cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3625
Views
0
Helpful
3
Replies

FirePower Syslog messages ID's

tsiemers1
Spotlight
Spotlight

I am trying to setup patterns in Logstash(ELK stack) to monitor FirePower logs.  I am trying to find a documentation that shows all the syslog messages that FirePower can produce to create a pattern file for them.  What I am looking for is similar to this documentation on the ASA.

http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logmsgs1.html

Does anything exist like this for the FirePower module?

3 Replies 3

Jason Kopacko
Level 4
Level 4

Just stumbled on your post, so sorry for the delay.

Not sure if you made any headway on this (hope so, since it says this post is 7 months old), but, go to: https://grokdebug.herokuapp.com/

And you can build and test any patterns.

Greg Gizinski
Level 1
Level 1

Did you ever find out if this documentation exists?

I ended up using kv(key value) within logstash as a filter.  But to answer your question, no it does not.

Review Cisco Networking for a $25 gift card