Skip to content

Conversation

@taylor-swanson
Copy link
Contributor

@taylor-swanson taylor-swanson commented Sep 24, 2025

Proposed commit message

Add support for Cisco IOS messages. Matches on the Cisco Emblem header in the log, and by default matches after Cisco ASA and FTD to avoid ambiguity.

Checklist

  • I have reviewed tips for building integrations and this pull request is aligned with them.
  • I have verified that all data streams collect metrics or logs.
  • I have added an entry to my package's changelog.yml file.
  • I have verified that Kibana version constraints are current according to guidelines.
    - [ ] I have verified that any added dashboard complies with Kibana's Dashboard good practices

How to test this PR locally

  1. Install assets for Cisco ASA, Cisco FTD, and Cisco IOS
  2. Configure the Syslog Router integration (no changes necessary to routing configs).
  3. Send Cisco ASA, FTD, and IOS logs to agent running integration
  4. Verify that logs have landed in the correct data streams

I manually verified that logs were routed to the correct data streams.

Related issues

- Add support for Cisco IOS messages. Matches on the Cisco Emblem header in the log.
@taylor-swanson taylor-swanson self-assigned this Sep 24, 2025
@taylor-swanson taylor-swanson added enhancement New feature or request Integration:syslog_router Syslog Router Team:Integration-Experience Security Integrations Integration Experience [elastic/integration-experience] labels Sep 24, 2025
@elastic-vault-github-plugin-prod

🚀 Benchmarks report

To see the full report comment with /test benchmark fullreport

@elasticmachine
Copy link

💚 Build Succeeded

cc @taylor-swanson

@taylor-swanson taylor-swanson marked this pull request as ready for review September 24, 2025 13:13
@taylor-swanson taylor-swanson requested a review from a team as a code owner September 24, 2025 13:13
@elasticmachine
Copy link

Pinging @elastic/integration-experience (Team:Integration-Experience)

@taylor-swanson taylor-swanson merged commit ed5ef4b into elastic:main Sep 25, 2025
9 checks passed
@elastic-vault-github-plugin-prod

Package syslog_router - 0.3.0 containing this change is available at https://epr.elastic.co/package/syslog_router/0.3.0/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request Integration:syslog_router Syslog Router Team:Integration-Experience Security Integrations Integration Experience [elastic/integration-experience]

3 participants