# Logs from Cisco SFR (IPS) to Elasticsearch

**URL:** <https://discuss.elastic.co/t/logs-from-cisco-sfr-ips-to-elasticsearch/242909>\
**Category:** Beats\
**Tags:** beats-module, filebeat\
**Created:** [July 28, 2020, 1:03pm UTC](https://discuss.elastic.co/t/logs-from-cisco-sfr-ips-to-elasticsearch/242909 "2020-07-28T13:03:47Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![robertitox](https://avatars.discourse-cdn.com/v4/letter/r/4491bb/32.png) [@robertitox](https://discuss.elastic.co/u/robertitox)\
**Post date:** [July 28, 2020, 1:03pm UTC](https://discuss.elastic.co/t/logs-from-cisco-sfr-ips-to-elasticsearch/242909/1 "2020-07-28T13:03:48Z")

</div>

Dear all, I have an ELK 7.8.0 server with Filebeat.

I've enabled cisco module from Filebeat and I have these different syslog listeners:

- syslog configured from filebeat.yml file: logging of Linux hosts
- asa fileset configured from cisco.yml file: logging of Cisco ASA firewall
- ios fileset configured from cisco.yml file: logging of Cisco switches and routers

I also can see there is a ftd fileset (Firepower Threat Defense) in order to catch logs from this type of Cisco IPS.

A month ago we have implemented a Cisco SFR module in our ASA firewall, the SFR is our IPS, so where do I have to send the SFR's logs ??? To filebeat's asa fileset or to filebeat's syslog??? I think I can't send the logs to ftd fileseat because FTD is a diferent type of IPS than SFR.

Special thanks !!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 25, 2020, 3:03pm UTC](https://discuss.elastic.co/t/logs-from-cisco-sfr-ips-to-elasticsearch/242909/2 "2020-08-25T15:03:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
