Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
Parser:
Title: Network Session ASIM parser for Cisco ASA
Version: '1.1.0'
LastUpdated: Jan 09, 2025
LastUpdated: Dec 23, 2025
Product:
Name: CiscoASA
Normalization:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
Parser:
Title: Network Session ASIM parser for Cisco ASA
Version: '1.1.0'
LastUpdated: Jan 09, 2025
LastUpdated: Dec 23, 2025
Product:
Name: CiscoASA
Normalization:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
TenantId,TimeGenerated [UTC],DeviceVendor,DeviceProduct,DeviceVersion,DeviceEventClassID,Activity,LogSeverity,OriginalLogSeverity,AdditionalExtensions,DeviceAction,ApplicationProtocol,EventCount,DestinationDnsDomain,DestinationServiceName,DestinationTranslatedAddress,DestinationTranslatedPort,CommunicationDirection,DeviceDnsDomain,DeviceExternalID,DeviceFacility,DeviceInboundInterface,DeviceNtDomain,DeviceOutboundInterface,DevicePayloadId,ProcessName,DeviceTranslatedAddress,DestinationHostName,DestinationMACAddress,DestinationNTDomain,DestinationProcessId,DestinationUserPrivileges,DestinationProcessName,DestinationPort,DestinationIP,DeviceTimeZone,DestinationUserID,DestinationUserName,DeviceAddress,DeviceName,DeviceMacAddress,ProcessID,EndTime [UTC],ExternalID,ExtID,FileCreateTime,FileHash,FileID,FileModificationTime,FilePath,FilePermission,FileType,FileName,FileSize,ReceivedBytes,Message,OldFileCreateTime,OldFileHash,OldFileID,OldFileModificationTime,OldFileName,OldFilePath,OldFilePermission,OldFileSize,OldFileType,SentBytes,EventOutcome,Protocol,Reason,RequestURL,RequestClientApplication,RequestContext,RequestCookies,RequestMethod,ReceiptTime,SourceHostName,SourceMACAddress,SourceNTDomain,SourceDnsDomain,SourceServiceName,SourceTranslatedAddress,SourceTranslatedPort,SourceProcessId,SourceUserPrivileges,SourceProcessName,SourcePort,SourceIP,StartTime [UTC],SourceUserID,SourceUserName,EventType,DeviceEventCategory,DeviceCustomIPv6Address1,DeviceCustomIPv6Address1Label,DeviceCustomIPv6Address2,DeviceCustomIPv6Address2Label,DeviceCustomIPv6Address3,DeviceCustomIPv6Address3Label,DeviceCustomIPv6Address4,DeviceCustomIPv6Address4Label,DeviceCustomFloatingPoint1,DeviceCustomFloatingPoint1Label,DeviceCustomFloatingPoint2,DeviceCustomFloatingPoint2Label,DeviceCustomFloatingPoint3,DeviceCustomFloatingPoint3Label,DeviceCustomFloatingPoint4,DeviceCustomFloatingPoint4Label,DeviceCustomNumber1,FieldDeviceCustomNumber1,DeviceCustomNumber1Label,DeviceCustomNumber2,FieldDeviceCustomNumber2,DeviceCustomNumber2Label,DeviceCustomNumber3,FieldDeviceCustomNumber3,DeviceCustomNumber3Label,DeviceCustomString1,DeviceCustomString1Label,DeviceCustomString2,DeviceCustomString2Label,DeviceCustomString3,DeviceCustomString3Label,DeviceCustomString4,DeviceCustomString4Label,DeviceCustomString5,DeviceCustomString5Label,DeviceCustomString6,DeviceCustomString6Label,DeviceCustomDate1,DeviceCustomDate1Label,DeviceCustomDate2,DeviceCustomDate2Label,FlexDate1,FlexDate1Label,FlexNumber1,FlexNumber1Label,FlexNumber2,FlexNumber2Label,FlexString1,FlexString1Label,FlexString2,FlexString2Label,RemoteIP,RemotePort,MaliciousIP,ThreatSeverity,IndicatorThreatType,ThreatDescription,ThreatConfidence,ReportReferenceLink,MaliciousIPLongitude,MaliciousIPLatitude,MaliciousIPCountry,Computer,SourceSystem,SimplifiedDeviceAction,Type,_ResourceId
01680ad8-1090-4dec-a395-f77b161a9051,"7/5/2023, 2:16:44.756 PM",Cisco,ASA,,106023,,Low,6,,,,,,,,0,,,,local4,,,,,,,self-serve-abc-2-vm03,,,123,,test,0,192.86.5.123,,,,192.168.1.1,_gateway,,,,,,,,,,,,,,,,%ASA-2-106007: Deny inbound UDP from 192.86.5.123/12345 to 192.86.5.123/12345 due to DNS Query,,,,,,,,,,,,,,,,,,,07-05-2023 14:16,,,,,,,,,,,,192.168.1.123,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,_gateway,OpsManager,,CommonSecurityLog,/subscriptions/e174f759-39db-49b8-b8bc-15cf9abca0f3/resourcegroups/kustoworksarc/providers/microsoft.hybridcompute/machines/col1
01680ad8-1090-4dec-a395-f77b161a9051,"7/5/2023, 2:16:44.756 PM",Cisco,ASA,,106023,,Low,6,,,,,,,,0,,,,local4,,,,,,,self-serve-abc-2-vm03,,,123,,test,0,192.86.5.123,,,,192.168.1.1,_gateway,,,,,,,,,,,,,,,,%ASA-2-106007: Deny inbound UDP from 192.86.5.123/12345 to 192.86.5.123/12345 due to DNS Query,,,,,,,,,,,,,,,,,,,23-12-2025 14:16,,,,,,,,,,,,192.168.1.123,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,_gateway,OpsManager,,CommonSecurityLog,/subscriptions/e174f759-39db-49b8-b8bc-15cf9abca0f3/resourcegroups/kustoworksarc/providers/microsoft.hybridcompute/machines/col1
01680ad8-1090-4dec-a395-f77b161a9051,"7/5/2023, 2:16:44.756 PM",Cisco,ASA,,106006,,Low,6,,,,,,,,8002,,,,local4,,,,,,,self-serve-efg-1-vm03,,,123,,test,8002,192.86.5.124,,,,192.168.1.2,_gateway,,,,,,,,,,,,,,,,"%FTD-4-106023: Deny udp src dev-test:192.86.5.123/12345 dst routing:192.86.4.1/123 by access-group ""ABC"" [0x00b0000, 0xf00000e0]",,,,,,,,,,,,,,,,,,,07-05-2023 14:16,,,,,,,,,,,,192.168.2.124,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,_gateway,OpsManager,,CommonSecurityLog,/subscriptions/e174f759-39db-49b8-b8bc-15cf9abca0f3/resourcegroups/kustoworksarc/providers/microsoft.hybridcompute/machines/col1
01680ad8-1090-4dec-a395-f77b161a9051,"7/5/2023, 2:16:44.756 PM",Cisco,ASA,,106001,,Low,6,,,,,,,,22,,,,local4,,,,,,,self-serve-abc-2-vm03,,,123,,test,22,192.86.5.125,,,,192.168.2.3,_gateway,,,,,,,,,,,,,,,,"%FTD-4-106023: Deny udp src dev-test:192.86.5.123/12345 dst routing:192.86.4.1/123 by access-group ""ABC"" [0x00b0000, 0xf00000e0]",,,,,,,,,,,,,,,,,,,07-05-2023 14:16,,,,,,,,,,,,192.168.4.125,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,_gateway,OpsManager,,CommonSecurityLog,/subscriptions/e174f759-39db-49b8-b8bc-15cf9abca0f3/resourcegroups/kustoworksarc/providers/microsoft.hybridcompute/machines/col1
01680ad8-1090-4dec-a395-f77b161a9051,"7/5/2023, 2:16:44.756 PM",Cisco,ASA,,113004,,Low,6,,,,,,,,0,,,,local4,,,,,,,self-serve-efg-1-vm03,,,123,,test,0,192.86.5.126,,,,192.168.2.4,_gateway,,,,,,,,,,,,,,,,%ASA-3-710003: TCP access denied by ACL from 192.86.5.123/12345 to outside:192.86.5.123/11,,,,,,,,,,,,,,,,,,,07-05-2023 14:16,,,,,,,,,,,,192.168.5.126,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,_gateway,OpsManager,,CommonSecurityLog,/subscriptions/e174f759-39db-49b8-b8bc-15cf9abca0f3/resourcegroups/kustoworksarc/providers/microsoft.hybridcompute/machines/col1
Expand Down
Loading