# Issue with application\_name field

**URL:** <https://community.graylog.org/t/issue-with-application-name-field/16930>\
**Category:** Graylog Central (peer support)\
**Tags:** pipeline-rules\
**Created:** [August 26, 2020, 12:27pm UTC](https://community.graylog.org/t/issue-with-application-name-field/16930 "2020-08-26T12:27:17Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Fabou78](https://avatars.discourse-cdn.com/v4/letter/f/9de053/32.png) [@Fabou78](https://community.graylog.org/u/Fabou78)\
**Post date:** [August 26, 2020, 12:27pm UTC](https://community.graylog.org/t/issue-with-application-name-field/16930/1 "2020-08-26T12:27:17Z")

</div>

I am running version 3.3.4 and I had setup a stream that was looking into the application\_name field in syslog messages received from ASA firewall as it seemed to be available without any specific configuration. All of this on a Syslog TCP input.

application\_name must match exactly %ASA-4-722037

From there I was using a pipeline to add some other custom fields and it was all working fine until I configure the command “logging device-id hostname” on my firewalls.

After this change on the firewalls graylog stopped recognising the application\_name field for reasons that I can’t understand.

According to the doc here [https://docs.graylog.org/en/3.3/pages/configuration/elasticsearch.html#custom-index-mappings](https://docs.graylog.org/en/3.3/pages/configuration/elasticsearch.html#custom-index-mappings) there should only be four default field timestamp, message, full\_message, and source.

Any idea on where the field application\_name was coming from in the first place?  
Why forcing name on firewalls would cause this to stop working?

I don’t have a clue on where to start looking to troubleshoot this I would like to understand it before I look into changing the stream rules (use something different then application\_name)

---

<div class="post-metadata">

**Author:** ![Fabou78](https://avatars.discourse-cdn.com/v4/letter/f/9de053/32.png) [@Fabou78](https://community.graylog.org/u/Fabou78)\
**Post date:** [September 2, 2020, 5:27pm UTC](https://community.graylog.org/t/issue-with-application-name-field/16930/2 "2020-09-02T17:27:11Z")

</div>

Anyone have any idea about the above?

---

<div class="post-metadata">

**Author:** ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)\
**Post date:** [September 2, 2020, 6:13pm UTC](https://community.graylog.org/t/issue-with-application-name-field/16930/3 "2020-09-02T18:13:29Z")

</div>

It’s very obvious, why it happend. Graylog by default parse normal syslog messages format, so `%ASA-4-722037` is parsed as application\_name field. So if use cisco command to include hostname, it moved `%ASA-4-722037` field to the right, so graylog use another field as appliacation\_name. Because Cisco don’t follow cisco standard, best way is to setup Raw Syslog input and use pipeline rules to correctly extract field.

Check this great article for explanation:

> **[Working with Cisco ASA / Nexus on Graylog](https://jalogisch.de/2018/working-with-cisco-asa-nexus-on-graylog/)**
>
> It is hard to have a working centralized logging environment when you run network devices. Every vendor has his own version and understanding of syslog. Additional most did not speak any kind of structured log format. Some speak some binary format. ...

---

<div class="post-metadata">

**Author:** ![Fabou78](https://avatars.discourse-cdn.com/v4/letter/f/9de053/32.png) [@Fabou78](https://community.graylog.org/u/Fabou78)\
**Post date:** [September 3, 2020, 9:40am UTC](https://community.graylog.org/t/issue-with-application-name-field/16930/4 "2020-09-03T09:40:08Z")

</div>

Thanks for your input, there is/was no mention about the application\_name field in the documentation so I was not sure where it was coming from. Also when I removed the command from the ASA device that field didn’t come back in Graylog…

Never used lookup before so I will try implementing what’s on the article.

Do you have any idea what he mean by “All of the above is needed with Graylog 2.4 - as of the new features in Graylog 3, this above would just be a content pack that includes everything.” in the article?

Not sure what content pack is.

---

<div class="post-metadata">

**Author:** ![shoothub](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/shoothub/32/6412_2.png) [@shoothub](https://community.graylog.org/u/shoothub)\
**Post date:** [September 3, 2020, 11:41am UTC](https://community.graylog.org/t/issue-with-application-name-field/16930/5 "2020-09-03T11:41:54Z")

</div>

Content pack is collection of extractors, pipeline rules, inputs, grok etc. so you can export as json file and import (backup) to another system (for sharing). Check docs.

[https://docs.graylog.org/en/3.3/pages/content\_packs.html](https://docs.graylog.org/en/3.3/pages/content_packs.html)

> **[Introduction to Content Packs | Graylog](https://www.graylog.org/features/content-packs)**
>
> Content Packs are collections of pre-built inputs, processing intelligence, display templates, and outputs (Alerts and Report).

I think, that it means, that all grok, pipeline rules, lookup tables can be exported as one content pack. In 2.4 version, some features to export some data was not possible as in newer graylog version

---

<div class="post-metadata">

**Author:** ![Fabou78](https://avatars.discourse-cdn.com/v4/letter/f/9de053/32.png) [@Fabou78](https://community.graylog.org/u/Fabou78)\
**Post date:** [September 3, 2020, 11:45am UTC](https://community.graylog.org/t/issue-with-application-name-field/16930/6 "2020-09-03T11:45:30Z")

</div>

Thanks a lot, I will read up on this

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [September 17, 2020, 11:45am UTC](https://community.graylog.org/t/issue-with-application-name-field/16930/7 "2020-09-17T11:45:47Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
