# Incoming logs from Cisco switches don't appear in filebeat-\* indexes

**URL:** <https://discuss.elastic.co/t/incoming-logs-from-cisco-switches-dont-appear-in-filebeat-indexes/241679>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 17, 2020, 2:54pm UTC](https://discuss.elastic.co/t/incoming-logs-from-cisco-switches-dont-appear-in-filebeat-indexes/241679 "2020-07-17T14:54:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![robertitox](https://avatars.discourse-cdn.com/v4/letter/r/4491bb/32.png) [@robertitox](https://discuss.elastic.co/u/robertitox)\
**Post date:** [July 17, 2020, 2:54pm UTC](https://discuss.elastic.co/t/incoming-logs-from-cisco-switches-dont-appear-in-filebeat-indexes/241679/1 "2020-07-17T14:54:15Z")

</div>

Dear all,

I have ELK 7.8.0 and I've configured cisco asa module from Filebeat 7.8.0 in order to receive incoming logs from Cisco switches. Here it is the /etc/filebeat/modules.d/cisco.yml below module.cisco line:

ios:  
enabled: true  
var.input: syslog  
var.syslog\_host: 10.1.1.1  
var.syslog\_port: 514

After restart filebeat, I run "tcpdump -i eth0 port 514" and I can see incoming logs in the eth0 interface:

10:04:53.496880 IP 172.16.1.15.61032 \> 10.1.1.1.syslog: SYSLOG local7.notice, length: 119  
10:04:58.645727 IP 172.16.1.15.61032 \> 10.1.1.1.syslog: SYSLOG local7.error, length: 101  
10:06:00.641406 IP 172.16.1.15.61032 \> 10.1.1.1.syslog: SYSLOG local7.notice, length: 119  
10:06:02.950845 IP 172.16.1.15.61032 \> 10.1.1.1.syslog: SYSLOG local7.error, length: 101  
10:10:08.349291 IP 172.16.1.15.61032 \> 10.1.1.1.syslog: SYSLOG local7.notice, length: 103

But after that, when I go to Discover and I choose Filebeat-\*, I search into these indexes for Cisco switches syslog events, but I can't see anything.....no syslogs at all.

What can be the problem? Because I see syslogs in the physical interface but I don't see them in filebeat-\* .

Thanks in advance !!!

---

<div class="post-metadata">

**Author:** ![Mario\_Castro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mario_castro/32/35107_2.png) [@Mario\_Castro](https://discuss.elastic.co/u/Mario_Castro)\
**Post date:** [July 21, 2020, 10:59am UTC](https://discuss.elastic.co/t/incoming-logs-from-cisco-switches-dont-appear-in-filebeat-indexes/241679/2 "2020-07-21T10:59:27Z")

</div>

Can you execute with full logging output enabled and paste the results in a proper Markdown format, please? `metricbeat -e -d "*"`

---

<div class="post-metadata">

**Author:** ![robertitox](https://avatars.discourse-cdn.com/v4/letter/r/4491bb/32.png) [@robertitox](https://discuss.elastic.co/u/robertitox)\
**Post date:** [July 21, 2020, 12:43pm UTC](https://discuss.elastic.co/t/incoming-logs-from-cisco-switches-dont-appear-in-filebeat-indexes/241679/3 "2020-07-21T12:43:11Z")

</div>

Dear Mario, I've implemented a new ELK server and now the Cisco logs are coming OK.

Thanks for your help!!!

Cheers

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 18, 2020, 2:43pm UTC](https://discuss.elastic.co/t/incoming-logs-from-cisco-switches-dont-appear-in-filebeat-indexes/241679/4 "2020-08-18T14:43:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
