-
Notifications
You must be signed in to change notification settings - Fork 4.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Filebeat Cisco ASA module - add ECS authentication fields for SIEM #32257
Comments
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
@leweafan Can you give the provenance for the 716039 message? It does not match the syntax shown in the Cisco docs. The order differs, and also the user, group and IP are wrapped in angle bracket — this latter part is interesting for me for another related issue.
|
Hello @efd6! Thank for help with this issue! We have event with id 716039 on our devices and format is correct. Please find screenshot in attachments. This format for Cisco Adaptive Security Appliance Version 9.16(3) - Released: May 26, 2021. |
Thanks for that. I will add in the extra pattern. |
@leweafan I believe this is fixed in v2.7.0. This version is still in snapshot. |
Hello @efd6! |
No. They weren't in the list, so they weren't added. |
Describe the enhancement:
Cisco ASA log has authentication messages for successful and failed attempt. But ECS fields important for SIEM like
event.category, event.type, event.action, event.outcome are missing.
Successful authentication messages have event.code:
Failure authentication messages have event.code:
Successful authentication message should have fields:
Failed authentication message should have fields:
Describe a specific use case for the enhancement or feature:
Successful authentication messages
Failed authentication messages
The text was updated successfully, but these errors were encountered: