Source Ip Address | Hide Query Show Query cisco_facility="ASA"
| host=?asaHost
| cisco_severity=?severity
| cisco_className=?classname
| sankey(source="host", target="src_addr")
| Sankey |
Top 10 Attempted Access To Ports | Hide Query Show Query host=?asaHost
| cisco_facility="ASA"
| cisco_mnemonic=710003
| dst_port=?DestPort
| top(dst_port)
| Pie Chart |
Cisco Secure Firewall ASA Series Syslog Messages | Hide Query Show Query cisco_facility="ASA"
| sankey(source="host", target="cisco_mnemonic")
| Sankey |
Connections Per Hour From Outside | Hide Query Show Query src_location="outside"
| match(file="cisco/asa/asa_message_class.csv", field="cisco_classDefinition")
| timechart(span=1h)
| Single Value |
Top 10 Destination Address | Hide Query Show Query top(destination_ip, limit=10)
| Pie Chart |
Number of ASA firewalls | Hide Query Show Query cisco_facility="ASA"
| count(field=host, distinct=true)
| Single Value |
Event List | Hide Query Show Query cisco_facility="ASA"
| host=?asaHost
| cisco_severity=?severity
| cisco_className=?classname
| rename(host,as=Firewall)
| rename(cisco_severity,as=Severity)
| rename(cisco_className,as="Class name")
| rename(cisco_mnemonic,as=Mnemonic)
| rename(cisco_message,as=Message)
| select(["@timestamp",Firewall,Severity,"Class name",Mnemonic,Message])
| Table |
Total Connection From Inside | Hide Query Show Query src_location="inside"
| match(file="cisco/asa/asa_message_class.csv", field="cisco_classDefinition")
| timechart(span=1h)
| Single Value |
Failed By Cisco Class Name | Hide Query Show Query groupBy(["cisco_severity","cisco_className"], function=(count(as="Count")))
| rename(field="cisco_severity", as="Severity")
| rename(field="cisco_className", as="ClassName")
| select([Severity, ClassName, Count])
| Table |
Top Source Ports | Hide Query Show Query cisco_severity=?severity
| timechart("source_port")
| Time Chart |
Total Accepted Connection | Hide Query Show Query cisco_action = "Built"
| timechart(span=1h)
| Single Value |
Top 10 Source Address | Hide Query Show Query top("source_ip", limit=10)
| Bar Chart |
ICMP Connction Denied | Hide Query Show Query cisco_message="*ICMP*"
| groupBy(type, function=[])
| rename(field="type", as="Type")
| Table |
Events Per Firewall | Hide Query Show Query cisco_facility="ASA"
| cisco_severity=?severity
| cisco_className=?classname
| groupby(host)
| rename(host,as=Firewall)
| rename("_count",as="Number of events")
| Table |
Severity Messages | Hide Query Show Query | Bar Chart |
Total Failed Connections | Hide Query Show Query cisco_message="*failed*"
| timechart(span=1h)
| Single Value |
Top 10 Messages | Hide Query Show Query cisco_facility="ASA"
| host=?asaHost
| cisco_severity=?severity
| cisco_className=?classname
| rename("cisco_classDefinition",as="ASA message classes")
| timechart("ASA message classes", limit=10)
| Time Chart |
Cisco Action by Ports | Hide Query Show Query groupBy([source_port, cisco_action, outside, inside], function = [])
| rename(field="source_port", as="Source Port")
| rename(field="cisco_action", as="Cisco Action")
| select(["Source Port", "Cisco Action"])
| Table |