# Syslog Input -\> Cisco ASA not fully parsing

**URL:** <https://discuss.elastic.co/t/syslog-input-cisco-asa-not-fully-parsing/197559>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 30, 2019, 5:02pm UTC](https://discuss.elastic.co/t/syslog-input-cisco-asa-not-fully-parsing/197559 "2019-08-30T17:02:27Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ztune](https://avatars.discourse-cdn.com/v4/letter/z/f4b2a3/32.png) [@ztune](https://discuss.elastic.co/u/ztune)\
**Post date:** [August 30, 2019, 5:02pm UTC](https://discuss.elastic.co/t/syslog-input-cisco-asa-not-fully-parsing/197559/1 "2019-08-30T17:02:27Z")

</div>

Hi Everyone,

I've got an issue I'm hoping someone can help with. I have a Win2016 server as my log collection server, with Filebeat running Syslog input and it outputs directly to Elasticsearch. The problem I'm having is with Cisco ASA events not parsing. I have the following in my filebeat logs:

`syslog/input.go:132	can't parse event as syslog rfc3164`

I've researched this on the forums here, and found "[Syslog input to support RFC5424 · Issue #6872 · elastic/beats · GitHub](https://github.com/elastic/beats/issues/6872)" but unfortunately that fix didn't seem to change anything. I'm starting to think it's a problem somewhere else in my configuration. Notably, I think I may have the syslog input part of Filebeat.yml incorrectly set up.

> ```
> #=========================== Filebeat inputs =============================
> 
> filebeat.inputs:
> 
> - type: log
> enabled: false
> paths:
> - c:\programdata\elasticsearch\logs\*
> 
> - type: syslog
> enabled: true
> protocol.udp:
> host: "0.0.0.0:514"
> 
> - type: syslog
> enabled: true
> protocol.tcp:
> host: "0.0.0.0:1514"
> 
> - type: syslog
> enabled: true
> protocol.udp:
> host: "0.0.0.0:9000"
> 
> ```

In Kibana, a Cisco ASA event comes in like this and does not fill in fields for "log.source.address" or "event.severity":

> **t** message \<148\>Aug 30 2019 11:42:00: %ASA-4-106023: Deny udp src outside:62.210.151.21/57312 dst inside:172.16.16.10/5060 by access-group "OUTSIDE\_ACL" [0x0, 0x0]

Should my syslog input be set to port 9000 only? Should I only have one? Is the ASA sending one of these other listening ports and bypassing the cisco module? I tried having our network engineer specify ports, such as port 9001 for the syslog destination, but then it seemed like I wasn't getting any events.

Thank you in advance for your time and assistance!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 27, 2019, 5:02pm UTC](https://discuss.elastic.co/t/syslog-input-cisco-asa-not-fully-parsing/197559/2 "2019-09-27T17:02:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
