We are using the ingest pipelines of some integrations as the basis as how we should classify our events in our Logstash Pipelines.
We have logs from both Cisco ASA and Cisco FTD, and while checking the ingest pipelines of those integrations I noticed that at least one cisco message id has a wrong classification.
The message id 302020 is, according to the Cisco documentation, a Built event, which would mean that a session was established, but in the ingest pipeline of both ASA and FTD, it is being treated as a Teardown event, which would mean that a session was terminated.
This part of the ingest pipeline for the cisco asa integration, sets the field event.action for event 302020 as flow-expiration.
The action for the 302020 event should be flow-creation.
Further in the pipeline the value of the event.action is used to create the field event.kind, event.category and event.type, so the event 302020 would have the following event fields.
event.action: flow-expiration
event.kind: event
event.category: network
event.type: [connection, end]
I think that the correct values for those fields should be:
event.action: flow-creation
event.kind: event
event.category: network
event.type: [connection, start]
This happens with the Cisco ASA integration, the Cisco FTD integration and also the Cisco ASA/FTD module in Filebeat.
Hello,
We are using the ingest pipelines of some integrations as the basis as how we should classify our events in our Logstash Pipelines.
We have logs from both Cisco ASA and Cisco FTD, and while checking the ingest pipelines of those integrations I noticed that at least one cisco message id has a wrong classification.
The message id
302020
is, according to the Cisco documentation, a Built event, which would mean that a session was established, but in the ingest pipeline of both ASA and FTD, it is being treated as a Teardown event, which would mean that a session was terminated.This part of the ingest pipeline for the cisco asa integration, sets the field
event.action
for event302020
asflow-expiration
.The action for the
302020
event should beflow-creation
.Further in the pipeline the value of the
event.action
is used to create the fieldevent.kind
,event.category
andevent.type
, so the event302020
would have the following event fields.event.action
:flow-expiration
event.kind
:event
event.category
:network
event.type
: [connection
,end
]I think that the correct values for those fields should be:
event.action
:flow-creation
event.kind
:event
event.category
:network
event.type
: [connection
,start
]This happens with the Cisco ASA integration, the Cisco FTD integration and also the Cisco ASA/FTD module in Filebeat.