Skip to content

Commit faa1e0e

Browse files
authored
[Cisco ASA] Fix GROK adding support to usernames ending with "$" (#8362)
* Support usernames ending with "$"
1 parent bb36819 commit faa1e0e

File tree

6 files changed

+873
-20
lines changed

6 files changed

+873
-20
lines changed

packages/cisco_asa/changelog.yml

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,18 @@
11
# newer versions go on top
2+
- version: "2.27.1"
3+
changes:
4+
- description: Support usernames ending with "$".
5+
type: bugfix
6+
link: https://github.com/elastic/integrations/pull/8362
7+
- description: Add "User was not found" as reason to 113015.
8+
type: bugfix
9+
link: https://github.com/elastic/integrations/pull/8362
10+
- description: Allow source to be a domain or an IP inside 313005.
11+
type: bugfix
12+
link: https://github.com/elastic/integrations/pull/8362
13+
- description: Create non-capturing groups for CISCO_USER GROK pattern
14+
type: bugfix
15+
link: https://github.com/elastic/integrations/pull/8362
216
- version: "2.27.0"
317
changes:
418
- description: Improve 'event.original' check to avoid errors if set.

packages/cisco_asa/data_stream/log/_dev/test/pipeline/test-additional-messages.log-expected.json

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -801,6 +801,7 @@
801801
}
802802
},
803803
"destination": {
804+
"address": "192.168.2.3",
804805
"ip": "192.168.2.3",
805806
"port": 10872
806807
},
@@ -861,6 +862,7 @@
861862
]
862863
},
863864
"source": {
865+
"address": "192.168.2.2",
864866
"ip": "192.168.2.2",
865867
"port": 53
866868
},
@@ -879,6 +881,7 @@
879881
}
880882
},
881883
"destination": {
884+
"address": "192.168.2.3",
882885
"ip": "192.168.2.3",
883886
"port": 10872
884887
},
@@ -943,6 +946,7 @@
943946
]
944947
},
945948
"source": {
949+
"address": "192.168.2.2",
946950
"ip": "192.168.2.2",
947951
"port": 53,
948952
"user": {
@@ -968,6 +972,7 @@
968972
}
969973
},
970974
"destination": {
975+
"address": "192.168.2.3",
971976
"ip": "192.168.2.3",
972977
"port": 10872
973978
},
@@ -1032,6 +1037,7 @@
10321037
]
10331038
},
10341039
"source": {
1040+
"address": "192.168.2.2",
10351041
"ip": "192.168.2.2",
10361042
"port": 53,
10371043
"user": {
@@ -1054,6 +1060,7 @@
10541060
}
10551061
},
10561062
"destination": {
1063+
"address": "192.168.2.3",
10571064
"ip": "192.168.2.3"
10581065
},
10591066
"ecs": {
@@ -1115,6 +1122,7 @@
11151122
]
11161123
},
11171124
"source": {
1125+
"address": "192.168.2.2",
11181126
"ip": "192.168.2.2"
11191127
},
11201128
"tags": [
@@ -1133,6 +1141,7 @@
11331141
}
11341142
},
11351143
"destination": {
1144+
"address": "192.168.2.3",
11361145
"ip": "192.168.2.3"
11371146
},
11381147
"ecs": {
@@ -1198,6 +1207,7 @@
11981207
]
11991208
},
12001209
"source": {
1210+
"address": "192.168.2.2",
12011211
"ip": "192.168.2.2"
12021212
},
12031213
"tags": [

packages/cisco_asa/data_stream/log/_dev/test/pipeline/test-sgt-tag-name.log

Lines changed: 10 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,4 +14,13 @@
1414
<142>Oct 06 2023 10:30:18 myAsaHostname : %ASA-6-302016: Teardown UDP connection 79784719 for outside:192.168.2.2/60556(9999:my_SgtName) to inside:192.168.2.3/53 duration 0:00:00 bytes 221
1515
<142>Oct 06 2023 10:34:45 myAsaHostname : %ASA-6-302020: Built outbound ICMP connection for faddr 192.168.2.2/0(9999:my_SgtName) gaddr 192.168.2.3/1 laddr 192.168.2.3/1 type 8 code 0
1616
<142>Oct 06 2023 10:32:10 myAsaHostname : %ASA-6-302021: Teardown ICMP connection for faddr 192.168.2.2/29(LOCAL\myUser1234, 9999:my_SgtName) gaddr 192.168.2.3/0 laddr 192.168.2.3/0 (myUser1234) type 8 code 0
17-
<140>Oct 06 2023 10:33:23 myAsaHostname : %ASA-4-313005: No matching connection for ICMP error message: icmp src outside:192.168.2.2(LOCAL\myUser1234, 9999:my_SgtName) dst inside:192.168.2.3 (type 3, code 3) on outside interface. Original IP payload: udp src 192.168.2.3/53 dst 192.168.2.2/54860.
17+
<140>Oct 06 2023 10:33:23 myAsaHostname : %ASA-4-313005: No matching connection for ICMP error message: icmp src outside:192.168.2.2(LOCAL\myUser1234, 9999:my_SgtName) dst inside:192.168.2.3 (type 3, code 3) on outside interface. Original IP payload: udp src 192.168.2.3/53 dst 192.168.2.2/54860.
18+
<142>Oct 25 2023 14:27:06 myAsaHostname : %ASA-6-302013: Built inbound TCP connection 101086093 for outside:192.168.2.2/56824 (192.168.2.2/56824)(LOCAL\myUser1234$, 9999:my_SgtName) to inside:192.168.2.3/443 (192.168.2.3/443) (myUser1234$)
19+
<142>Oct 25 2023 14:22:19 myAsaHostname : %ASA-6-302014: Teardown TCP connection 63490259 for outside:192.168.2.2/49786(LOCAL\myUser1234$, 9999:my_SgtName) to inside:192.168.2.3/5985 duration 0:00:30 bytes 0 SYN Timeout (myUser1234$)
20+
<142>Oct 25 2023 14:29:02 myAsaHostname : %ASA-6-302015: Built inbound UDP connection 101095490 for outside:192.168.2.2/61219 (192.168.2.2/61219)(LOCAL\myUser1234$, 9999:my_SgtName) to inside:192.168.2.3/53 (192.168.2.3/53) (myUser1234$)
21+
<142>Oct 25 2023 14:30:31 myAsaHostname : %ASA-6-302016: Teardown UDP connection 101101684 for outside:192.168.2.2/62253(LOCAL\myUser1234$, 9999:my_SgtName) to inside:192.168.2.3/53 duration 0:00:00 bytes 216 (myUser1234$)
22+
<142>Oct 25 2023 14:32:55 myAsaHostname : %ASA-6-302020: Built inbound ICMP connection for faddr 192.168.2.2/1(LOCAL\myUser1234$, 9999:my_SgtName) gaddr 192.168.2.3/0 laddr 192.168.2.3/0 (myUser1234$) type 8 code 0
23+
<142>Oct 25 2023 14:27:04 myAsaHostname : %ASA-6-302021: Teardown ICMP connection for faddr 192.168.2.2/1(LOCAL\myUser1234$, 9999:my_SgtName) gaddr 192.168.2.3/0 laddr 192.168.2.3/0 (myUser1234$) type 8 code 0
24+
<140>Oct 25 2023 06:53:06 myAsaHostname : %ASA-4-313005: No matching connection for ICMP error message: icmp src outside:192.168.2.2(LOCAL\myUser1234$, 9999:my_SgtName) dst inside:192.168.2.3 (type 3, code 3) on outside interface. Original IP payload: udp src 192.168.2.3/53 dst 192.168.2.2/55735.
25+
<142>Oct 25 2023 14:35:37 myAsaHostname : %ASA-6-113015: AAA user authentication Rejected : reason = User was not found : local database : user = ***** : user IP = 192.168.2.2
26+
<164>Oct 25 2023 14:40:42 myAsaHostname : %ASA-4-313005: No matching connection for ICMP error message: icmp src inside:192.168.2.2 dst outside:myComputer1.myDomain.com (type 3, code 3) on inside interface. Original IP payload: udp src myComputer1.myDomain.com/53 dst 192.168.2.2/58164.

0 commit comments

Comments
 (0)