Filebeat Modules
#10843
Replies: 2 comments 2 replies
-
Sorry for being a noob, just trying to understand. Is it possible to have a module parse the syslog messages coming in? Or does it have to come in on a separate port for it to work correctly? |
Beta Was this translation helpful? Give feedback.
0 replies
-
What does you cisco filebeat pillar look like? When setting up the module, I usually use the default ports in https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-cisco.html |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Can we get better documentation on enable Filebeat Modules like Cisco modules.
I've got netflow to work and trying to just enable the cisco modules and hopefully allow it work with the generic syslog udp 514.
I can mimic the netflow and or other modules used in the example but the modules for cisco is configured but has no enabled filesets.
Reading searching these dicussions for modules all leads to something similar but have not found a working solution.
Please note that I'm just using this as a test bed next to another siem solution to compare differences. I don't fully understand how using salt to manage configs for the docker containers and verifying the troubleshooting steps unless they are spelled out in the discussions.
Beta Was this translation helpful? Give feedback.
All reactions