# Send Cisco ASA Logs to ElasticSearch

**URL:** <https://discuss.elastic.co/t/send-cisco-asa-logs-to-elasticsearch/213749>\
**Category:** Elasticsearch\
**Created:** [January 3, 2020, 8:11pm UTC](https://discuss.elastic.co/t/send-cisco-asa-logs-to-elasticsearch/213749 "2020-01-03T20:11:41Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![YogeshAggarwal](https://avatars.discourse-cdn.com/v4/letter/y/a9a28c/32.png) [@YogeshAggarwal](https://discuss.elastic.co/u/YogeshAggarwal)\
**Post date:** [January 3, 2020, 8:11pm UTC](https://discuss.elastic.co/t/send-cisco-asa-logs-to-elasticsearch/213749/1 "2020-01-03T20:11:42Z")

</div>

Hi, I am new to Elastic and need some help as i could not find an answer even after extensive googling.  
I have installed Elasticsearch 7.5, kibana 7.5, Filebeat and Logstash.  
All of these things works fine when i forward linux system logs using filebeat system modules and i can see linux logs in elasticsearch.

Now i need to send firewall logs to elasticsearch but it doesn't work. I have removed logstash from filebeat output and left elasticsearch only but it still doesn't work. I need to forward all the logs from ASA firewalls to elasticsearch.

I did tcpdump to see if packets are coming to machine and i can see firewall is sending bunch of data to systemon port 9000

Here are few of the outputs..

[root@elk-ap01.dev modules.d] 0 # filebeat modules list  
Enabled:  
cisco  
system

Disabled:  
apache

[root@elk-ap01.dev modules.d] 2 # cat ../filebeat.yml | grep -v "#"  
filebeat.inputs:

- type: log  
enabled: true  
paths:

- type: syslog  
enabled: true  
protocol.udp:  
host: "0.0.0.0:9000"

filebeat.config.modules:  
path: ${path.config}/modules.d/\*.yml  
reload.enabled: false  
setup.template.settings:  
index.number\_of\_shards: 1  
setup.kibana:  
host: "[elkdev.domain.com:5601](http://elkdev.domain.com:5601)"  
output.elasticsearch:  
hosts: ["[elkdev.domain.com:9200](http://elkdev.domain.com:9200)"]  
processors:

- add\_host\_metadata: ~
- add\_cloud\_metadata: ~
- add\_docker\_metadata: ~
- add\_kubernetes\_metadata: ~  
[root@elk-ap01.dev modules.d] 0 #

What am i missing and how can i see firewall logs in kibana ?

---

<div class="post-metadata">

**Author:** ![pjanzen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pjanzen/32/13756_2.png) [@pjanzen](https://discuss.elastic.co/u/pjanzen)\
**Post date:** [January 3, 2020, 8:27pm UTC](https://discuss.elastic.co/t/send-cisco-asa-logs-to-elasticsearch/213749/2 "2020-01-03T20:27:08Z")

</div>

I think per default the data is stored in filebeat index, have you created a index pattern for it?

---

<div class="post-metadata">

**Author:** ![YogeshAggarwal](https://avatars.discourse-cdn.com/v4/letter/y/a9a28c/32.png) [@YogeshAggarwal](https://discuss.elastic.co/u/YogeshAggarwal)\
**Post date:** [January 8, 2020, 4:26pm UTC](https://discuss.elastic.co/t/send-cisco-asa-logs-to-elasticsearch/213749/4 "2020-01-08T16:26:32Z")

</div>

I created it using filebeat setup -e command and it can see the logs from Linux systems and but not from ASA firewall

---

<div class="post-metadata">

**Author:** ![YogeshAggarwal](https://avatars.discourse-cdn.com/v4/letter/y/a9a28c/32.png) [@YogeshAggarwal](https://discuss.elastic.co/u/YogeshAggarwal)\
**Post date:** [January 8, 2020, 7:06pm UTC](https://discuss.elastic.co/t/send-cisco-asa-logs-to-elasticsearch/213749/5 "2020-01-08T19:06:20Z")

</div>

when i am trying to open asa firewall filebeat dashboard, i see sharing error in below right corner

{  
"took": 6,  
"timed\_out": false,  
"\_shards": {  
"total": 18,  
"successful": 17,  
"skipped": 0,  
"failed": 1,  
"failures": [  
{  
"shard": 0,  
"index": "filebeat-7.5.0-2019.12.19-000001",  
"node": "3Y6Kg80STPy2AFxUegq2Jw",  
"reason": {  
"type": "query\_shard\_exception",  
"reason": "No mapping found for [@timestamp] in order to sort on",  
"index\_uuid": "3eGch-MZRba053s48IpC1g",  
"index": "filebeat-7.5.0-2019.12.19-000001"  
}  
}  
]  
},  
"hits": {  
"total": 0,  
"max\_score": null,  
"hits":   
},  
"aggregations": {  
"2": {  
"doc\_count\_error\_upper\_bound": 0,  
"sum\_other\_doc\_count": 0,  
"buckets":   
}  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 5, 2020, 7:06pm UTC](https://discuss.elastic.co/t/send-cisco-asa-logs-to-elasticsearch/213749/6 "2020-02-05T19:06:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
