# Cisco FTD logging messages being ignored and wrong source

**URL:** <https://community.graylog.org/t/cisco-ftd-logging-messages-being-ignored-and-wrong-source/21070>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules\
**Created:** [September 2, 2021, 2:29pm UTC](https://community.graylog.org/t/cisco-ftd-logging-messages-being-ignored-and-wrong-source/21070 "2021-09-02T14:29:47Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![pepperoni-pi](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/pepperoni-pi/32/9424_2.png) [@pepperoni-pi](https://community.graylog.org/u/pepperoni-pi)\
**Post date:** [September 2, 2021, 2:29pm UTC](https://community.graylog.org/t/cisco-ftd-logging-messages-being-ignored-and-wrong-source/21070/1 "2021-09-02T14:29:48Z")

</div>

## Description of your problem

I set up a Graylog demo for myself and it has been going pretty well. The main issues that I am encountering are related to Cisco FTDs (which are essentially virtual ASAs). The Syslog UDP input has trouble indexing the various parts of the messages or even just ignores the logs entirely. Is there a way to see if logs are being discarded? The source is often indexed improperly and ends up showing as the month (Aug/Sep) instead of the source IP or hostname.

#Captured by Sylog UDP input but using a packet capture I found that it doesn’t have PRI field so no facility or log level are found leaving them as Unknown and -1.  
`Sep 02 2021 13:05:44 192.168.22.1 %FTD-6-430002: DeviceUUID: a12a9578-56ab-11eb-8010-87b13c2c7c5d, AccessControlRuleAction: Allow, SrcIP: 192.168.2.213, DstIP: 10.10.10.10, SrcPort: 61243, DstPort: 49680, Protocol: tcp, IngressInterface: outside, EgressInterface: inside, IngressZone: outside-fw1, EgressZone: inside-fw1, ACPolicy: Firewall, AccessControlRuleName: outside-in-1, Prefilter Policy: Default Prefilter Policy, User: No Authentication Required, InitiatorPackets: 2, ResponderPackets: 1, InitiatorBytes: 120, ResponderBytes: 66, NAPPolicy: Balanced Security and Connectivity`

#Not captured by Syslog UDP input and does have PRI field  
`<190>Sep 02 14:04:59 192.168.22.1 : %FTD-6-302016: Teardown UDP connection 13584982 for outside:192.168.2.213/61654(LOCAL\user1) to inside:10.10.10.10/53 duration 0:00:00 bytes 0 (user1)`

## Description of steps you’ve taken to attempt to solve the issue

For now, I’m using Raw/Plaintext UDP and seeing all of the messages, but unfortunately nothing is indexed using this input and I’ll have to create all of the indexing myself. Obviously, this is not ideal especially because I can’t seem to find a way to index the portions in the PRI field (log level and facility). It would be nice to use the Syslog UDP input because it already handles this except that it seems to be discarding a large number of messages sent by the FTDs. To address the source issue, I had to create a pipeline to write the gl2\_remote\_ip as the source and then attempt a reverse dns lookup to convert it to the FQDN if it exists. Then an extractor removes the domain leaving just the hostname.

## Environmental information

Integration with LibreNMS. Mostly Cisco devices.

### Operating system information

Ubuntu 20.04

### Package versions

Graylog - 4.1.3+9d79c05  
MongoDB - v4.0.26  
Elasticsearch - 7.10.2

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [September 3, 2021, 12:29am UTC](https://community.graylog.org/t/cisco-ftd-logging-messages-being-ignored-and-wrong-source/21070/2 "2021-09-03T00:29:37Z")

</div>

Hello && Welcome

When setting up our Input for Cisco Switches we had the same problems with Syslog UDP and just like yourself we switched to Raw/Plaintext UDP. I’ll try to answer some of your questions.

> [@pepperoni-pi](#):
>
> Is there a way to see if logs are being discarded?

On the Graylog Server, not that I know of. Basically, I had to do the same as yourself, run a packet capture.

> [@pepperoni-pi](#):
>
> unfortunately nothing is indexed using this input and I’ll have to create all of the indexing myself.

Could you elaborate further on this? Are you referring to the Syslog UDP input or Raw/Plaintext?

> [@pepperoni-pi](#):
>
> Obviously, this is not ideal especially because I can’t seem to find a way to index the portions in the PRI field (log level and facility).

There are probably a couple ways of doing this. What we did was use the Raw/Paintex UDP input. Then we created some regex extractors to have fields that were needed (log level and facility) for searching, dashboards, etc… I seen you are using a pipeline, that is another option if preferred. We had done the same with a pipeline for FQDN. One of our problems was settings. This was in System/Configurations. We had to adjusting our order in which these processors were applied.

Example:

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/6/63faf65ad25b16f905ef88d653053b32978f83ee.png)

Maybe something here can help

> **[the NEW Marketplace](https://community.graylog.org/c/marketplace/31)**
>
> Find, explore, and try out Graylog add-ons created by Graylog community members and enthusiasts. Plugins, extractors, content packs and GELF libraries are available as well as guides and documentation.

Sorry I cant give you a direct answer on the Syslog UDP input.

---

<div class="post-metadata">

**Author:** ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)\
**Post date:** [September 3, 2021, 10:47am UTC](https://community.graylog.org/t/cisco-ftd-logging-messages-being-ignored-and-wrong-source/21070/3 "2021-09-03T10:47:41Z")

</div>

Hi @pepperoni-pi  
Cisco facility and serverity is also contained in messages, they uses syntax: `%facility-severity-MNEMONIC:description`

In case of FTD, facility is always FTD and severity is number from 1 - 7  
So you can use this simple GROK to parse it:

```auto
\\%FTD-%{DATA:ftd_severity:int}-%{DATA:ftd_messageid}: %{GREEDYDATA:cisco_msg}

```

> **[Cisco ASA 5500 Series Configuration Guide using the CLI, 8.4 and 8.6 -...](https://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/monitor_syslog.html#95407)**
>
> Configuring Logging

> **[Cisco ASA Series Syslog Messages - Messages Listed by
	 Severity Level...](https://www.cisco.com/c/en/us/td/docs/security/asa/syslog/b_syslog/messages-listed-by-severity-level.html)**
>
> Messages Listed by
> Severity Level

Try to play with default syslog format or EMBLEM format.

> **[Cisco ASA 5500 Series Configuration Guide using the CLI, 8.4 and 8.6 -...](https://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/monitor_syslog.html#93979)**
>
> Configuring Logging

If you want to include hostname of FTD in messages non EMBLEM format, configure it in cisco:  
`logging device-id hostname` instead of `ipaddress`

> **[Cisco ASA 5500 Series Configuration Guide using the CLI, 8.4 and 8.6 -...](https://www.cisco.com/c/en/us/td/docs/security/asa/asa84/configuration/guide/asa_84_cli_config/monitor_syslog.html#97915)**
>
> Configuring Logging

Then you can extend GROK to include also hostname and save it as source.

---

<div class="post-metadata">

**Author:** ![pepperoni-pi](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/pepperoni-pi/32/9424_2.png) [@pepperoni-pi](https://community.graylog.org/u/pepperoni-pi)\
**Post date:** [September 3, 2021, 5:11pm UTC](https://community.graylog.org/t/cisco-ftd-logging-messages-being-ignored-and-wrong-source/21070/4 "2021-09-03T17:11:34Z")

</div>

@gsmith

> [@gsmith](#):
>
> > [@pepperoni-pi](#):
> >
> > unfortunately nothing is indexed using this input and I’ll have to create all of the indexing myself.
> 
> Could you elaborate further on this? Are you referring to the Syslog UDP input or Raw/Plaintext?

I was referring to the Raw/Plaintext input. It only indexes the source and message fields.

> [@gsmith](#):
>
> > [@pepperoni-pi](#):
> >
> > Obviously, this is not ideal especially because I can’t seem to find a way to index the portions in the PRI field (log level and facility).
> 
> There are probably a couple ways of doing this. What we did was use the Raw/Paintex UDP input. Then we created some regex extractors to have fields that were needed (log level and facility) for searching, dashboards, etc… I seen you are using a pipeline, that is another option if preferred. We had done the same with a pipeline for FQDN. One of our problems was settings. This was in System/Configurations. We had to adjusting our order in which these processors were applied.

The problem I’m running into is that I can’t seem to find a way to extract the facility and log level from the syslog packet header. [RFC5424](https://datatracker.ietf.org/doc/html/rfc5424#section-6.2). Clip from Wireshark capture:

 ![Screen Shot 2021-09-03 at 1.03.37 PM](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/1/1dfdf5756c0eb709dbcf4b7bee4caa1b350e7820.png)  
The log level could be extracted from the “FTD-6-302016” portion, but the facility isn’t in the message portion of the packet. Is there another variable besides $message available in pipeline rules or a sub level like $message.header that contains the eight bit header value?

Thanks for letting me know about the Graylog Marketplace. I’m new to Graylog so I was not aware that even existed.

---

<div class="post-metadata">

**Author:** ![pepperoni-pi](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/pepperoni-pi/32/9424_2.png) [@pepperoni-pi](https://community.graylog.org/u/pepperoni-pi)\
**Post date:** [September 3, 2021, 5:57pm UTC](https://community.graylog.org/t/cisco-ftd-logging-messages-being-ignored-and-wrong-source/21070/5 "2021-09-03T17:57:08Z")

</div>

@shoothub

> [@shoothub](#):
>
> Cisco facility and serverity is also contained in messages, they uses syntax: `%facility-severity-MNEMONIC:description`
> 
> In case of FTD, facility is always FTD and severity is number from 1 - 7

But FTD is not the facility. Facility is a number between 0 - 23 ([RFC5424](https://datatracker.ietf.org/doc/html/rfc5424#section-6.2)) that is found in the packet header. The log level can be extracted from “FTD-6-302016”, but the facility can only be found in the packet header. I’m trying to figure out what variable contains the packet header. In pipeline rules, I’m using things like $message.gl2\_remote\_ip. Is there a variable that contains the 8-bit header like $message.header?

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [September 4, 2021, 1:36am UTC](https://community.graylog.org/t/cisco-ftd-logging-messages-being-ignored-and-wrong-source/21070/6 "2021-09-04T01:36:59Z")

</div>

Hello,  
I was researching this issue and came across this. Not sure if you seen this yet.

[Configure Global Syslog Configuration](https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200479-Configure-Logging-on-FTD-via-FMC.html#:~:text=in%20this%20image.-,Configure%20Global%20Syslog%20Configuration,-There%20are%20certain)

I was wondering is how you configured your Cisco setting for logging?

---

<div class="post-metadata">

**Author:** ![pepperoni-pi](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/pepperoni-pi/32/9424_2.png) [@pepperoni-pi](https://community.graylog.org/u/pepperoni-pi)\
**Post date:** [September 7, 2021, 3:43pm UTC](https://community.graylog.org/t/cisco-ftd-logging-messages-being-ignored-and-wrong-source/21070/7 "2021-09-07T15:43:12Z")

</div>

> [@gsmith](#):
>
> Configure Global Syslog Configuration

That page looks familiar. Pretty sure I’ve used that when setting up the syslog configuration on the firewall. The firewall configuration is not the issue though. What I’m trying to figure out is how to extract the the facility and log level from the header.

---

<div class="post-metadata">

**Author:** ![pepperoni-pi](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/pepperoni-pi/32/9424_2.png) [@pepperoni-pi](https://community.graylog.org/u/pepperoni-pi)\
**Post date:** [September 7, 2021, 8:59pm UTC](https://community.graylog.org/t/cisco-ftd-logging-messages-being-ignored-and-wrong-source/21070/8 "2021-09-07T20:59:42Z")

</div>

I’m giving up on the default Syslog UDP input and switching to Raw/Plaintext UDP and pipelining out all the data I need. I’m going to start a new thread just around getting the facility and log level out of the header.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [September 21, 2021, 9:00pm UTC](https://community.graylog.org/t/cisco-ftd-logging-messages-being-ignored-and-wrong-source/21070/9 "2021-09-21T21:00:26Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
