Logstash parsing not consistant

Hi,

I took your 2 log lines and neither matched your grok. Removing <%{WORD:syslogpri}> seems to fix the issue and it now parses both lines. Can you confirm you're using the right grok.

 match => [ "message", "%{TIMESTAMP_ISO8601:server_time}<%{NUMBER:syslognum}>%{CISCOTIMESTAMP:cisco_time} %{SYSLOGHOST:hostname} : %{DATA:asa_message}"]