Index ASA logs


#1

I am trying to setup ELK for ASA logs , issue I am facing is parsing ASA logs. Any help will be appreciated.

I am getting following error message

"No Compatible Fields: The "logstash-*" index pattern does not contain any of the following field types: ip"

Thanks
Pankaj


#2

Maybe this will help.
https://jackhanington.com/blog/2015/06/16/send-cisco-asa-syslogs-to-elasticsearch-using-logstash/


#3

Still not able to index IP field

name
_index
_type
geoip.location
@version
_source
_id
raw_message
type
path
host
syslog_host.raw
path.raw
raw_message.raw
tags.raw
syslog_host
host.raw
type.raw
message
tags
@timestamp


(Magnus Bäck) #4

Isn't that error message from Kibana? When are you getting it? Which field is supposed to contain an IP address? What's your current configuration?


#5

Its internal POC platform I am trying to build . I have Centos Virtual instance with Logstash 1.5.3 , Kibana 4.1 and ES 1.7.1.

Regards
Pankaj


(Magnus Bäck) #6

Okay, but please try to answer the questions I posted earlier.


#7

Yes Error message I am getting is from Kibana. I am trying to visualize the traffic with Geo IP or other chart.

Regards
Pankaj


(system) #8