vpn.cisco
The tags beginning with vpn.cisco
identify log events generated by Cisco ASA VPN.
Valid tags and data tables
The full tag must have 4 levels. The first two are fixed as vpn.cisco
. The third level identifies the product and the fourth is the type of events sent.
These are the valid tags and corresponding data tables that will receive the parsers' data:
Product / Service | Tags | Data tables |
---|---|---|
Cisco ASA AnyConnect |
|
Union table - This is a union table that collects events from a set of tables for easy access and analysis. Learn more about this union table in this article. |
|
| |
Cisco FTD AnyConnect |
|
|
For more information, read more about Devo tags.
Table structure
These are the fields displayed in these tables:
vpn.cisco.asa.anyconnect
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
| Â | Â |
host |
| vhost | Â |
logType |
| Â | Â |
Severity |
| Â | Â |
EventID |
| Â | Â |
Group |
| Â | Â |
User |
| Â | Â |
srcIP |
| Â | Â |
srcIPV6 |
| Â | Â |
srcPort |
| Â | Â |
dstIP |
| Â | Â |
dstPort |
| Â | Â |
interface |
| Â | Â |
clientType |
| Â | Â |
ipv4Address |
| Â | Â |
ipv6Address |
| Â | Â |
SessionType |
| Â | Â |
Duration |
| Â | Â |
BytesXmt |
| Â | Â |
BytesRcv |
| Â | Â |
Reason |
| Â | Â |
svcMessage |
| Â | Â |
svcMessageCode |
| Â | Â |
Type |
| Â | Â |
error |
| Â | Â |
message |
| Â | Â |
hostchain |
|  | ✓ |
tag |
|  | ✓ |
rawMessage |
| rawSource | Â |
vpn.cisco.ftd.anyconnect
Field | Type | Source field name | Extra fields |
---|---|---|---|
eventdate |
| Â | Â |
host |
| vhost | Â |
logType |
| Â | Â |
Severity |
| Â | Â |
EventID |
| Â | Â |
Group |
| Â | Â |
User |
| Â | Â |
srcIP |
| Â | Â |
srcIPV6 |
| Â | Â |
srcPort |
| Â | Â |
dstIP |
| Â | Â |
dstPort |
| Â | Â |
interface |
| Â | Â |
clientType |
| Â | Â |
ipv4Address |
| Â | Â |
ipv6Address |
| Â | Â |
SessionType |
| Â | Â |
Duration |
| Â | Â |
BytesXmt |
| Â | Â |
BytesRcv |
| Â | Â |
Reason |
| Â | Â |
svcMessage |
| Â | Â |
svcMessageCode |
| Â | Â |
Type |
| Â | Â |
error |
| Â | Â |
message |
| Â | Â |
hostchain |
|  | ✓ |
tag |
|  | ✓ |
rawMessage |
| rawSource | Â |
Â