-
Notifications
You must be signed in to change notification settings - Fork 444
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Cisco ASA] Add support for Authentication and VPN Events #4721
Comments
Pinging @elastic/security-external-integrations (Team:Security-External Integrations) |
Interesting, kibana shows VPN events for filebeat-7.9.3 (cisco module enabled), but not for filebeat-7.10.0. |
Hey @jurim76, there should be at least some VPN events showing as our pipeline supports a few VPN events (e.g. 716002 and 713049. We haven't removed any events from the pipeline. Could you provide some examples of events that you're no longer seeing? |
Hello Here are missing entries for VPN events %ASA-4-106103: access-list VPN_FILTER_DEV denied icmp for user 'user.name' outside/172.16.24.67(8) -> outside/10.80.103.32(0) hit-cnt 1 first hit %ASA-5-746012: user-identity: Add IP-User mapping 10.160.103.32 - TEST\MSOL_956e694d46b7 Succeeded - PIP notification %ASA-4-113019: Group = DefaultWEBVPNGroup, Username = user.name, IP = 90.90.90.90, Session disconnected. Session Type: SSL, Duration: 8h:46m:04s, By Another issue that filebeat unable to start after installation with enabled cisco module (filebeat 7.10.0, Debian 10)
Kibana search screenshots |
I can quickly comment on the Umbrella side, there has been a fix created for this, so the workaround should not need to be applied in the next release: For the different events that is not being ingested I would need to come back to you on that one. |
Hello, The bug is still exists for filebeat 7.11.1 021-03-01T10:13:07.610Z ERROR fileset/factory.go:121 Error checking input configuration: No paths were defined for input accessing config |
Looks like my current issue is relevant to this elastic/beats#24721 |
Hi all, %ASA-7-734003: DAP: User name , Addr ipaddr : Session Attribute: attr name/value Possible Attributes for example:
So in this case, the asa syslog would send 8 syslog messages all with the same username and every single Attribute. |
Some notes from me. Filebeat 7.15.1 |
Hi! We're labeling this issue as |
Transferring to integrations repo. |
Hi! We just realized that we haven't looked into this issue in a while. We're sorry! We're labeling this issue as |
While the Cisco module provides coverage for some ASA authentication events, we regularly see requests for broader coverage of both authentication and VPN events.
Attached sheet includes all the relevant events that should be covered by the module.
Cisco ASA Auth and VPN Events.xlsx
The text was updated successfully, but these errors were encountered: