# Parsing Cisco ASA Log

**URL:** <https://discuss.elastic.co/t/parsing-cisco-asa-log/179726>\
**Category:** Logstash\
**Created:** [May 6, 2019, 8:01am UTC](https://discuss.elastic.co/t/parsing-cisco-asa-log/179726 "2019-05-06T08:01:57Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Omar\_Alshair](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/omar_alshair/32/45596_2.png) [@Omar\_Alshair](https://discuss.elastic.co/u/Omar_Alshair)\
**Post date:** [May 6, 2019, 8:01am UTC](https://discuss.elastic.co/t/parsing-cisco-asa-log/179726/1 "2019-05-06T08:01:58Z")

</div>

I'm trying to parse Cisco logs to only show message 106023 and 106100 which are the permitted traffic and the denied traffic. I've been having an issue with my configuration, can someone take a look at it I'm not sure what i am doing wrong.

```
input {
        udp {
                port => 5514
                type => "cisco-fw"
        }
}

filter {
        if [type] == "cisco-fw" {
                if "%ASA-106023" in [message] {
                        grok {
                                match => [
                                        "message", "%{CISCOFW106023}"
                                ]
                        }
                } else if "%ASA-106100" in [message] {
                        grok {
                                match => [
                                        "message", "%{CISCOFW106100}"
                                ]
                        }
                } else {
                        drop {}
                }
        }
}

output {
        elasticsearch {
                hosts => ["localhost:9200"]
                index => "syslog-%{+YYYY.MM}"
        }
        stdout { codec => rubydebug }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 3, 2019, 8:13am UTC](https://discuss.elastic.co/t/parsing-cisco-asa-log/179726/2 "2019-06-03T08:13:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
