Improving Cisco IOS Filebeats Module

Hi All,

Just wanted to drop a line out to the Community and devs to say I am currently working to extend the number of logs passed by the cisco ios filebeat module.

Forked Version of module is here:

So Far all changes as constrained to the pipeline.js so its possible to just copy this file over the original to test the new features.

Its is NOT production ready and is very much a work in progress there are some bugs and things that havent figured correct way of handling yet but it does handle a lot more log types than the original.

I welcome any example ios logs people may have which contain useful meta data for passing. Where possible trying to map fields to Core ECS or extend cisco.* but welcome feedback on field names etc.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.