Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[cisco_asa]: Username captured contains quotes #12576

Open
swg0101 opened this issue Feb 3, 2025 · 1 comment
Open

[cisco_asa]: Username captured contains quotes #12576

swg0101 opened this issue Feb 3, 2025 · 1 comment
Labels
bug Something isn't working, use only for issues Integration:cisco_asa Cisco ASA Team:Security-Deployment and Devices Deployment and Devices Security team [elastic/sec-deployment-and-devices]

Comments

@swg0101
Copy link

swg0101 commented Feb 3, 2025

Integration Name

Cisco ASA [cisco_asa]

Dataset Name

cisco_asa.log

Integration Version

2.41.0

Agent Version

8.17.1

Agent Output Type

elasticsearch

Elasticsearch Version

8.17.1

OS Version and Architecture

Ubuntu 22.04 LTS

Software/API Version

Cisco ASA

Error Message

No errors encountered.

Event Original

<140>Dec 22 2024 21:49:35: %ASA-4-106103: access-list #ACSACL#-IP-HeartBase_ACL-61799a35 denied tcp for user 'dlew2' outside/10.122.1.1(51950) -> inside/201.3.120.29(443) hit-cnt 1 first hit [0xd3e666fa, 0x0]
<140>Dec 22 2024 21:49:35: %ASA-4-106103: access-list VPN-FILTER-ACL denied udp for user 'alewis' outside/10.122.22.150(137) -> outside/10.129.30.255(137) hit-cnt 1 first hit [0x37222895, 0xc5eddc02]

What did you do?

Default configuration

What did you see?

The related.user and user.name fields get parsed, but the quotes are also included in the username themselves.

What did you expect to see?

The quotes should be left out of the username and not be included.

Anything else?

No response

@andrewkroh andrewkroh added Integration:cisco_asa Cisco ASA Team:Security-Deployment and Devices Deployment and Devices Security team [elastic/sec-deployment-and-devices] labels Feb 3, 2025
@elasticmachine
Copy link

Pinging @elastic/sec-deployment-and-devices (Team:Security-Deployment and Devices)

@taylor-swanson taylor-swanson added bug Something isn't working, use only for issues and removed needs:triage labels Feb 3, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working, use only for issues Integration:cisco_asa Cisco ASA Team:Security-Deployment and Devices Deployment and Devices Security team [elastic/sec-deployment-and-devices]
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants