Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions packages/cisco_ios/changelog.yml
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# newer versions go on top
- version: "1.35.3"
changes:
- description: Fix observer.type classification precedence for Cisco IOS logs.
type: bugfix
link: https://github.com/elastic/integrations/issues/18432
- version: "1.35.2"
changes:
- description: Fix parsing of timestamps with timezone abbreviation.
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,3 +7,4 @@
<166>352134: ASR920: Aug 3 08:08:47.142: %SEC-6-IPACCESSLOGP: list ACL_CE-SECURITY denied udp 81.2.69.192(0) -> 224.0.0.252(0), 1 packet
<166>352133: ASR920: Aug 3 08:04:47.140: %SEC-6-IPACCESSLOGNP: list ACL_CE-SECURITY denied 112 89.160.20.112 -> 224.0.0.18, 295 packets
<163>81681: CORE: Aug 3 08:09:55.769: %SNMP-SW1-3-RESPONSE_DELAYED: processing Get of cefcFRUPowerStatusEntry.1.2030 (4620 msecs)
<190>: 2025 Jul 21 12:33:58 EAT: %AAA-6-AAA_ACCOUNTING_MESSAGE: update:process:NTP:New time: Mon Jul 21 12:33:57 2025
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,7 @@
},
"observer": {
"product": "IOS",
"type": "firewall",
"type": "router",
"vendor": "Cisco"
},
"related": {
Expand Down Expand Up @@ -107,7 +107,7 @@
},
"observer": {
"product": "IOS",
"type": "firewall",
"type": "router",
"vendor": "Cisco"
},
"related": {
Expand Down Expand Up @@ -172,7 +172,7 @@
},
"observer": {
"product": "IOS",
"type": "firewall",
"type": "router",
"vendor": "Cisco"
},
"related": {
Expand Down Expand Up @@ -229,7 +229,7 @@
"message": "(exec timer expired, tty 1 (192.168.0.1)), user username",
"observer": {
"product": "IOS",
"type": "firewall",
"type": "router",
"vendor": "Cisco"
},
"tags": [
Expand Down Expand Up @@ -271,15 +271,15 @@
"message": "Configured from console by username on vty1 (192.168.0.1)",
"observer": {
"product": "IOS",
"type": "firewall",
"type": "router",
"vendor": "Cisco"
},
"tags": [
"preserve_original_event"
]
},
{
"@timestamp": "2025-08-03T08:11:02.204Z",
"@timestamp": "2026-08-03T08:11:02.204Z",
"cisco": {
"ios": {
"facility": "LINEPROTO",
Expand Down Expand Up @@ -313,15 +313,15 @@
"message": "Line protocol on Interface GigabitEthernet0/0/7, changed state to up",
"observer": {
"product": "IOS",
"type": "firewall",
"type": "switch",
"vendor": "Cisco"
},
"tags": [
"preserve_original_event"
]
},
{
"@timestamp": "2025-08-03T08:08:47.142Z",
"@timestamp": "2026-08-03T08:08:47.142Z",
"cisco": {
"ios": {
"access_list": "ACL_CE-SECURITY",
Expand Down Expand Up @@ -400,7 +400,7 @@
]
},
{
"@timestamp": "2025-08-03T08:04:47.140Z",
"@timestamp": "2026-08-03T08:04:47.140Z",
"cisco": {
"ios": {
"access_list": "ACL_CE-SECURITY",
Expand Down Expand Up @@ -484,7 +484,7 @@
]
},
{
"@timestamp": "2025-08-03T08:09:55.769Z",
"@timestamp": "2026-08-03T08:09:55.769Z",
"cisco": {
"ios": {
"facility": "SNMP-SW1",
Expand Down Expand Up @@ -518,7 +518,45 @@
"message": "processing Get of cefcFRUPowerStatusEntry.1.2030 (4620 msecs)",
"observer": {
"product": "IOS",
"type": "firewall",
"type": "router",
"vendor": "Cisco"
},
"tags": [
"preserve_original_event"
]
},
{
"@timestamp": "2025-07-21T12:33:58.000+03:00",
"cisco": {
"ios": {
"facility": "AAA"
}
},
"ecs": {
"version": "8.17.0"
},
"event": {
"category": [
"network"
],
"code": "AAA_ACCOUNTING_MESSAGE",
"original": "<190>: 2025 Jul 21 12:33:58 EAT: %AAA-6-AAA_ACCOUNTING_MESSAGE: update:process:NTP:New time: Mon Jul 21 12:33:57 2025",
"provider": "firewall",
"severity": 6,
"type": [
"info"
]
},
"log": {
"level": "informational",
"syslog": {
"priority": 190
}
},
"message": "update:process:NTP:New time: Mon Jul 21 12:33:57 2025",
"observer": {
"product": "IOS",
"type": "router",
"vendor": "Cisco"
},
"tags": [
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"expected": [
{
"@timestamp": "2025-12-08T20:07:53.081Z",
"@timestamp": "2026-12-08T20:07:53.081Z",
"cisco": {
"ios": {
"facility": "TCP",
Expand Down Expand Up @@ -43,7 +43,7 @@
},
"observer": {
"product": "IOS",
"type": "firewall",
"type": "router",
"vendor": "Cisco"
},
"related": {
Expand All @@ -62,7 +62,7 @@
]
},
{
"@timestamp": "2025-12-08T20:07:53.081Z",
"@timestamp": "2026-12-08T20:07:53.081Z",
"cisco": {
"ios": {
"facility": "TCP",
Expand Down Expand Up @@ -104,7 +104,7 @@
},
"observer": {
"product": "IOS",
"type": "firewall",
"type": "router",
"vendor": "Cisco"
},
"related": {
Expand All @@ -123,7 +123,7 @@
]
},
{
"@timestamp": "2025-12-08T20:07:53.081Z",
"@timestamp": "2026-12-08T20:07:53.081Z",
"cisco": {
"ios": {
"facility": "TCP",
Expand Down Expand Up @@ -164,7 +164,7 @@
},
"observer": {
"product": "IOS",
"type": "firewall",
"type": "router",
"vendor": "Cisco"
},
"related": {
Expand All @@ -183,7 +183,7 @@
]
},
{
"@timestamp": "2025-12-08T20:07:53.081Z",
"@timestamp": "2026-12-08T20:07:53.081Z",
"cisco": {
"ios": {
"facility": "TCP",
Expand Down Expand Up @@ -224,7 +224,7 @@
},
"observer": {
"product": "IOS",
"type": "firewall",
"type": "router",
"vendor": "Cisco"
},
"related": {
Expand All @@ -243,7 +243,7 @@
]
},
{
"@timestamp": "2025-12-08T20:07:53.081Z",
"@timestamp": "2026-12-08T20:07:53.081Z",
"cisco": {
"ios": {
"facility": "TCP",
Expand Down Expand Up @@ -284,7 +284,7 @@
},
"observer": {
"product": "IOS",
"type": "firewall",
"type": "router",
"vendor": "Cisco"
},
"related": {
Expand All @@ -303,7 +303,7 @@
]
},
{
"@timestamp": "2025-12-08T20:07:53.081Z",
"@timestamp": "2026-12-08T20:07:53.081Z",
"cisco": {
"ios": {
"facility": "TCP",
Expand Down Expand Up @@ -345,7 +345,7 @@
},
"observer": {
"product": "IOS",
"type": "firewall",
"type": "router",
"vendor": "Cisco"
},
"related": {
Expand Down
Loading
Loading