This repository has been archived by the owner on Mar 22, 2024. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 589
Cisco ASA Netflow Missing "switched" and other fields #22
Labels
Comments
ASA is using different fields in unix EPOCH time
|
Even better this works for the new ASA and fixes all errors |
Thanks for the sample event. That is helpful. Let me see what I can come up with. |
@robcowart am happy to test if you need a tester. we don't have an ASA but maybe related? I'm only seeing data in a few viz: i have captures of my data if that helps |
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Pulling from a 5525X on ASA 9.2 i'm seeing issues identical to those reported in #18. They seem to be caused by the ingest data missing fields referenced in the searches, the index pattern time calcs, all of it. Cisco docs indicate that while they export at v9, they use non-standard tuples (of course). Here's an event sample for which fields are present, hopefully there's a rational way to compose the missing fields or update the searches for this given its widespread use:
This works on pf/opnsense very well, any advice on getting Cisco to play ball with it (or more likely the other way around) would be appreciated.
The text was updated successfully, but these errors were encountered: