# Unable to load ASA logs in SIEM

**URL:** <https://discuss.elastic.co/t/unable-to-load-asa-logs-in-siem/247977>\
**Category:** SIEM\
**Created:** [September 9, 2020, 8:29am UTC](https://discuss.elastic.co/t/unable-to-load-asa-logs-in-siem/247977 "2020-09-09T08:29:49Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kupauw](https://avatars.discourse-cdn.com/v4/letter/k/848f3c/32.png) [@Kupauw](https://discuss.elastic.co/u/Kupauw)\
**Post date:** [September 9, 2020, 8:29am UTC](https://discuss.elastic.co/t/unable-to-load-asa-logs-in-siem/247977/1 "2020-09-09T08:29:50Z")

</div>

Hi everyone.

Last week i set up a filebeat (7.8.1) to ingest syslog from an Cisco ASA.  
Everything works fine and the data is visible in kibana. Now when i go to the SIEM page and try to setup SIEM with the Cisco module there is a button that says "Check Data" when i click it i get the message, "No data has been received from this module yet".

Is have tried different filebeat versions but i get the same message.

Here is my filebeat.yml:

```auto
    filebeat.config.modules:
      path: ${path.config}/modules.d/*.yml
      reload.enabled: true
    reload.period: 10s

    # Configuratie van de output
    output.elasticsearch:
      username: xxx
      password: xxx
      protocol: https
      hosts: ["xxx:9200", "xxx:9200", "xxx:9200"]
      loadbalance: true
      bulk_max_size: 256
      worker: 3
      index: "asa-vpn-anyconnect"

```

Here is my cisco.yml (filebeat module in etc/filebeat/modules.d/)

```auto
    - module: cisco
      asa:
        enabled: true
      
        # Set which input to use between syslog (default) or file.
        #var.input: syslog
      
        # The interface to listen to UDP based syslog traffic. Defaults to
        # localhost. Set to 0.0.0.0 to bind to all available interfaces.
        var.syslog_host: 1.1.1.1
      
        # The UDP port to listen for syslog traffic. Defaults to 9001.
        #var.syslog_port: 9001
      
        # Set the log level from 1 (alerts only) to 7 (include all messages).
        # Messages with a log level higher than the specified will be dropped.
        # See https://www.cisco.com/c/en/us/td/docs/security/asa/syslog/b_syslog/syslogs-sev-level.html
        #var.log_level: 7

```

Could it be an issue that i use different index names instead of the default filebeat-\*?

---

<div class="post-metadata">

**Author:** ![Kupauw](https://avatars.discourse-cdn.com/v4/letter/k/848f3c/32.png) [@Kupauw](https://discuss.elastic.co/u/Kupauw)\
**Post date:** [September 9, 2020, 9:22am UTC](https://discuss.elastic.co/t/unable-to-load-asa-logs-in-siem/247977/2 "2020-09-09T09:22:24Z")

</div>

Ok i found the issue!  
When you use non-default index names you have to define them in the Kibana Settings. Go to Management -\> Advanced Settings -\> SIEM -\> Elasticsearch indices.

Just leaving this here, maybe more people make the same mistake.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 7, 2020, 9:22am UTC](https://discuss.elastic.co/t/unable-to-load-asa-logs-in-siem/247977/3 "2020-10-07T09:22:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
