# Logstash Patterns - Firewalls - Best Place to Find it

**URL:** <https://discuss.elastic.co/t/logstash-patterns-firewalls-best-place-to-find-it/239107>\
**Category:** Logstash\
**Created:** [June 29, 2020, 11:48am UTC](https://discuss.elastic.co/t/logstash-patterns-firewalls-best-place-to-find-it/239107 "2020-06-29T11:48:06Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![mgotechlock](https://avatars.discourse-cdn.com/v4/letter/m/dc4da7/32.png) [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Post date:** [June 29, 2020, 11:48am UTC](https://discuss.elastic.co/t/logstash-patterns-firewalls-best-place-to-find-it/239107/1 "2020-06-29T11:48:06Z")

</div>

My use case is Cisco ASA firewall logs but I think these questions apply more broadly.

I am trying do the parsing of Cisco ASA logs in logstash, not using Filebeat.

1. I'd like to not reinvent the wheel so where can I find the Filebeat Cisco module's code that does this parsing, so that I can use that code in logstash parsing?

2. There is a logstash-patterns-core/patterns/firewall file. ([logstash-patterns-core](https://github.com/logstash-plugins/logstash-patterns-core)) But it doesn't map fields to ECS field names. For example it uses src\_ip instead of source.address. Why on earth would elastic put out this file and not use ECS field names?

3. Related to #1, I've looked and looked and looked. Is there an updated github page for mapping Cisco ASA to ECS fields? I would expect it to be the one I linked to already, but using custom, non-ECS fields is a non-starter.

---

<div class="post-metadata">

**Author:** ![Wolfram\_Haussig](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wolfram_haussig/32/70528_2.png) [@Wolfram\_Haussig](https://discuss.elastic.co/u/Wolfram_Haussig)\
**Post date:** [June 29, 2020, 12:59pm UTC](https://discuss.elastic.co/t/logstash-patterns-firewalls-best-place-to-find-it/239107/2 "2020-06-29T12:59:53Z")

</div>

Hi,

Have a look here: [https://github.com/elastic/beats/tree/master/x-pack/filebeat/module/cisco](https://github.com/elastic/beats/tree/master/x-pack/filebeat/module/cisco)

In particular, here is the ingest pipeline for ElasticSearch including the grok patterns: [https://github.com/elastic/beats/blob/master/x-pack/filebeat/module/cisco/shared/ingest/asa-ftd-pipeline.yml](https://github.com/elastic/beats/blob/master/x-pack/filebeat/module/cisco/shared/ingest/asa-ftd-pipeline.yml)

Best regards  
Wolfram

---

<div class="post-metadata">

**Author:** ![mgotechlock](https://avatars.discourse-cdn.com/v4/letter/m/dc4da7/32.png) [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Post date:** [July 16, 2020, 7:56pm UTC](https://discuss.elastic.co/t/logstash-patterns-firewalls-best-place-to-find-it/239107/3 "2020-07-16T19:56:18Z")

</div>

So I looked at the filebeat modules and they are not like the logstash pipelines I am used to seeing. So if I took those pipelines from filebeat and put in as logstash pipelines, are they going to work as is?

For example the ASA one starts with

> processors:
> 
> - grok:  
> field: message  
> patterns:  
> - "(?:%{SYSLOG\_HEADER})?\s\*%{GREEDYDATA:log.original}"  
> pattern\_definitions:  
> SYSLOG\_HEADER: "(?:%{SYSLOGFACILITY}\s\*)?(?:%{FTD\_DATE:_temp_.raw\_date}:?\s+)?(?:%{PROCESS\_HOST}|%{HOST\_PROCESS})(?:{DATA})?%{SYSLOG\_END}?"  
> SYSLOGFACILITY: "\<%{NONNEGINT:syslog.facility:int}(?:.%{NONNEGINT:syslog.priority:int})?\>"  
> # Beginning with version 6.3, Firepower Threat Defense provides the option to enable timestamp as per RFC 5424.  
> FTD\_DATE: "(?:%{TIMESTAMP\_ISO8601}|%{ASA\_DATE})"  
> ASA\_DATE: "(?:%{DAY} )?%{MONTH} \*%{MONTHDAY}(?: %{YEAR})? %{TIME}(?: %{TZ})?"  
> PROCESS: "(?:[^%\s:\+)"  
> SYSLOG\_END: "(?:(:|\s)\s+)"  
> # exactly match the syntax for firepower management logs  
> PROCESS\_HOST: "(?:%{PROCESS:process.name}:\s%{SYSLOGHOST:host.name})"  
> HOST\_PROCESS: "(?:%{SYSLOGHOST:host.hostname}:?\s+)?(?:%{PROCESS:process.name}?(?:\[%{POSINT:process.pid:long}\])?)?"

Would i have to wrap that in a filter {} and is -grok even a valid syntax? I've always just used grok no dash. If you can give me a start of what might need changing to be useful in a logstash pipeline, I can go from there.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 16, 2020, 8:09pm UTC](https://discuss.elastic.co/t/logstash-patterns-firewalls-best-place-to-find-it/239107/4 "2020-07-16T20:09:25Z")

</div>

That is YAML, which is not a valid logstash configuration, but transforming it should be straightforward. I would try

```
filter {
    grok {
        pattern_definitions => {
            "SYSLOG_HEADER" => "(?:%{SYSLOGFACILITY}\s*)?(?:%{FTD_DATE:temp.raw_date}:?\s+)?(?:%{PROCESS_HOST}|%{HOST_PROCESS})(?:{DATA})?%{SYSLOG_END}?"
            "SYSLOGFACILITY" => "<%{NONNEGINT:syslog.facility:int}(?:.%{NONNEGINT:syslog.priority:int})?>"
            "FTD_DATE" => "(?:%{TIMESTAMP_ISO8601}|%{ASA_DATE})"
            "ASA_DATE" => "(?:%{DAY} )?%{MONTH} *%{MONTHDAY}(?: %{YEAR})? %{TIME}(?: %{TZ})?"
            "PROCESS" => "(?:[^%\s:\+)"
            "SYSLOG_END" => "(?:(:|\s)\s+)"
            "PROCESS_HOST" => "(?:%{PROCESS:process.name}:\s%{SYSLOGHOST:host.name})"
            "HOST_PROCESS" => "(?:%{SYSLOGHOST:host.hostname}:?\s+)?(?:%{PROCESS:process.name}?(?:\[%{POSINT:process.pid:long}\])?)?"
        }
        match => { "message" => "(?:%{SYSLOG_HEADER})?\s*%{GREEDYDATA:log.original}" }
    }
}
```

---

<div class="post-metadata">

**Author:** ![mgotechlock](https://avatars.discourse-cdn.com/v4/letter/m/dc4da7/32.png) [@mgotechlock](https://discuss.elastic.co/u/mgotechlock)\
**Post date:** [July 16, 2020, 8:15pm UTC](https://discuss.elastic.co/t/logstash-patterns-firewalls-best-place-to-find-it/239107/5 "2020-07-16T20:15:43Z")

</div>

Thank you. That's exactly the kind of help I needed. I'm just going to mark that as the solution even though I won't be able to test for a while.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 13, 2020, 8:15pm UTC](https://discuss.elastic.co/t/logstash-patterns-firewalls-best-place-to-find-it/239107/6 "2020-08-13T20:15:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
