-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[filebeat] improve cisco ASA module message patterns #18410
Comments
Pinging @elastic/siem (Team:SIEM) |
I am taking a look at this one, will update the issue with a status later on. |
Any update on this? These message types are frequently used and should definitely be supported. |
@P1llus Any updates? |
I ended up doing a larger rewrite which tok longer time than anticipated. I see now that I should have rather done this change first. Give me a couple of days and I can post an update @felix-lessoer and @Gimlie102 |
Describe the enhancement:
Filebeat's cisco ASA module does not parse messages of the following types:
unhandled messages ids
We would like to extract at least
destination.ip
andsource.ip
fields.Here are examples of messages not being parsed cisco_syslog.txt
The text was updated successfully, but these errors were encountered: