{"id":853,"date":"2017-10-01T09:46:30","date_gmt":"2017-10-01T08:46:30","guid":{"rendered":"http:\/\/www.balajibandi.com\/?p=853"},"modified":"2019-03-23T09:55:11","modified_gmt":"2019-03-23T09:55:11","slug":"wsa-logs-to-syslog-server-for-kibana-logstash","status":"publish","type":"post","link":"https:\/\/www.balajibandi.com\/?p=853","title":{"rendered":"WSA Logs to syslog Server for Kibana\/Logstash"},"content":{"rendered":"\n<h4 class=\"wp-block-heading\">Configuring Cisco WSA (Web Security Appliance) with SYSLOG Server<\/h4>\n\n\n\n<p> To configure&nbsp;Cisco WSA to send logs to your FTP Server: <\/p>\n\n\n\n<p> Log into your Cisco WSA web admin console and go to&nbsp;<strong>System Administration |&nbsp;Log Subscriptions<\/strong><\/p>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"866\" height=\"100\" src=\"http:\/\/www.balajibandi.com\/wp-content\/uploads\/2019\/03\/image-3.png\" alt=\"\" class=\"wp-image-854\" srcset=\"https:\/\/www.balajibandi.com\/wp-content\/uploads\/2019\/03\/image-3.png 866w, https:\/\/www.balajibandi.com\/wp-content\/uploads\/2019\/03\/image-3-300x35.png 300w, https:\/\/www.balajibandi.com\/wp-content\/uploads\/2019\/03\/image-3-768x89.png 768w, https:\/\/www.balajibandi.com\/wp-content\/uploads\/2019\/03\/image-3-705x81.png 705w\" sizes=\"auto, (max-width: 866px) 100vw, 866px\" \/><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"881\" height=\"515\" src=\"http:\/\/www.balajibandi.com\/wp-content\/uploads\/2019\/03\/image-4.png\" alt=\"\" class=\"wp-image-855\" srcset=\"https:\/\/www.balajibandi.com\/wp-content\/uploads\/2019\/03\/image-4.png 881w, https:\/\/www.balajibandi.com\/wp-content\/uploads\/2019\/03\/image-4-300x175.png 300w, https:\/\/www.balajibandi.com\/wp-content\/uploads\/2019\/03\/image-4-768x449.png 768w, https:\/\/www.balajibandi.com\/wp-content\/uploads\/2019\/03\/image-4-705x412.png 705w\" sizes=\"auto, (max-width: 881px) 100vw, 881px\" \/><figcaption><br><br><br><\/figcaption><\/figure>\n\n\n\n<p>\nClick&nbsp;<strong>accesslogs<\/strong>&nbsp;under the \u2018Log Name\u2019 column.\nSet the log style to <strong>Squid Details<\/strong>\nIn the <strong>Custom Fields<\/strong> section enter:\n<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\">#Fields: %L %e %a %k %B %A %w\/%h %s %q %g %p %R %c %XF %Y<\/pre>\n\n\n\n<p>This adds some useful fields such as referrer URL that WebSpy Vantage utilizes in reports. Set the <strong>Retrieval Method<\/strong> to <strong>FTP on Remote Server<\/strong>. Leave the <strong>Maximum Time Interva<\/strong>l between Transferring as the default (3600). Enter the FTP Host, Directory, Username and Password of your FTP server. <\/p>\n\n\n\n<figure class=\"wp-block-image\"><img loading=\"lazy\" decoding=\"async\" width=\"883\" height=\"576\" src=\"http:\/\/www.balajibandi.com\/wp-content\/uploads\/2019\/03\/image-5.png\" alt=\"\" class=\"wp-image-856\" srcset=\"https:\/\/www.balajibandi.com\/wp-content\/uploads\/2019\/03\/image-5.png 883w, https:\/\/www.balajibandi.com\/wp-content\/uploads\/2019\/03\/image-5-300x196.png 300w, https:\/\/www.balajibandi.com\/wp-content\/uploads\/2019\/03\/image-5-768x501.png 768w, https:\/\/www.balajibandi.com\/wp-content\/uploads\/2019\/03\/image-5-705x460.png 705w\" sizes=\"auto, (max-width: 883px) 100vw, 883px\" \/><\/figure>\n\n\n\n<p> Click&nbsp;S<strong>ubmit<\/strong>&nbsp;to save your changes. <\/p>\n\n\n\n<p><strong>Commit<\/strong> the changes to take effective<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Configuring Cisco WSA (Web Security Appliance) with SYSLOG Server To configure&nbsp;Cisco WSA to send logs to your FTP Server: Log into your Cisco WSA web admin console and go to&nbsp;System Administration |&nbsp;Log Subscriptions Click&nbsp;accesslogs&nbsp;under the \u2018Log Name\u2019 column. Set the log style to Squid Details In the Custom Fields section enter: #Fields: %L %e %a [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11],"tags":[],"class_list":["post-853","post","type-post","status-publish","format-standard","hentry","category-ccie-sec"],"_links":{"self":[{"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=\/wp\/v2\/posts\/853","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=853"}],"version-history":[{"count":2,"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=\/wp\/v2\/posts\/853\/revisions"}],"predecessor-version":[{"id":858,"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=\/wp\/v2\/posts\/853\/revisions\/858"}],"wp:attachment":[{"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=853"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=853"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.balajibandi.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=853"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}