You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Please post all product and debugging questions on our forum. Your questions will reach our wider community members there, and if we confirm that there is a bug, then we can open a new issue here.
For all general issues, please provide the following details for fast resolution:
Version: 5.0.3
Operating System: Centos 7 based Elastic docker image logstash-oss:6.2.0
Config File (if you have sensitive info, please remove it):
input { tcp { port => 5002 proxy_protocol => true type => "cisco-asa" } }
This is the first time I have attempted to use proxy protocol with the tcp input so I don't know if I am not configuring it correctly or if this is a bug. Any help will be appreciated.
The text was updated successfully, but these errors were encountered:
It may be. Although #51 refers to JSON input. In my case, I am sending syslog from mostly Cisco switches. What can I provide to help troubleshoot the issue?
Please post all product and debugging questions on our forum. Your questions will reach our wider community members there, and if we confirm that there is a bug, then we can open a new issue here.
For all general issues, please provide the following details for fast resolution:
input { tcp { port => 5002 proxy_protocol => true type => "cisco-asa" } }
{ "_index": "logstash-cisco-asa-2018.02.08", "_type": "doc", "_id": "U4pjdWEBuOTf8uMsTEIG", "_version": 1, "_score": null, "_source": { "timestamp": "Feb 08 2018 07:28:17", "type": "cisco-asa", "@timestamp": "2018-02-08T12:28:17.231Z", "log_sequence_number": "305012", "cisco_tag": "ASA-6-305012", "host": "PROXY TCP4 19", "@version": "1", "src_interface": "inside", "log_severity": "6", "proxy_host": "PROXY TCP4 19", "proxy_port": "PROX", "src_ip": "_IP_", "tags": [ "cisco" ], "host_ip": "_IP_", "action": "Teardown", "protocol": "TCP", "message": "Teardown dynamic TCP translation from inside: _IP_/42546 to outside:_IP_/42546 duration 0:00:00", "src_port": "42546", "xlate_type": "dynamic", "log_facility": "ASA", "src_locality": "private", "src_xlated_ip": "_IP_", "src_xlated_interface": "outside" }, "fields": { "@timestamp": [ "2018-02-08T12:28:17.231Z" ] }, "sort": [ 1518092897231 ] }
I have an nginx load balancer configured to send proxy protocol:
`server {
`
The nginx server is using proxy protocol v1
The input plugin does not appear to be parsing the proxy protocol header correctly.
"host": "PROXY TCP4 19"
"proxy_host": "PROXY TCP4 19"
"proxy_port": "PROX"
This is the first time I have attempted to use proxy protocol with the tcp input so I don't know if I am not configuring it correctly or if this is a bug. Any help will be appreciated.
The text was updated successfully, but these errors were encountered: