# Cisco ASA NSEL: firewall\_event field and fw\_ext\_event fields support

**URL:** https://forum.elastiflow.com/t/cisco-asa-nsel-firewall-event-field-and-fw-ext-event-fields-support/395
**Category:** ElastiFlow Community
**Tags:** flow-collector
**Created:** [July 16, 2026, 9:28am UTC](https://forum.elastiflow.com/t/cisco-asa-nsel-firewall-event-field-and-fw-ext-event-fields-support/395 "2026-07-16T09:28:38Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Evgeny](https://avatars.discourse-cdn.com/v4/letter/e/a88e57/32.png) [@Evgeny](https://forum.elastiflow.com/u/Evgeny)
#### Post date: [July 16, 2026, 9:28am UTC](https://forum.elastiflow.com/t/cisco-asa-nsel-firewall-event-field-and-fw-ext-event-fields-support/395/1 "2026-07-16T09:28:38Z")

</div>

Hi everyone,  
I am currently testing ElastiFlow v7.26.2 in my environment and have encountered an issue with Cisco ASA NSEL (NetFlow Security Event Logging) event parsing.

Specifically, during my testing, I noticed that the standard firewall\_event field is completely missing, while the fw\_ext\_event field is populated correctly. According to the Cisco NSEL specifications, both standard and extended event IDs should map to their respective human-readable meanings, but currently, only the extended ones are appearing.

```auto

 "sec.action.id": 2034,

 "sec.action.name": "TCP_FINS",

```

 ![image](https://canada1.discourse-cdn.com/flex035/uploads/elastiflow/original/1X/be8eb9a953ae0eb35c672faf2c245ebd945fa93f.png)

---

<div class="post-metadata">

### Author: ![daniel.harada](https://avatars.discourse-cdn.com/v4/letter/d/d6d6ee/32.png) [@daniel.harada](https://forum.elastiflow.com/u/daniel.harada)
#### Post date: [July 16, 2026, 4:23pm UTC](https://forum.elastiflow.com/t/cisco-asa-nsel-firewall-event-field-and-fw-ext-event-fields-support/395/2 "2026-07-16T16:23:31Z")

</div>

Can you let me know what you’re wanting us to see in the screenshots you’ve provided? Based on [https://www.cisco.com/c/en/us/td/docs/security/asa/special/netflow/asa\_netflow.html](https://www.cisco.com/c/en/us/td/docs/security/asa/special/netflow/asa_netflow.html), the event ID 2034 shown in the screenshots is being correctly mapped as NP\_FLOW\_TCP\_FINS.

What event ID are you expecting to be mapped for the firewall\_event field? Is there documentation that you’re able to provide that shows this mapping?

---

<div class="post-metadata">

### Author: ![Evgeny](https://avatars.discourse-cdn.com/v4/letter/e/a88e57/32.png) [@Evgeny](https://forum.elastiflow.com/u/Evgeny)
#### Post date: [July 16, 2026, 5:19pm UTC](https://forum.elastiflow.com/t/cisco-asa-nsel-firewall-event-field-and-fw-ext-event-fields-support/395/3 "2026-07-16T17:19:36Z")

</div>

Yes, extended field (NSEL Extended Event ID ) mapped correctly, but NSEL Event ID completly missing. [https://www.cisco.com/c/en/us/td/docs/security/asa/special/netflow/asa\_netflow.html](https://www.cisco.com/c/en/us/td/docs/security/asa/special/netflow/asa_netflow.html)

Based on this documentation NSEL Event ID needs to be mapped something like: Created/Updated/Deleted

Something like:

sec.action.name: “Deleted”

sec.reason.name: “TCP\_FINS”

---

<div class="post-metadata">

### Author: ![system](https://yyz1.discourse-cdn.com/flex035/user_avatar/forum.elastiflow.com/system/32/59_2.png) [@system](https://forum.elastiflow.com/u/system)
#### Post date: [August 15, 2026, 5:20pm UTC](https://forum.elastiflow.com/t/cisco-asa-nsel-firewall-event-field-and-fw-ext-event-fields-support/395/4 "2026-08-15T17:20:36Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
