# Logstash config with cisco asa and filebeat problem

**URL:** <https://discuss.elastic.co/t/logstash-config-with-cisco-asa-and-filebeat-problem/47542>\
**Category:** Logstash\
**Created:** [April 15, 2016, 10:00pm UTC](https://discuss.elastic.co/t/logstash-config-with-cisco-asa-and-filebeat-problem/47542 "2016-04-15T22:00:43Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![navox19](https://avatars.discourse-cdn.com/v4/letter/n/49beb7/32.png) [@navox19](https://discuss.elastic.co/u/navox19)\
**Post date:** [April 15, 2016, 10:00pm UTC](https://discuss.elastic.co/t/logstash-config-with-cisco-asa-and-filebeat-problem/47542/1 "2016-04-15T22:00:43Z")

</div>

Hello  
I need to get a configuration code for the config file of logstash for filebeat and firewall cisco asa at the same time  
please i need help

thanks

---

<div class="post-metadata">

**Author:** ![navox19](https://avatars.discourse-cdn.com/v4/letter/n/49beb7/32.png) [@navox19](https://discuss.elastic.co/u/navox19)\
**Post date:** [April 15, 2016, 10:27pm UTC](https://discuss.elastic.co/t/logstash-config-with-cisco-asa-and-filebeat-problem/47542/2 "2016-04-15T22:27:04Z")

</div>

i'm lost for 2 month 😢  
i have filebeat working fine and i want to add cisco asa config  
need help plez

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 17, 2016, 9:09am UTC](https://discuss.elastic.co/t/logstash-config-with-cisco-asa-and-filebeat-problem/47542/3 "2016-04-17T09:09:30Z")

</div>

What do you have so far? What problems do you have with it?

---

<div class="post-metadata">

**Author:** ![navox19](https://avatars.discourse-cdn.com/v4/letter/n/49beb7/32.png) [@navox19](https://discuss.elastic.co/u/navox19)\
**Post date:** [April 17, 2016, 4:53pm UTC](https://discuss.elastic.co/t/logstash-config-with-cisco-asa-and-filebeat-problem/47542/4 "2016-04-17T16:53:02Z")

</div>

I need to collect logs from a firewall asa , and from a linux machine by filebeat  
i know how to configure filebeat but i'm loste in configuring firewall asa logstash  
and i dont know how to make them work together at the same time  
Thank you

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [April 17, 2016, 8:11pm UTC](https://discuss.elastic.co/t/logstash-config-with-cisco-asa-and-filebeat-problem/47542/5 "2016-04-17T20:11:16Z")

</div>

It's unlikely anyone will write this for you, you need to share what you have done so far.

---

<div class="post-metadata">

**Author:** ![navox19](https://avatars.discourse-cdn.com/v4/letter/n/49beb7/32.png) [@navox19](https://discuss.elastic.co/u/navox19)\
**Post date:** [April 18, 2016, 12:24am UTC](https://discuss.elastic.co/t/logstash-config-with-cisco-asa-and-filebeat-problem/47542/6 "2016-04-18T00:24:58Z")

</div>

I have 3 files under /conf.d

30-elasticsearch-output.conf

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

10-syslog-filter.conf

filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
syslog\_pri { }  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}

02-beats-input.conf  
input {  
beats {  
port =\> 5044  
ssl =\> true  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
}

and i want to config logstash to get cisco asa logs  
i have this tuto to help [http://ict.renevdmark.nl/2015/10/22/cisco-asa-alerts-and-kibana/](http://ict.renevdmark.nl/2015/10/22/cisco-asa-alerts-and-kibana/)

and i'm lost how to put this config right

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 19, 2016, 7:44pm UTC](https://discuss.elastic.co/t/logstash-config-with-cisco-asa-and-filebeat-problem/47542/7 "2016-04-19T19:44:43Z")

</div>

Well, Cisco devices don't speak the Beats protocol, so the first step would be to add an input that they're capable of sending to. Syslog, perhaps? If so there's an example of how to receive syslog messages in the Logstash documentation.

---

<div class="post-metadata">

**Author:** ![navox19](https://avatars.discourse-cdn.com/v4/letter/n/49beb7/32.png) [@navox19](https://discuss.elastic.co/u/navox19)\
**Post date:** [April 19, 2016, 8:28pm UTC](https://discuss.elastic.co/t/logstash-config-with-cisco-asa-and-filebeat-problem/47542/8 "2016-04-19T20:28:41Z")

</div>

you can close the thread , i solved the problem by adding this config  
input {  
tcp {  
port =\> 5514  
type =\> syslog  
}  
udp {  
port =\> 5514  
type =\> syslog  
}  
}

02-syslog.conf

filter {  
if [type] == "syslog" {  
if "%ASA-" in [message] {  
grok {  
match =\> [  
"message", "%{CISCOFW106001}",  
"message", "%{CISCOFW106006\_106007\_106010}",  
"message", "%{CISCOFW106014}",  
"message", "%{CISCOFW106015}",  
"message", "%{CISCOFW106021}",  
"message", "%{CISCOFW106023}",  
"message", "%{CISCOFW106100}",  
"message", "%{CISCOFW110002}",  
"message", "%{CISCOFW302010}",  
"message", "%{CISCOFW302013\_302014\_302015\_302016}",  
"message", "%{CISCOFW302020\_302021}",  
"message", "%{CISCOFW305011}",  
"message", "%{CISCOFW313001\_313004\_313008}",  
"message", "%{CISCOFW313005}",  
"message", "%{CISCOFW402117}",  
"message", "%{CISCOFW402119}",  
"message", "%{CISCOFW419001}",  
"message", "%{CISCOFW419002}",  
"message", "%{CISCOFW500004}",  
"message", "%{CISCOFW602303\_602304}",  
"message", "%{CISCOFW710001\_710002\_710003\_710005\_710006}",  
"message", "%{CISCOFW713172}",  
"message", "%{CISCOFW733100}"  
]  
}

# Parse the syslog severity and facility

```
  syslog_pri { }
              geoip {
                source => "src_ip"
                            target => "geoip"
                            database => "/opt/logstash/GeoLiteCity.dat"
                            add_field => ["[geoip][coordinates]", "%{[geoip][longitude]}" ]
                            add_field => ["[geoip][coordinates]", "%{[geoip][latitude]}" ]
  }
            mutate {
  convert => ["[geoip][coordinates]", "float"]
  }

```

# do GeoIP lookup for the ASN/ISP information.

```
geoip {
  database => "/opt/logstash/GeoIPASNum.dat"
  source => "src_ip"
}
            mutate {
              add_field => { "logtype" => "SysLOG" }
              add_tag => ["pre-processed", "Firewall", "ASA"]
              }
}

```

}  
}

99-outputs.conf

output {  
elasticsearch {  
host =\> localhost  
index =\> "log-%{type}-%{+yyyyMM}"  
}  
stdout { codec =\> rubydebug }  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:01am UTC](https://discuss.elastic.co/t/logstash-config-with-cisco-asa-and-filebeat-problem/47542/9 "2017-07-06T05:01:31Z")

</div>


