# Kibana log error message "event.dataset cisco.asa failed to find message"

**URL:** <https://discuss.elastic.co/t/kibana-log-error-message-event-dataset-cisco-asa-failed-to-find-message/240034>\
**Category:** Logs\
**Created:** [July 6, 2020, 3:58pm UTC](https://discuss.elastic.co/t/kibana-log-error-message-event-dataset-cisco-asa-failed-to-find-message/240034 "2020-07-06T15:58:43Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![robertitox](https://avatars.discourse-cdn.com/v4/letter/r/4491bb/32.png) [@robertitox](https://discuss.elastic.co/u/robertitox)\
**Post date:** [July 6, 2020, 3:58pm UTC](https://discuss.elastic.co/t/kibana-log-error-message-event-dataset-cisco-asa-failed-to-find-message/240034/1 "2020-07-06T15:58:43Z")

</div>

Dear people, I have an ELK 7.8.0 server running OK.

I've setup the Cisco ASA module in filebeat and all the ASA logs are coming OK to my ELK server on port UDP/514. I can see the ASA lohgs in Discover and SIEM Netwotk tab.

But when I go to Kibana --\> Observavility --\> Logs I see a lot of error messages:

 ![imagen](https://us1.discourse-cdn.com/elastic/original/3X/f/5/f52bace00dfb391b94fce8c8fb0f76a608523c11.png)

But when I go to Kibana --\> Discover, at cisco.asa error times I can't see any syslog message, so I think Kibana can't retrieve Cisco ASA logs at those times for any reason I don't know.  
My cisco module is this:

- module: cisco  
asa:  
enabled: true  
var.input: syslog  
var.syslog\_host: 10.1.1.15  
var.syslog\_port: 514  
var.log\_level: 7

What can be the problem? Can you help me please?

Special thanks !!!

---

<div class="post-metadata">

**Author:** ![robertitox](https://avatars.discourse-cdn.com/v4/letter/r/4491bb/32.png) [@robertitox](https://discuss.elastic.co/u/robertitox)\
**Post date:** [July 7, 2020, 12:40am UTC](https://discuss.elastic.co/t/kibana-log-error-message-event-dataset-cisco-asa-failed-to-find-message/240034/2 "2020-07-07T00:40:47Z")

</div>

The same occurs with event.dataset equal to netflow.log:

 ![imagen](https://us1.discourse-cdn.com/elastic/original/3X/5/1/51659f76af62e7028c024ffccbc81ae50d1a932e.png)

Netflow data is received by Netflow module from Filebeat.

How can be the problem?

Thanks !!!

---

<div class="post-metadata">

**Author:** ![robertitox](https://avatars.discourse-cdn.com/v4/letter/r/4491bb/32.png) [@robertitox](https://discuss.elastic.co/u/robertitox)\
**Post date:** [July 7, 2020, 3:00pm UTC](https://discuss.elastic.co/t/kibana-log-error-message-event-dataset-cisco-asa-failed-to-find-message/240034/3 "2020-07-07T15:00:23Z")

</div>

I add:

Cisco and Netflow' Filebeat modules put the data in the same filebeat index,and these are my filebeat indices from July:

 ![imagen](https://us1.discourse-cdn.com/elastic/original/3X/e/a/eac19ee98f43bbdb00b63e868ce0dd941a48cd02.png)

---

<div class="post-metadata">

**Author:** ![afgomez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/afgomez/32/59274_2.png) [@afgomez](https://discuss.elastic.co/u/afgomez)\
**Post date:** [July 16, 2020, 3:03pm UTC](https://discuss.elastic.co/t/kibana-log-error-message-event-dataset-cisco-asa-failed-to-find-message/240034/4 "2020-07-16T15:03:34Z")

</div>

Hi @robertitox,

Thanks for your message! This looks like a bug in Kibana. I have opened an [issue in our github](https://github.com/elastic/kibana/issues/72069).

---

<div class="post-metadata">

**Author:** ![robertitox](https://avatars.discourse-cdn.com/v4/letter/r/4491bb/32.png) [@robertitox](https://discuss.elastic.co/u/robertitox)\
**Post date:** [July 17, 2020, 1:34pm UTC](https://discuss.elastic.co/t/kibana-log-error-message-event-dataset-cisco-asa-failed-to-find-message/240034/5 "2020-07-17T13:34:34Z")

</div>

Dear Alejandro, thanks a lot for your help.

I could see there is no message field in the incoming log, so a message failed error appears. So it's not an problem, isn't it?

Regards!!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 14, 2020, 1:34pm UTC](https://discuss.elastic.co/t/kibana-log-error-message-event-dataset-cisco-asa-failed-to-find-message/240034/6 "2020-08-14T13:34:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
