Skip to content

Graylog plugins and Content Packs for Cisco IOS/IOS-XE/NX

License

Notifications You must be signed in to change notification settings

hrleinonen/graylog-cisco

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

7 Commits
 
 
 
 
 
 

Repository files navigation

Graylog3 supported

Content Pack includes:

  • Couple new GROK patern files
    • CISCO_MNEMONIC_FIRSTPART
    • CISCO_MNEMONIC_LASTPART
  • Extractors for syslog messages
    • Supported new fields in search: CISCO_MESSAGE = Full syslog message CISCO_MNEMONIC_FIRSTPART = Mnemonic first part like SYS, LINK or PARSER CISCO_MNEMONIC_LASTPART = Mnemonic last part like MODEM_UP, CONFIG_I or UPDOWN CISCO_MNEMONIC = Full Mnemonic like SYS-5-CONFIG_I, LINEPROTO-5-UPDOWN or CISCO800-2-MODEM_UP
  • Basic dashboard called Cisco "Switches And Routers"
    • 10 Most Used MNEMONICS 1 Day
    • 10 Least Used MNEMONICS 1 Day
    • Cisco Syslog Levels 1 Day
    • Top 10 Syslog Senders 1 Day
    • 10 Least Common MSG 1 Day
    • 10 Most Common MSG 1 Day
    • Number of Messages per hour **** NOTE START ****
    • Edit search query source if needed, default is "gl2_source_input:5cc199348a66df5bf971ef41" **** NOTE END ****
  • Default input port is 1515

Cisco syslog config example: #logging origin-id ip #logging source-interface #logging host transport udp port 1515

Happy logging,

/Ville

About

Graylog plugins and Content Packs for Cisco IOS/IOS-XE/NX

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published