Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Cisco IOS Integration] Events are cutted / Error #7152

Open
makkaroni8 opened this issue Jul 26, 2023 · 3 comments
Open

[Cisco IOS Integration] Events are cutted / Error #7152

makkaroni8 opened this issue Jul 26, 2023 · 3 comments
Labels
bug Something isn't working Integration:CiscoIOS Cisco IOS Team:Security-Deployment and Devices Deployment and Devices Security team

Comments

@makkaroni8
Copy link

Hi,
I'm encountering an issue where an event is being interrupted / Error. In my old syslog I get this message:
630774: Jul 26 14:22:19.367 MESZ: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint XXXXXX failed Reason : Failed to select socket. Timeout : 5 (Connection timed out)
But the following comes to ELK
<187>488117: DHVCA2: 300874: Jul 26 14:22:19.367 MESZ: %PKI-3-CRL_FETCH_FAIL: CRL fetch for trustpoint XXXXXX failed

I'm not sure if this is the same problem. but I also get this:
<187>422153: KSCA-MKZ: Reason : Failed to select socket. Timeout : 5 (Connection timed out)
and i get this error
Processor "dissect" with tag "dissect_header" in pipeline "logs-cisco_ios.log-1.16.2" failed with message "Unable to find match for dissect pattern: %{_temp_.header} %%{message} against source: <187>422153: KSCA-MKZ: Reason : Failed to select socket. Timeout : 5 (Connection timed out) "
I'm not sure if this error is my fault, but I have no idea how to fix it.

@elasticmachine
Copy link

Pinging @elastic/security-external-integrations (Team:Security-External Integrations)

@efd6
Copy link
Contributor

efd6 commented Jul 27, 2023

@makkaroni8 Can you provide complete documents for the events that you believe are corrupted, with the preserve original event option turned on? It is not clear to me what the issue is here; the first example looks fine and the second example is an invalid message, so the error is expected.

@narph narph added Team:Security-Deployment and Devices Deployment and Devices Security team and removed Team:Security-External Integrations labels Jan 29, 2024
@taylor-swanson taylor-swanson added the bug Something isn't working label Mar 4, 2024
@pkoutsovasilis
Copy link
Contributor

I will kindly make the the same request as the comment above. Having such documents, with the preserve original event option turned on, are gonna be tremendously beneficial to tackle this one 🙂

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working Integration:CiscoIOS Cisco IOS Team:Security-Deployment and Devices Deployment and Devices Security team
Projects
None yet
Development

No branches or pull requests

7 participants