<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Endpoint Security to send syslogs in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/cisco-endpoint-security-to-send-syslogs/m-p/4777624#M7323</link>
    <description>No, not directly from the platform.   Depending on the SEIM, most of them have a way to get it, but they all use the API.&lt;BR /&gt;If you're using Elastic, I know that Logrhythm (which is just elastic underneath) uses a beat, but I think they built it themselves.&lt;BR /&gt;There's a way to do it here using RabbitMQ (because in the end you need a queueing system to process the data) &lt;A href="https://www.linkedin.com/pulse/your-endpoints-siem-fabio-lichinchi/" target="_blank"&gt;https://www.linkedin.com/pulse/your-endpoints-siem-fabio-lichinchi/&lt;/A&gt;&lt;BR /&gt;</description>
    <pubDate>Fri, 17 Feb 2023 18:39:24 GMT</pubDate>
    <dc:creator>Ken Stieers</dc:creator>
    <dc:date>2023-02-17T18:39:24Z</dc:date>
    <item>
      <title>Cisco Endpoint Security to send syslogs</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-endpoint-security-to-send-syslogs/m-p/4777617#M7322</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;Is it possible to send Cisco Endpoint security logs to &lt;STRONG&gt;Ubuntu syslog server&lt;/STRONG&gt; via API ?&lt;/P&gt;&lt;P&gt;We are planning to connect Cisco endpoint security logs to Azure Sentinel and its possible as per the document but it require server less - Azure function ( which has extra cost)&lt;/P&gt;&lt;P&gt;As we already have Ubuntu server which collects the Syslog from other networking appliances and forwards to Sentinel workspace. We wanted to know if we can send the Cisco endpoint logs to ubuntu syslog server ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Feb 2023 18:19:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-endpoint-security-to-send-syslogs/m-p/4777617#M7322</guid>
      <dc:creator>Subi</dc:creator>
      <dc:date>2023-02-17T18:19:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Endpoint Security to send syslogs</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-endpoint-security-to-send-syslogs/m-p/4777624#M7323</link>
      <description>No, not directly from the platform.   Depending on the SEIM, most of them have a way to get it, but they all use the API.&lt;BR /&gt;If you're using Elastic, I know that Logrhythm (which is just elastic underneath) uses a beat, but I think they built it themselves.&lt;BR /&gt;There's a way to do it here using RabbitMQ (because in the end you need a queueing system to process the data) &lt;A href="https://www.linkedin.com/pulse/your-endpoints-siem-fabio-lichinchi/" target="_blank"&gt;https://www.linkedin.com/pulse/your-endpoints-siem-fabio-lichinchi/&lt;/A&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 17 Feb 2023 18:39:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-endpoint-security-to-send-syslogs/m-p/4777624#M7323</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2023-02-17T18:39:24Z</dc:date>
    </item>
  </channel>
</rss>

