# Cisco Logs | Graylog

**URL:** <https://community.graylog.org/t/cisco-logs-graylog/3772>\
**Category:** Graylog Central (peer support)\
**Created:** [January 11, 2018, 6:52pm UTC](https://community.graylog.org/t/cisco-logs-graylog/3772 "2018-01-11T18:52:50Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![itsmebalaji](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/itsmebalaji/32/1574_2.png) [@itsmebalaji](https://community.graylog.org/u/itsmebalaji)\
**Post date:** [January 11, 2018, 6:52pm UTC](https://community.graylog.org/t/cisco-logs-graylog/3772/1 "2018-01-11T18:52:50Z")

</div>

Dear Graylog Team ,

Is there any way in order to Make Cisco logs more comfortable in Graylog through any plugins

For an example if am getting authentication fail logs how to extrace source , Destination , Port , and userid from the message and send an alert Via Mail

Is there any way to customer the email alert rather than sending it glimpsy can we make it in a summarized manner

Please help me on this

---

<div class="post-metadata">

**Author:** ![zionio](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/zionio/32/926_2.png) [@zionio](https://community.graylog.org/u/zionio)\
**Post date:** [January 12, 2018, 10:57am UTC](https://community.graylog.org/t/cisco-logs-graylog/3772/2 "2018-01-12T10:57:06Z")

</div>

Maybe this can help:

> [@Is it possible to send Cisco Switch logs to Graylog](https://community.graylog.org/t/is-it-possible-to-send-cisco-switch-logs-to-graylog/3479/5):
>
> you will only need to define a Syslog Input on Graylog and after that configure your devices to send their syslog message to that created input. [http://docs.graylog.org/en/2.3/pages/sending\_data.html#syslog](http://docs.graylog.org/en/2.3/pages/sending_data.html#syslog) You might find some of the available content packs and descriptions in the marketplace useful.

---

<div class="post-metadata">

**Author:** ![itsmebalaji](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/itsmebalaji/32/1574_2.png) [@itsmebalaji](https://community.graylog.org/u/itsmebalaji)\
**Post date:** [January 12, 2018, 11:18am UTC](https://community.graylog.org/t/cisco-logs-graylog/3772/3 "2018-01-12T11:18:06Z")

</div>

Hey Zionio ,

I was able to receive cisco messages from syslog into graylog i want to extract source ip , destination ip , from the message can i know how

---

<div class="post-metadata">

**Author:** ![jan](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/jan/32/11_2.png) [@jan](https://community.graylog.org/u/jan)\
**Post date:** [January 12, 2018, 11:38am UTC](https://community.graylog.org/t/cisco-logs-graylog/3772/4 "2018-01-12T11:38:10Z")

</div>

for that you use extractors or the processing pipeline.

---

<div class="post-metadata">

**Author:** ![zionio](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/zionio/32/926_2.png) [@zionio](https://community.graylog.org/u/zionio)\
**Post date:** [January 12, 2018, 12:23pm UTC](https://community.graylog.org/t/cisco-logs-graylog/3772/5 "2018-01-12T12:23:59Z")

</div>

as @jan said you can check on GL marketplace [https://marketplace.graylog.org/addons?search=cisco](https://marketplace.graylog.org/addons?search=cisco)

Hope this helps 🤔

---

<div class="post-metadata">

**Author:** ![itsmebalaji](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/itsmebalaji/32/1574_2.png) [@itsmebalaji](https://community.graylog.org/u/itsmebalaji)\
**Post date:** [January 12, 2018, 1:27pm UTC](https://community.graylog.org/t/cisco-logs-graylog/3772/6 "2018-01-12T13:27:42Z")

</div>

Already tried this , no use of it

---

<div class="post-metadata">

**Author:** ![itsmebalaji](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/itsmebalaji/32/1574_2.png) [@itsmebalaji](https://community.graylog.org/u/itsmebalaji)\
**Post date:** [January 12, 2018, 1:35pm UTC](https://community.graylog.org/t/cisco-logs-graylog/3772/7 "2018-01-12T13:35:07Z")

</div>

I have tried but unable to extract source ip and destination from a single message

One of the log example :  
100.65.203.6 334: Jan 12 15:43:55.889 IST: %SW\_MATM-4-MACFLAP\_NOTIF: Host 10f3.1149.2f20 in vlan 862 is flapping between port Gi0/26 and port Gi0/25

Please help me with the extraction of Source IP , Mac address , Vlan And ports

---

<div class="post-metadata">

**Author:** ![zionio](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/zionio/32/926_2.png) [@zionio](https://community.graylog.org/u/zionio)\
**Post date:** [January 12, 2018, 2:15pm UTC](https://community.graylog.org/t/cisco-logs-graylog/3772/8 "2018-01-12T14:15:01Z")

</div>

Based on log example, you can create a GROK extractor with:

> %{IPV4:source\_ip} %{GREEDYDATA} Host %{DATA:mac\_accdress} in vlan %{INT:vlan} is flapping between port %{GREEDYDATA:port\_a} and port %{GREEDYDATA:port\_b}

Remember to check: Named captures only

 ![](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/e/e4cc41adedaa9d5ec16361da5cf62c1549b96482.png)

Hope this helps 🤔

---

<div class="post-metadata">

**Author:** ![itsmebalaji](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/itsmebalaji/32/1574_2.png) [@itsmebalaji](https://community.graylog.org/u/itsmebalaji)\
**Post date:** [January 14, 2018, 12:04pm UTC](https://community.graylog.org/t/cisco-logs-graylog/3772/9 "2018-01-14T12:04:56Z")

</div>

> [@itsmebalaji](#):
>
> MACFLAP\_NOTIF

Ziono I have applied the gork pattern but its not displaying in Graylog main page Field value

---

<div class="post-metadata">

**Author:** ![zionio](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/zionio/32/926_2.png) [@zionio](https://community.graylog.org/u/zionio)\
**Post date:** [January 16, 2018, 4:43pm UTC](https://community.graylog.org/t/cisco-logs-graylog/3772/10 "2018-01-16T16:43:17Z")

</div>

Can you show me a log example that did not match the GROK pattern created ?

---

<div class="post-metadata">

**Author:** ![itsmebalaji](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/itsmebalaji/32/1574_2.png) [@itsmebalaji](https://community.graylog.org/u/itsmebalaji)\
**Post date:** [January 20, 2018, 6:55am UTC](https://community.graylog.org/t/cisco-logs-graylog/3772/11 "2018-01-20T06:55:09Z")

</div>

It has been started working , is it possible to send the gork fields in email alert

I mean i have extracted a specific fields from the message is it possible send only these fields in email alert

Thanks & Regards ,  
Balaji

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [February 3, 2018, 6:55am UTC](https://community.graylog.org/t/cisco-logs-graylog/3772/12 "2018-02-03T06:55:12Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
