# Sending syslog to FileBeat from Cisco Asa

**URL:** <https://discuss.elastic.co/t/sending-syslog-to-filebeat-from-cisco-asa/185147>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 11, 2019, 9:42am UTC](https://discuss.elastic.co/t/sending-syslog-to-filebeat-from-cisco-asa/185147 "2019-06-11T09:42:58Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jsandri](https://avatars.discourse-cdn.com/v4/letter/j/b9e5f3/32.png) [@jsandri](https://discuss.elastic.co/u/jsandri)\
**Post date:** [June 11, 2019, 9:42am UTC](https://discuss.elastic.co/t/sending-syslog-to-filebeat-from-cisco-asa/185147/1 "2019-06-11T09:42:58Z")

</div>

Hi everyone!  
I am a new user of elk and beats and I am trying to send logs from a Cisco Asa to a virtual machine with filebeat 7.1.1 using UDP. Logs are received but I encountered the following error message:

> 2019-06-11T16:13:33.168+0700 ERROR [syslog] syslog/input.go:131 can't parse event as syslog rfc3164 {"message": "\<166\>%ASA-6-106100: access-list mpls\_access\_in denied icmp mpls/X.X.X.219(11) -\> SG\_Office/X.X.X.10(0) hit-cnt 8 300-second interval [0x7c6ff586, 0x1f024755]\n"}

[Here](http://kb.eventtracker.com/evtpass/evtPages/MessageCode_ASA-6-106100_67942.asp) is more explication about the log message.

filebeat.yml looks like this:

> ```
> filebeat.inputs:
> - type: syslog
> protocol.udp:
> host: ":9000"
> enabled: true
> output.console:
> pretty: true
> 
> ```

For the time being, I am just trying to have something stable on the filebeat side. If anyone can help me 🙂

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [June 13, 2019, 9:30am UTC](https://discuss.elastic.co/t/sending-syslog-to-filebeat-from-cisco-asa/185147/2 "2019-06-13T09:30:20Z")

</div>

> [@jsandri](#):
>
> \<166\>%ASA-6-106100: access-list mpls\_access\_in denied icmp mpls/X.X.X.219(11) -\> SG\_Office/X.X.X.10(0) hit-cnt 8 300-second interval [0x7c6ff586, 0x1f024755]

Hi.

This message doesn't look like proper Syslog. It's missing the timestamp and hostname.

It works when I manually add them:

> \<166\>Jun 13 01:23:45 localhost %ASA-6-106100: access-list mpls\_access\_in denied icmp mpls/X.X.X.219(11) -\> SG\_Office/X.X.X.10(0) hit-cnt 8 300-second interval [0x7c6ff586, 0x1f024755]

You need to configure your Cisco ASA device to include the hostname and timestamp.

Here you can find instructions on how to add the timestamp:

> **[Configure Adaptive Security Appliance (ASA) Syslog](https://www.cisco.com/c/en/us/support/docs/security/pix-500-series-security-appliances/63884-config-asa-00.html#anc12)**
>
> This document describes sample configuration that demonstrates how to configure different logging options on ASA that runs code Version 8.4 or later.

Here explains how to add a hostname or "device ID":  
[https://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/monitor\_syslog.html#wp1065641](https://www.cisco.com/c/en/us/td/docs/security/asa/asa82/configuration/guide/config/monitor_syslog.html#wp1065641)

FYI, the next version of Filebeat, 7.2.0, will include a [module to parse Cisco ASA logs.](https://www.elastic.co/guide/en/beats/filebeat/7.2/filebeat-module-cisco.html)

---

<div class="post-metadata">

**Author:** ![jsandri](https://avatars.discourse-cdn.com/v4/letter/j/b9e5f3/32.png) [@jsandri](https://discuss.elastic.co/u/jsandri)\
**Post date:** [June 14, 2019, 6:58am UTC](https://discuss.elastic.co/t/sending-syslog-to-filebeat-from-cisco-asa/185147/3 "2019-06-14T06:58:08Z")

</div>

Thanks for your answer but unfortunately even after having added the timestamp and hostname I have the same error.

> 2019-06-14T13:44:39.829+0700 ERROR [syslog] syslog/input.go:131 can't parse event as syslog rfc3164 {"message": "\<166\>Jun 14 2019 14:44:39 SGP-FWA-01 : %ASA-6-106015: Deny TCP (no connection) from X.X.X.145/58050 to X.X.X.55/443 flags RST on interface SG\_Office\n"}

However, I have checked on Kibana and it seems to miss nothing but I don't really like keeping an error in my files. By the way, do you know when the new version will be released?

---

<div class="post-metadata">

**Author:** ![jsandri](https://avatars.discourse-cdn.com/v4/letter/j/b9e5f3/32.png) [@jsandri](https://discuss.elastic.co/u/jsandri)\
**Post date:** [June 19, 2019, 2:52am UTC](https://discuss.elastic.co/t/sending-syslog-to-filebeat-from-cisco-asa/185147/4 "2019-06-19T02:52:43Z")

</div>

Any ideas?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 17, 2019, 2:52am UTC](https://discuss.elastic.co/t/sending-syslog-to-filebeat-from-cisco-asa/185147/5 "2019-07-17T02:52:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
