# SIEM Elastic - Beta -7.2 - Cisco module - unable to see data

**URL:** <https://discuss.elastic.co/t/siem-elastic-beta-7-2-cisco-module-unable-to-see-data/187546>\
**Category:** SIEM\
**Created:** [June 26, 2019, 10:39am UTC](https://discuss.elastic.co/t/siem-elastic-beta-7-2-cisco-module-unable-to-see-data/187546 "2019-06-26T10:39:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mons](https://avatars.discourse-cdn.com/v4/letter/m/c5a1d2/32.png) [@Mons](https://discuss.elastic.co/u/Mons)\
**Post date:** [June 26, 2019, 10:39am UTC](https://discuss.elastic.co/t/siem-elastic-beta-7-2-cisco-module-unable-to-see-data/187546/1 "2019-06-26T10:39:05Z")

</div>

Hi All,

I am trying my hands on SIEM elastic module.

Wanted to configure Cisco network device’s logs using add data option under SIEM. Followed the steps under RPM. Have enabled the filebeat module for cisco as well.

But unfortunately I am not getting any data. What settings I need to modify under /etc/filebeat/modules.d/cisco.yml file?

I am getting following error on kibana while checking module status  
No data has been received from this module yet

Please help. Do I need sample cisco-asa logs for the same or filebeat cisco module should be able to transfer the data to my elasticsearch node?

Thanks

---

<div class="post-metadata">

**Author:** ![rashmi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rashmi/32/16391_2.png) [@rashmi](https://discuss.elastic.co/u/rashmi)\
**Post date:** [July 16, 2019, 3:50pm UTC](https://discuss.elastic.co/t/siem-elastic-beta-7-2-cisco-module-unable-to-see-data/187546/2 "2019-07-16T15:50:20Z")

</div>

moved it to SIEM .

Hope to get some response here.

Thanks  
Rashmi

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [July 17, 2019, 1:51am UTC](https://discuss.elastic.co/t/siem-elastic-beta-7-2-cisco-module-unable-to-see-data/187546/3 "2019-07-17T01:51:58Z")

</div>

It would be helpful for us to see the configuration that you are using. Could you please share that with us. This is how I have mine setup in my filebeat.yml:

```auto
filebeat.modules:
  - module: cisco
    asa:
      var:
        input: syslog
        syslog_host: '0.0.0.0'
        syslog_port: 9003

```

Then I configured the ASA to stream syslog to `<filebeat_server_ip>:9003`.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 14, 2019, 1:52am UTC](https://discuss.elastic.co/t/siem-elastic-beta-7-2-cisco-module-unable-to-see-data/187546/4 "2019-08-14T01:52:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
