Refer to the official Cisco documentation below to configure log forwarding from Cisco ASA.
The Scope application supports ingestion of Cisco ASA logs in the Syslog format.
Apr 17 2020 14:08:08 SNL-ASA-VPN-A01 : %ASA-6-302016: Teardown UDP connection 110577675 for Outside:10.123.123.123/53723 to Inside:10.233.123.123/53
Jul 15 13:38:08 81.2.69.142 %ASA-6-302015: Built outbound UDP connection 743108828 for outside:ns10/53 (ns10/53) to MND_sec:192.168.174.100/48347
<165>Jul 06 2022 07:00:33 vpn02 : %ASA-5-752016: IKEv1 was successful at setting up a tunnel. Map Tag = outside_map. Map Sequence Number = 27.
Apr 15 2013 09:36:50: %ASA-4-106023: Deny tcp src dmz:10.1.2.30/63016 dst outside:192.168.0.8/53 by access-group "acl_dmz"
Oct 10 2018 12:34:56 localhost CiscoASA[999]: %ASA-6-305011: Built dynamic TCP translation from inside:172.31.98.44/1772 to outside:192.168.98.44/8256
Jan 1 01:00:27 beats asa[1234]: %ASA-7-999999: This message is not filtered.
<166>:May 18 10:56:03 EDT: %ASA-session-6-302021: Teardown ICMP connection for faddr 10.11.12.13/1(LOCAL\username@example.com) gaddr 10.11.12.13/0 laddr 10.11.12.13/0