Skip to content

Conversation

@taylor-swanson
Copy link
Contributor

@taylor-swanson taylor-swanson commented Jun 23, 2025

Proposed commit message

  • Add support for Kiwi format logs. The Kiwi header is removed and the remaining log is parsed like a normal Cisco IOS log.

The Kiwi Syslog server alters the original Cisco IOS log by inserting a Original Address=IP at the beginning of the log, along with an RFC 5424 header.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
    - [ ] I have verified that any added dashboard complies with Kibana's Dashboard good practices

How to test this PR locally

cd packages/cisco_ios elastic-package test 

Related issues

@taylor-swanson taylor-swanson self-assigned this Jun 23, 2025
@taylor-swanson taylor-swanson requested a review from a team as a code owner June 23, 2025 19:15
@taylor-swanson taylor-swanson added enhancement New feature or request Integration:cisco_ios Cisco IOS Team:Security-Deployment and Devices DEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices] labels Jun 23, 2025
@elasticmachine
Copy link

Pinging @elastic/sec-deployment-and-devices (Team:Security-Deployment and Devices)

@taylor-swanson taylor-swanson marked this pull request as draft June 23, 2025 19:31
@elastic-vault-github-plugin-prod

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

- Add support for Kiwi format logs. The Kiwi header is removed and the remaining log is parsed like a normal Cisco IOS log.
@taylor-swanson taylor-swanson force-pushed the enhance/cisco-ios-kiwi branch from bfccac5 to 62222d7 Compare June 26, 2025 12:46
@taylor-swanson taylor-swanson marked this pull request as ready for review June 26, 2025 12:50
@elasticmachine
Copy link

💚 Build Succeeded

History

cc @taylor-swanson

@taylor-swanson taylor-swanson merged commit 89397dd into elastic:main Jun 30, 2025
7 checks passed
@taylor-swanson taylor-swanson deleted the enhance/cisco-ios-kiwi branch June 30, 2025 19:38
@elastic-vault-github-plugin-prod

Package cisco_ios - 1.31.0 containing this change is available at https://epr.elastic.co/package/cisco_ios/1.31.0/

robester0403 pushed a commit to robester0403/integrations that referenced this pull request Jul 8, 2025
- Add support for Kiwi format logs. The Kiwi header is removed and the remaining log is parsed like a normal Cisco IOS log.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:cisco_ios Cisco IOS Team:Security-Deployment and Devices DEPRECATED Deployment and Devices Security team [elastic/sec-deployment-and-devices]

3 participants