Hi All,
I am trying my hands on SIEM elastic module.
Wanted to configure Cisco network device’s logs using add data option under SIEM. Followed the steps under RPM. Have enabled the filebeat module for cisco as well.
But unfortunately I am not getting any data. What settings I need to modify under /etc/filebeat/modules.d/cisco.yml file?
I am getting following error on kibana while checking module status
No data has been received from this module yet
Please help. Do I need sample cisco-asa logs for the same or filebeat cisco module should be able to transfer the data to my elasticsearch node?
Thanks