03-04-2017 11:47 AM
Hi friends,
I have been tasked to implement open source logging server and forward all switches and routers..etc logs to it.
I have made it building elk stack 4.5 on ubuntu server 16 and working well but...
My issue that all received logs have the same severity of 5 and facility which is not correct according to the received logs.
Any one could make it before to help me? Any ideas guys?
Thank you all in advance
M.R.
Solved! Go to Solution.
03-06-2017 04:28 AM
Hi,
You need to edit your Logstash configuration, and filter input using grok.
I have set up ELK in the past and found some useful configurations online.
Take a look at this configuration for cisco devices. (ASA is slightly different due to log format)
https://gist.github.com/clay584/5a75009ad571af3d0648
03-06-2017 04:28 AM
Hi,
You need to edit your Logstash configuration, and filter input using grok.
I have set up ELK in the past and found some useful configurations online.
Take a look at this configuration for cisco devices. (ASA is slightly different due to log format)
https://gist.github.com/clay584/5a75009ad571af3d0648
03-11-2017 06:13 AM
Hi Lewis,
Thank you so much for your help, I figured out what was the issue and handled it , beside you link helped me too.
this link helped me too http://grokdebug.herokuapp.com/
thank you again
11-08-2017 07:53 AM
Hello did you follow a guide that you can share for all the installing process?
thanks in advance and best regards!
03-04-2022 12:11 AM - edited 03-04-2022 12:12 AM
Hi,
I need to visualize logs of the switch through elk but I need help to figure it out. Can you help me with that?
Thanks in advance
03-04-2022 12:34 AM
Hello,
as I understand it, you have to create a dashboard in order to visualize data (Step 4 in the page linked below). Is that what you are looking for ?
03-09-2022 11:16 PM
03-10-2022 12:17 AM
Hello,
check the link below for the Logstash part. Is that what you are looking for ?
https://www.neteye-blog.com/2017/10/sending-cisco-syslogs-to-elasticsearch-a-simple-guide/
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide