# Send logs from Cisco Firewall to Graylog

**URL:** <https://community.graylog.org/t/send-logs-from-cisco-firewall-to-graylog/27441>\
**Category:** Graylog Central (peer support)\
**Tags:** cisco, asa\
**Created:** [January 25, 2023, 2:55pm UTC](https://community.graylog.org/t/send-logs-from-cisco-firewall-to-graylog/27441 "2023-01-25T14:55:44Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![brkw](https://avatars.discourse-cdn.com/v4/letter/b/a587f6/32.png) [@brkw](https://community.graylog.org/u/brkw)\
**Post date:** [January 25, 2023, 2:55pm UTC](https://community.graylog.org/t/send-logs-from-cisco-firewall-to-graylog/27441/1 "2023-01-25T14:55:44Z")

</div>

Before you post: Your responses to these questions will help the community help you. Please complete this template if you’re asking a support question.  
**Don’t forget to select tags to help index your topic!**

**1. Describe your incident:**  
I’m looking for a way how to send only specific ID’s to Graylog server. I mean not all logs classified as warning, error or something, I just want to send a specific ID’s - for example if someone from inside trying to reach out any IP outside and one of my access list deny this request, the log ID is 106100.

**2. Describe your environment:**

- OS Information: Cisco ASA, Graylog is installed on Ubuntu 22.04

- Package Version: Graylog 5.0

- Service logs, configurations, and environment variables: that is I’m looking for how to configure

**3. What steps have you already taken to try and solve the problem?**  
Still nothing.

**4. How can the community help?**  
Advice.

**Helpful Posting Tips:** [Tips for Posting Questions that Get Answers](https://community.graylog.org/t/tips-for-posting-questions-that-get-answers/21828) [Hold down CTRL and link on link to open tips documents in a separate tab]

---

<div class="post-metadata">

**Author:** ![ihe](https://avatars.discourse-cdn.com/v4/letter/i/a88e57/32.png) [@ihe](https://community.graylog.org/u/ihe)\
**Post date:** [January 25, 2023, 4:56pm UTC](https://community.graylog.org/t/send-logs-from-cisco-firewall-to-graylog/27441/2 "2023-01-25T16:56:46Z")

</div>

As far as I remember ASA, you can decide up to which log-level you want to send logs. You can also change the log-level per ID if I remember correctly. With those both properties you can send logs to Graylog.

If you receive more in Graylog than you want you can delete Logs based on their ID:

1. build a rule to extract the ID in a certain field, we call it asa\_syslog\_id
2. create a rule if the field has a certain value to drop the message

---

<div class="post-metadata">

**Author:** ![joe.gross](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/joe.gross/32/13372_2.png) [@joe.gross](https://community.graylog.org/u/joe.gross)\
**Post date:** [January 25, 2023, 4:59pm UTC](https://community.graylog.org/t/send-logs-from-cisco-firewall-to-graylog/27441/3 "2023-01-25T16:59:28Z")

</div>

Or, if your list of event, ideas is very short, you can build a rule that throws away any message that does not contain your specific IDs. Boolean operators in pipelines are very useful for this.

---

<div class="post-metadata">

**Author:** ![brkw](https://avatars.discourse-cdn.com/v4/letter/b/a587f6/32.png) [@brkw](https://community.graylog.org/u/brkw)\
**Post date:** [January 25, 2023, 5:31pm UTC](https://community.graylog.org/t/send-logs-from-cisco-firewall-to-graylog/27441/4 "2023-01-25T17:31:44Z")

</div>

I think that my list is really short. My goal is to drop the logs on the source - Cisco. It’s not necessary to receive all logs to the Graylog server and drop it there - it will exhaust my SSD soon.

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [January 25, 2023, 11:02pm UTC](https://community.graylog.org/t/send-logs-from-cisco-firewall-to-graylog/27441/5 "2023-01-25T23:02:46Z")

</div>

Hey @brkw

The suggestion that @ihe stated might help, for example you can set the _Severity Levels_ for warning/critical etc… that may help to reduce the amount of logs your receiving.

---

<div class="post-metadata">

**Author:** ![joe.gross](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/joe.gross/32/13372_2.png) [@joe.gross](https://community.graylog.org/u/joe.gross)\
**Post date:** [January 26, 2023, 4:55pm UTC](https://community.graylog.org/t/send-logs-from-cisco-firewall-to-graylog/27441/6 "2023-01-26T16:55:02Z")

</div>

You may be surprised. Dropping messages as soon as they arrive does not require much I/O.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [February 9, 2023, 4:55pm UTC](https://community.graylog.org/t/send-logs-from-cisco-firewall-to-graylog/27441/7 "2023-02-09T16:55:27Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
