- Notifications
You must be signed in to change notification settings - Fork 513
Labels
Integration:cisco_iosCisco IOSCisco IOSTeam:Security-Deployment and DevicesDEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices]DEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices]enhancementNew feature or requestNew feature or request
Description
Example of the Kiwi syslog format:
<190>Original Address=192.168.0.1 1 2025-06-23T16:13:32.168Z ns-host-1 kiwi-syslog-test 3356 MSGOUT TEST-HOST: *Jun 23 15:52:38.534: %SYS-6-LOGOUT: User test-user has exited tty session 1(192.168.0.1) The Kiwi Syslog server alters the original Cisco IOS log by inserting a Original Address=IP at the beginning of the log, along with an RFC 5424 header. By removing this header, the rest of the message is a standard Cisco IOS format that can be used with the existing pipeline.
Metadata
Metadata
Assignees
Labels
Integration:cisco_iosCisco IOSCisco IOSTeam:Security-Deployment and DevicesDEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices]DEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices]enhancementNew feature or requestNew feature or request