# Syslog Cisco ASA

**URL:** <https://discuss.elastic.co/t/syslog-cisco-asa/74220>\
**Category:** Elasticsearch\
**Created:** [February 7, 2017, 12:16pm UTC](https://discuss.elastic.co/t/syslog-cisco-asa/74220 "2017-02-07T12:16:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![zen.xen](https://avatars.discourse-cdn.com/v4/letter/z/e495f1/32.png) [@zen.xen](https://discuss.elastic.co/u/zen.xen)\
**Post date:** [February 7, 2017, 12:16pm UTC](https://discuss.elastic.co/t/syslog-cisco-asa/74220/1 "2017-02-07T12:16:15Z")

</div>

Hello,  
I need some help, I have ELK on Windows and I'd like to collect logs from Cisco ASA, how shoud I configure my ELK?  
elasticsearch - 2.2.1  
logstash - 2.2.2  
kibana - 4.4.1

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [February 7, 2017, 12:39pm UTC](https://discuss.elastic.co/t/syslog-cisco-asa/74220/2 "2017-02-07T12:39:14Z")

</div>

It is pretty hard to help without a concrete problem. If you google for this topic, you will find plenty of hits - but of course I dont know if any of those posts covers your problem/issue.

Also, if you check out the logstash grok filter, it has plenty of [Cisco ASA](https://github.com/logstash-plugins/logstash-patterns-core/blob/master/patterns/firewalls) patterns. So, fair share of things to reuse.

If your problem is getting up and running with logstash, then the [getting started](https://www.elastic.co/guide/en/logstash/5.2/getting-started-with-logstash.html) guide might be worth a read.

If you struggle, please show exact configurations and errors, so people can help. Also, please make sure to drop a note in the appropriate forums.

Thanks a lot!

---

<div class="post-metadata">

**Author:** ![Rinat](https://avatars.discourse-cdn.com/v4/letter/r/dec6dc/32.png) [@Rinat](https://discuss.elastic.co/u/Rinat)\
**Post date:** [February 18, 2017, 4:26pm UTC](https://discuss.elastic.co/t/syslog-cisco-asa/74220/3 "2017-02-18T16:26:09Z")

</div>

Thanks for reply.  
I was directed to the same github page when requesting logstash patterns for cisco asa.

How do I add those filters to logstash.conf?

Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 18, 2017, 4:26pm UTC](https://discuss.elastic.co/t/syslog-cisco-asa/74220/4 "2017-03-18T16:26:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
