Cisco ASA Logstash Parsing

Cisco ASA Logstash Parsing

I recently had an opportunity to get around to creating some Cisco ASA parsing for logstash to detect some abnormal activity on the network. So now that I have created the parsing and have to say it works pretty good; I figured I would share it with anyone else that may have a need for this as well. I will also share the dashboard that I created in case you want that as well.

You will need to add the following to your current logstash.conf file.. I placed this at the top of my config below all inputs before standard syslog parsing to make sure it was processed first, tagged and passed the next level of syslog parsing.

That’s it!

Here are some screenshots of what the dashboard looks like.

Screen Shot 2014-12-11 at 9.58.47 PM Screen Shot 2014-12-11 at 9.59.05 PM

To download the dashboard grab it here.

Enjoy!

13 thoughts on “Cisco ASA Logstash Parsing

  1. Hi,
    You show some drop rates in your Dashboard. How are these data values represented in the logstash.conf ?

    Regards Christian

  2. Hello,

    nice tutorial. Have you also installed the new Kibana 4? I want the same thing in your tutorial with Kibana 4. Can you tell me how can i do this?

    Best Regards

    Daniel

    • @Daniel – I am actually learning to use Kibana4 right now as well. Love the interface but so much different.

  3. I using your kibana template but i has problem:

    Oops! FacetPhaseExecutionException[Facet [0]: (value) field [drop_rate_current_burst] not found]

    Oops! FacetPhaseExecutionException[Facet [0]: (value) field [drop_rate_current_avg] not found]

    Oops! FacetPhaseExecutionException[Facet [0]: (value) field [drop_rate_max_avg] not found]

    Oops! FacetPhaseExecutionException[Facet [0]: (value) field [drop_rate_max_burst] not found]

    How to fix it ?

  4. Hi mrlesmithjr

    Thanks for add the above blog very use . Just new to Kibana , wondering what is the best way to load the dashboards in kibana using your file you added .

Leave a Reply

Your email address will not be published. Required fields are marked *

*