Indeed, the src_ip & dst_ip are different if the direction is inbound or outbound.
You will need to update the Logstash Cookbook page for Cisco ASA too, because we replace the pattern CISCOFW302020_302021 by two patterns (CISCOFW302020_302021_1 and CISCOFW302020_302021_2).
Migrated from: https://github.com/elastic/logstash/issues/1369 ....
Hi,
There is an issue with the built-in pattern for Cisco ASA firewalls. The line :
should be replaced by :
Indeed, the src_ip & dst_ip are different if the direction is inbound or outbound.
You will need to update the Logstash Cookbook page for Cisco ASA too, because we replace the pattern CISCOFW302020_302021 by two patterns (CISCOFW302020_302021_1 and CISCOFW302020_302021_2).