Cisco ASA Content Pack

The following content pack is available for use with a Graylog Illuminate license and Graylog Enterprise or Graylog Security. Contact sales to learn more about obtaining Illuminate.

The Cisco ASA (Adaptive Security Appliance) is a multipurpose firewall appliance from Cisco, typically used for packet filtering but also supporting stateful inspection, application inspection, NAT, DHCP, routing, and VPN. This technology pack processes Cisco ASA and Firepower logs, providing normalization and enrichment of common events of interest.

Supported Version(s)

  • Cisco ASA: up to version 9.x

  • Cisco Firepower: 7.1 and higher

Requirements

  • Configure Cisco ASA device(s) to transmit syslog to your Graylog server syslog input. See Cisco's documentation, Configure Adaptive Security Appliance (ASA) Syslog, for details.

  • Graylog raw or syslog input. The ASA syslog format may be rejected by a standard Graylog syslog input because it is not RFC-compliant; configure RFC 5424 output on the ASA to use a syslog input, or send the logs to a raw input instead.

  • Graylog Server 5.0.3 or later with a valid Enterprise license.

Stream Configuration

This technology pack includes 1 stream:

  • "Illuminate:Cisco Device Messages"

Hint: If this stream does not exist prior to the activation of this pack then it is created and configured to route messages to this stream and the associated index set. There should not be any stream rules configured for this stream.

Index Set Configuration

This technology pack includes 1 index set definition:

  • "Cisco Devices Event Log Messages"

Hint: If this index set is already defined, then nothing is changed. If this index set does not exist, then it is created with retention settings of a daily rotation and 90 days of retention. These settings can be adjusted as required after installation.

Log Format Example

%ASA-6-302013: Built outbound TCP connection 12345 for outside:203.0.113.10/443 (203.0.113.10/443) to inside:192.168.1.100/54321 (192.168.1.100/54321) %ASA-6-302014: Teardown TCP connection 12345 for outside:203.0.113.10/443 to inside:192.168.1.100/54321 duration 0:00:05 bytes 4096 TCP FINs %ASA-4-106023: Deny tcp src outside:91.218.115.144/42778 dst outside:12.41.64.11/53 by access-group "outside_access_in_1" [0x0, 0x0] %ASA-6-605005: Login permitted from 192.168.1.10/22 to inside:192.168.1.1/ssh for user "admin" %ASA-3-605004: Login failed from 192.168.1.10/22 to inside:192.168.1.1/ssh for user "baduser" %ASA-5-111007: Begin configuration: 192.168.0.100 reading from http [POST] %ASA-5-111008: User 'admin' executed the 'show running-config' command. Jul 13 2021 14:13:19: %FTD-6-302014: Teardown TCP connection 8065 for inside:10.10.0.100/50511 to identity:172.10.124.136/51311 duration 0:00:00 bytes 422 TCP Reset-I %ASA-1-338002: Threat-detection detected a host scan from outside:91.218.115.1, average rate 30 acl-drop per sec, is above configured rate-interval %ASA-3-106001: Inbound TCP connection denied from 91.218.115.1/1234 to 192.168.1.1/80 flags SYN on interface outside

What is Provided

  • Parsing rules to extract Cisco ASA and Firepower logs into Graylog schema compatible fields.

  • Field extraction, normalization, and message enrichment for all supported event IDs.

  • GIM event categorization for 300+ event IDs.

  • Cisco ASA Spotlight dashboards: ASA/Firepower Overview (Overview, Network, Device Authentication, High Priority Messages tabs) and IDS/IPS Messages.

Events Processed by This Technology Pack

This technology pack supports parsing and enrichment for the following Cisco message type prefixes (all normalized to event_source_product = CISCO-ASA):

  • %ASA

  • %FTD

  • %NGIPS

  • %NGFW

GIM Categorization

GIM categorization is provided for the following event codes:

Cisco ASA Spotlight

The Cisco ASA Spotlight offers two dashboards for monitoring Cisco ASA and Firepower events: an ASA/Firepower Overview dashboard with four tabs (Overview, Network, Device Authentication, High Priority Messages) and an IDS/IPS Messages dashboard.

ASA/Firepower Overview

Network

Device Authentication

High Priority Messages

IDS/IPS Messages