# Logstash 2.0.0 and Cisco ASA syslog

**URL:** <https://discuss.elastic.co/t/logstash-2-0-0-and-cisco-asa-syslog/35604>\
**Category:** Logstash\
**Created:** [November 25, 2015, 8:06pm UTC](https://discuss.elastic.co/t/logstash-2-0-0-and-cisco-asa-syslog/35604 "2015-11-25T20:06:25Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![edgoad](https://avatars.discourse-cdn.com/v4/letter/e/278dde/32.png) [@edgoad](https://discuss.elastic.co/u/edgoad)\
**Post date:** [November 25, 2015, 8:06pm UTC](https://discuss.elastic.co/t/logstash-2-0-0-and-cisco-asa-syslog/35604/1 "2015-11-25T20:06:25Z")

</div>

I have all my Cisco devices forwarding syslog to a central server, and then using Logstash-Forwarder to forward them to logstash. For general syslog features this works great, but I can't get logstash to properly grok the logs from my ASAs. I followed several tutorials online (such as [https://jackhanington.com/blog/2014/04/21/using-logstash-elasticsearch-and-kibana-for-cisco-asa-syslog-message-analysis/](https://jackhanington.com/blog/2014/04/21/using-logstash-elasticsearch-and-kibana-for-cisco-asa-syslog-message-analysis/)), but I keep getting the dreaded **\_grokparsefailure** tag instead. The only thing I can think of is that the logs somehow dont match the expected patterns, I tried [https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/) and it sometimes reports success, others no.

Has something changed in logstash 2? Is my input messed up? Any guidance whatsoever?

Below are a few (sanitized) lines from my syslog:  
2015-11-25T11:53:09.089380-08:00 xx.xx.xx.xx %ASA-6-302015: Built outbound UDP connection 2394972349 for outside:xx.xx.xx.xx/53 (xx.xx.xx.xx/53) to inside:xx.xx.xx.xx/56848 (xx.xx.xx.xx/56848)  
2015-11-25T11:53:09.089673-08:00 xx.xx.xx.xx %ASA-6-302014: Teardown TCP connection 2394972321 for outside:xx.xx.xx.xx/80 to inside:xx.xx.xx.xx/52005 duration 0:00:00 bytes 854 TCP FINs  
2015-11-25T11:53:09.091128-08:00 xx.xx.xx.xx %ASA-6-305012: Teardown dynamic TCP translation from inside:xx.xx.xx.xx/1769 to outside:xx.xx.xx.xx/1769 duration 0:01:01  
2015-11-25T11:53:09.091186-08:00 xx.xx.xx.xx %ASA-6-305012: Teardown dynamic UDP translation from Training:xx.xx.xx.xx/52497 to outside:xx.xx.xx.xx/52497 duration 0:00:31  
2015-11-25T11:53:09.091186-08:00 xx.xx.xx.xx %ASA-6-305012: Teardown dynamic UDP translation from Training:xx.xx.xx.xx/52230 to outside:xx.xx.xx.xx/52230 duration 0:00:31  
2015-11-25T11:53:09.092227-08:00 xx.xx.xx.xx %ASA-6-302014: Teardown TCP connection 2394972322 for outside:xx.xx.xx.xx/80 to inside:xx.xx.xx.xx/52006 duration 0:00:00 bytes 982 TCP FINs  
2015-11-25T11:53:09.097249-08:00 xx.xx.xx.xx %ASA-6-302016: Teardown UDP connection 2394972349 for outside:xx.xx.xx.xx/53 to inside:xx.xx.xx.xx/56848 duration 0:00:00 bytes 269  
2015-11-25T11:53:09.107922-08:00 xx.xx.xx.xx %ASA-6-305012: Teardown dynamic TCP translation from inside:xx.xx.xx.xx/48261 to outside:xx.xx.xx.xx/48261 duration 0:01:01  
2015-11-25T11:53:09.107922-08:00 xx.xx.xx.xx %ASA-6-305012: Teardown dynamic TCP translation from inside:xx.xx.xx.xx/1754 to outside:xx.xx.xx.xx/1754 duration 0:01:01  
2015-11-25T11:53:09.124678-08:00 xx.xx.xx.xx %ASA-6-305012: Teardown dynamic TCP translation from inside:xx.xx.xx.xx/3724 to outside:xx.xx.xx.xx/45036 duration 0:01:01

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 25, 2015, 8:22pm UTC](https://discuss.elastic.co/t/logstash-2-0-0-and-cisco-asa-syslog/35604/2 "2015-11-25T20:22:13Z")

</div>

What's your configuration? Are the lines above examples of failures? If not, please supply such a line.

---

<div class="post-metadata">

**Author:** ![edgoad](https://avatars.discourse-cdn.com/v4/letter/e/278dde/32.png) [@edgoad](https://discuss.elastic.co/u/edgoad)\
**Post date:** [November 25, 2015, 8:44pm UTC](https://discuss.elastic.co/t/logstash-2-0-0-and-cisco-asa-syslog/35604/3 "2015-11-25T20:44:01Z")

</div>

Those lines are from the syslog file, which I assume is the source. It appears that all of the ASA logs get the \_grokparsefail tag whenever I try to use a grok pattern such as:  
grok {  
match =\> [  
"cisco\_message", "%{CISCOFW106001}",  
"cisco\_message", "%{CISCOFW106006\_106007\_106010}",  
"cisco\_message", "%{CISCOFW106014}",  
"cisco\_message", "%{CISCOFW106015}",  
"cisco\_message", "%{CISCOFW106021}",  
"cisco\_message", "%{CISCOFW106023}",  
"cisco\_message", "%{CISCOFW106100}",  
"cisco\_message", "%{CISCOFW110002}",  
"cisco\_message", "%{CISCOFW302010}",  
"cisco\_message", "%{CISCOFW302013\_302014\_302015\_302016}",  
"cisco\_message", "%{CISCOFW302020\_302021}",  
"cisco\_message", "%{CISCOFW305011}",  
"cisco\_message", "%{CISCOFW313001\_313004\_313008}",  
"cisco\_message", "%{CISCOFW313005}",  
"cisco\_message", "%{CISCOFW402117}",  
"cisco\_message", "%{CISCOFW402119}",  
"cisco\_message", "%{CISCOFW419001}",  
"cisco\_message", "%{CISCOFW419002}",  
"cisco\_message", "%{CISCOFW500004}",  
"cisco\_message", "%{CISCOFW602303\_602304}",  
"cisco\_message", "%{CISCOFW710001\_710002\_710003\_710005\_710006}",  
"cisco\_message", "%{CISCOFW713172}",  
"cisco\_message", "%{CISCOFW733100}"  
]  
}

########################### Logstash config ###################  
input {  
lumberjack {  
port =\> 5043  
type =\> "logs"  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
}

filter {  
if "syslog" in [tags] and "pre-processed" not in [tags] {  
if "%ASA-" in [message] {  
mutate {  
add\_tag =\> ["pre-processed", "Firewall", "ASA"]  
add\_field =\> ["syslog\_raw\_message", "{message}"]  
}  
syslog\_pri { }  
grok {  
patterns\_dir =\> "/opt/logstash/patterns/custom"  
match =\> ["message", "%{GREEDYDATA:cisco\_message}"]  
}  
}

output {  
elasticsearch { hosts =\> ["localhost:9200"] }

# stdout { codec =\> rubydebug }

}

---

<div class="post-metadata">

**Author:** ![edgoad](https://avatars.discourse-cdn.com/v4/letter/e/278dde/32.png) [@edgoad](https://discuss.elastic.co/u/edgoad)\
**Post date:** [November 25, 2015, 10:18pm UTC](https://discuss.elastic.co/t/logstash-2-0-0-and-cisco-asa-syslog/35604/4 "2015-11-25T22:18:53Z")

</div>

I think I may have solved my own problem (hurray!)

I was looking at [https://jackhanington.com/blog/tag/logstash/](https://jackhanington.com/blog/tag/logstash/), and he creates a script that inputs a mapping? into logstash. I did this but was still getting errors, until I noticed that he tagged his traffic type as "cisco-fw". I performed the same and viola!

So far there have been no \_grokparsefailure or lines appearing in my logstash.log

---

<div class="post-metadata">

**Author:** ![navox19](https://avatars.discourse-cdn.com/v4/letter/n/49beb7/32.png) [@navox19](https://discuss.elastic.co/u/navox19)\
**Post date:** [April 15, 2016, 10:26pm UTC](https://discuss.elastic.co/t/logstash-2-0-0-and-cisco-asa-syslog/35604/5 "2016-04-15T22:26:09Z")

</div>

@edgoad can you give me your config plz your input and filter and output i'm lost ,  
i have filebeat working fine and i want to add cisco asa config  
need help plez

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:02am UTC](https://discuss.elastic.co/t/logstash-2-0-0-and-cisco-asa-syslog/35604/6 "2017-07-06T05:02:00Z")

</div>


