%{CISCOFW710001_710002_710003_710005_710006}",
        "message", "%{CISCOFW713172}",
        "message", "%{CISCOFW733100}"
      ]
    }

    }
  }
}

```

However, i noticed that all the documents with the \_grokparsefailure tag have no "ciscotag" added to it. The cisco tag comes from "CISCO\_TAGGED\_SYSLOG" and i noticed that it checks for a timestamp, our messages dont contain a timestamp:

> Deny tcp src INSIDE-VRF4100:123.123.123.123/49733 dst SDN-VRF110:123.124.14.124/80 by access-group "INSIDE-VRF4100\_access\_in" [0x73808163, 0x4d11f759]

I think this is why we have millions of documents with the \_grokparsefailure tag. How can we fix this?

EDIT: I added so that if the logs had \_grokparsefailure in the tags, it would output the messages to a file and this is what i got (some of it):

> {"src\_ip":"123.123.123.123","host":"123.123.123.123","tags":["syslog","pre-processed","Firewall","ASA","\_grokparsefailure"],"duration":"0:00:00","@version":"1","protocol":"TCP","syslog\_severity":"notice","cendotServiceName":"tjosan","syslog\_facility":"user-level","cendotSID":"123123","connection\_id":"2702609852","@timestamp":"2018-07-05T08:03:35.125Z","dst\_interface":"WEB-VRF4990","src\_port":"9604","cendotFQDN":"server.fqdn","dst\_port":"80","reason":"TCP Reset","message":"\<166\>%ASA-6-302014: Teardown TCP connection 2702609852 for LB-IN:123.123.123.123/9604 to WEB-VRF4990:123.123.123.123/80 duration 0:00:00 bytes 2119 TCP Reset-O from LB-IN\n","src\_interface":"LB-IN","action":"Teardown","dst\_ip":"123.123.213.123","syslog\_severity\_code":5,"bytes":"2119","syslog\_facility\_code":1}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 2, 2018, 9:46am UTC](https://discuss.elastic.co/t/grok-failure-with-cisco-asa-using-built-in-plugin/138679/2 "2018-08-02T09:46:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
