Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Cherry-pick #14519 to 7.5: [Filebeat] Fix parsing of Cisco ASA/FTD message 302021 #14611

Merged
merged 1 commit into from
Nov 19, 2019

Conversation

adriansr
Copy link
Contributor

Cherry-pick of PR #14519 to 7.5 branch. Original message:

This fixes (again) the format of ASA/FTD message code 302021 which wasn't clear between Cisco's docs and Logstash pattern in #13259.

Seems that a field can be either a port number or an ICMP code. To be safe it's better to just ignore this value.

This fixes (again) the format of ASA/FTD message code 302021 which
wasn't clear between Cisco's docs and Logstash pattern in elastic#13259.

Seems that a field can be either a port number or an ICMP code. To be
safe it's better to just ignore this value.

(cherry picked from commit 02fc1c0)
@adriansr adriansr merged commit 4e9d1a2 into elastic:7.5 Nov 19, 2019
leweafan pushed a commit to leweafan/beats that referenced this pull request Apr 28, 2023
…14611)

This fixes (again) the format of ASA/FTD message code 302021 which
wasn't clear between Cisco's docs and Logstash pattern in elastic#13259.

Seems that a field can be either a port number or an ICMP code. To be
safe it's better to just ignore this value.

(cherry picked from commit c0cb4fd)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants