# No data from filebeat cisco module

**URL:** <https://discuss.elastic.co/t/no-data-from-filebeat-cisco-module/239402>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 1, 2020, 5:19am UTC](https://discuss.elastic.co/t/no-data-from-filebeat-cisco-module/239402 "2020-07-01T05:19:17Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![bqy314495](https://avatars.discourse-cdn.com/v4/letter/b/ecc23a/32.png) [@bqy314495](https://discuss.elastic.co/u/bqy314495)\
**Post date:** [July 1, 2020, 5:19am UTC](https://discuss.elastic.co/t/no-data-from-filebeat-cisco-module/239402/1 "2020-07-01T05:19:17Z")

</div>

hi, guys  
i'm new to this platform and want to do some cisco device monitoring , in my lab i've setted netflow and syslog on asa firewall , and now i can see data from netflow and make dashboards on kibana.  
which now perplexed me is that i can find syslog messages in Observabillity--\> logs like this:

 ![screenshot2](https://us1.discourse-cdn.com/elastic/original/3X/3/e/3ea5f5430c128eedf6ed5d194042ea1bfbef6930.png)  
but there is nothing on dashboard : **[Filebeat Cisco] ASA Firewall**  
 ![screenshot](https://us1.discourse-cdn.com/elastic/original/3X/c/5/c55e57bf3628cc5dba4fcd4d498031af868787a1.png)  
here is the configuration on /etc/filebeat/modules.d/cisco.yml , what's wrong and what i should do more?

```auto
     - module: cisco
       asa:
          enabled: true
          var.input: syslog
          var.syslog_host: 0.0.0.0
          var.syslog_port: 9001
          var.log_level: 7
    
    #cisco.asa.message_id 
    #cisco.asa.suffix
    #cisco.asa.source_interface
    #cisco.asa.destination_interface
    #cisco.asa.rule_name
    #cisco.asa.source_username
    #cisco.asa.destination_username
    #cisco.asa.mapped_source_ip
    #cisco.asa.mapped_source_host
    #cisco.asa.mapped_source_port
    #cisco.asa.mapped_destination_ip
    #cisco.asa.mapped_destination_host
    #cisco.asa.mapped_destination_port
    #cisco.asa.threat_level
    #cisco.asa.threat_category
    #cisco.asa.connection_id
    #cisco.asa.icmp_type
    #cisco.asa.icmp_code
    #cisco.asa.connection_type
    #cisco.asa.dap_records

```

---

<div class="post-metadata">

**Author:** ![bqy314495](https://avatars.discourse-cdn.com/v4/letter/b/ecc23a/32.png) [@bqy314495](https://discuss.elastic.co/u/bqy314495)\
**Post date:** [July 1, 2020, 5:34am UTC](https://discuss.elastic.co/t/no-data-from-filebeat-cisco-module/239402/2 "2020-07-01T05:34:31Z")

</div>

btw , the version is 7.8  
the configuration on my firewall  
syslog:

```auto
logging enable
logging timestamp
logging standby
logging buffer-size 409600
logging console debugging
logging monitor debugging
logging buffered debugging
logging trap debugging
logging history debugging
logging asdm debugging
logging device-id ipaddress inside system
logging host inside 10.226.xx.xx 17/9001
logging debug-trace

```

netflow

```auto
flow-export destination inside 10.226.xx.xx 2055

```

elasticsearch, kibana, logstash and filebeat are all installed on one server

---

<div class="post-metadata">

**Author:** ![bqy314495](https://avatars.discourse-cdn.com/v4/letter/b/ecc23a/32.png) [@bqy314495](https://discuss.elastic.co/u/bqy314495)\
**Post date:** [July 6, 2020, 1:36am UTC](https://discuss.elastic.co/t/no-data-from-filebeat-cisco-module/239402/3 "2020-07-06T01:36:18Z")

</div>

it seems the pipeline not working

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [July 6, 2020, 6:34pm UTC](https://discuss.elastic.co/t/no-data-from-filebeat-cisco-module/239402/4 "2020-07-06T18:34:59Z")

</div>

Could you please share your complete `filebeat.yml` configuration here?

Thanks,

Shaunak

---

<div class="post-metadata">

**Author:** ![bqy314495](https://avatars.discourse-cdn.com/v4/letter/b/ecc23a/32.png) [@bqy314495](https://discuss.elastic.co/u/bqy314495)\
**Post date:** [July 7, 2020, 1:54am UTC](https://discuss.elastic.co/t/no-data-from-filebeat-cisco-module/239402/5 "2020-07-07T01:54:22Z")

</div>

hi shaunak  
thanks for reply , here is my filebeat.yml configuration  
after i turned the output from logstash to elasticsearch , the module working

```auto
filebeat.inputs:
- type: log
  enabled: true
  paths:
    - /var/log/*.log
  level: debug
  review: 1
  json.keys_under_root: true
  json.overwrite_keys: true
  json.add_error_key: true
  json.message_key: message
  multiline.pattern: ^\[
  multiline.negate: false
  multiline.match: after

setup.template.settings:
  index.number_of_shards: 1
setup.ilm.enabled: auto
setup.ilm.overwrite: true

setup.kibana:
  host: "localhost:5601"

output.elasticsearch:
  hosts: ["localhost:9200"]
  pipeline: geoip-info

processors:
  - add_host_metadata: ~
  - add_cloud_metadata: ~
  - add_docker_metadata: ~

```

---

<div class="post-metadata">

**Author:** ![bqy314495](https://avatars.discourse-cdn.com/v4/letter/b/ecc23a/32.png) [@bqy314495](https://discuss.elastic.co/u/bqy314495)\
**Post date:** [July 7, 2020, 2:10am UTC](https://discuss.elastic.co/t/no-data-from-filebeat-cisco-module/239402/6 "2020-07-07T02:10:25Z")

</div>

after i turned output to elasticsearch , the dashboard get working now

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/2/82d8705a4b4b0cb7ec4fa846dd3c477a49b42bda.png)

but i can not find log meessage on this page now , is that a normal behavior ?  
oservability --\> logs

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/0/9057a2a59d11d3ea830916ed71d4ad0d211bb945.png)

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [July 7, 2020, 12:38pm UTC](https://discuss.elastic.co/t/no-data-from-filebeat-cisco-module/239402/7 "2020-07-07T12:38:44Z")

</div>

Is that your entire `filebeat.yml` file? I was expecting to see a `filebeat.config.modules` section as it is responsible for loading up external module configuration files, e.g. `/etc/filebeat/modules.d/cisco.yml`. Without that section it would seem that you are not using the Cisco module but instead are ingesting and parsing the logs using manual configuration, which is not ideal.

Also, could you call the [Elasticsearch Get Index Template API](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-get-template.html) and post the Filebeat 7.8 template here please? If it's large, please feel free to use [pastebin.com](http://pastebin.com) or [gist.github.com](http://gist.github.com) and post the link here instead.

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [July 7, 2020, 1:06pm UTC](https://discuss.elastic.co/t/no-data-from-filebeat-cisco-module/239402/8 "2020-07-07T13:06:14Z")

</div>

The `cisco/asa` fileset is [removing the original `message` field](https://github.com/elastic/beats/blob/7854c4887c8c9fa93d1bfc2d66e5a9dcacd2931e/x-pack/filebeat/module/cisco/shared/ingest/asa-ftd-pipeline.yml#L470-L479) in it's ingest pipeline, which is why you don't see it in the Kibana Logs UI. There is an issue to fix this in the future: [https://github.com/elastic/beats/issues/14708](https://github.com/elastic/beats/issues/14708).

---

<div class="post-metadata">

**Author:** ![bqy314495](https://avatars.discourse-cdn.com/v4/letter/b/ecc23a/32.png) [@bqy314495](https://discuss.elastic.co/u/bqy314495)\
**Post date:** [July 8, 2020, 4:17am UTC](https://discuss.elastic.co/t/no-data-from-filebeat-cisco-module/239402/9 "2020-07-08T04:17:09Z")

</div>

really thanks ， i will have a try

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 5, 2020, 6:17am UTC](https://discuss.elastic.co/t/no-data-from-filebeat-cisco-module/239402/10 "2020-08-05T06:17:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
