<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firesight Event Log Archival in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firesight-event-log-archival/m-p/2849594#M1031915</link>
    <description>&lt;P&gt;I noticed that I was only carrying roughly 1 days worth of connection events in Firesight and increased the max retention from 1 to 10 million. I will have to wait and see but simple math would tell me that will allow me to store 10 days worth of data.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Realistically I need to be able to run reports showing application and web traffic for an employee. These report requests don't come often through HR so I don't want to necessarily keep the records in the active database.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I was curious if there was a way to rollup and archive the event log data for future reporting or any other suggestions people may have for solving my potential problem.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 12:55:04 GMT</pubDate>
    <dc:creator>nrunge1</dc:creator>
    <dc:date>2019-03-12T12:55:04Z</dc:date>
    <item>
      <title>Firesight Event Log Archival</title>
      <link>https://community.cisco.com/t5/network-security/firesight-event-log-archival/m-p/2849594#M1031915</link>
      <description>&lt;P&gt;I noticed that I was only carrying roughly 1 days worth of connection events in Firesight and increased the max retention from 1 to 10 million. I will have to wait and see but simple math would tell me that will allow me to store 10 days worth of data.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Realistically I need to be able to run reports showing application and web traffic for an employee. These report requests don't come often through HR so I don't want to necessarily keep the records in the active database.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I was curious if there was a way to rollup and archive the event log data for future reporting or any other suggestions people may have for solving my potential problem.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 12:55:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-event-log-archival/m-p/2849594#M1031915</guid>
      <dc:creator>nrunge1</dc:creator>
      <dc:date>2019-03-12T12:55:04Z</dc:date>
    </item>
    <item>
      <title>I was told by Cisco that best</title>
      <link>https://community.cisco.com/t5/network-security/firesight-event-log-archival/m-p/2849595#M1031918</link>
      <description>&lt;P&gt;I was told by Cisco that best any appliance is going to do in terms of retention is 30 days. It looks like Sourcefire maintained a Splunk plugin so that is the direction I am headed.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I also have asked Cisco if they can confirm that the plugin still has resources post acquisition.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Mar 2016 21:25:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-event-log-archival/m-p/2849595#M1031918</guid>
      <dc:creator>nrunge1</dc:creator>
      <dc:date>2016-03-07T21:25:36Z</dc:date>
    </item>
    <item>
      <title>You should configure a syslog</title>
      <link>https://community.cisco.com/t5/network-security/firesight-event-log-archival/m-p/2849596#M1031920</link>
      <description>&lt;P&gt;You should configure a syslog server, and send the data you need from Firepower Management Center.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;FMC is not intended for logging. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2016 09:50:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-event-log-archival/m-p/2849596#M1031920</guid>
      <dc:creator>Dennis Perto</dc:creator>
      <dc:date>2016-03-09T09:50:47Z</dc:date>
    </item>
    <item>
      <title>Well, the device not intended</title>
      <link>https://community.cisco.com/t5/network-security/firesight-event-log-archival/m-p/2849597#M1031929</link>
      <description>&lt;P&gt;Well, the device not intended for "x" definitely seems to be the answer I get every time I find a caveat so I suppose that makes sense :]&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2016 13:47:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-event-log-archival/m-p/2849597#M1031929</guid>
      <dc:creator>nrunge1</dc:creator>
      <dc:date>2016-03-09T13:47:18Z</dc:date>
    </item>
    <item>
      <title>I'm sorry about that. I have</title>
      <link>https://community.cisco.com/t5/network-security/firesight-event-log-archival/m-p/2849598#M1031937</link>
      <description>&lt;P&gt;I'm sorry about that. I have seen too many systems sold as a SIEM solution, but then shit hits the fan, and we can hold the log for a couple of hours.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I have a 5506-X at home sending syslog to a free Graylog2 server. The 5506-X only have a "real time" log.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2016 13:50:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-event-log-archival/m-p/2849598#M1031937</guid>
      <dc:creator>Dennis Perto</dc:creator>
      <dc:date>2016-03-09T13:50:40Z</dc:date>
    </item>
    <item>
      <title>Don't get me wrong. I like</title>
      <link>https://community.cisco.com/t5/network-security/firesight-event-log-archival/m-p/2849599#M1031947</link>
      <description>&lt;P&gt;Don't get me wrong. I like the platform. Our partner just did a poor job both in selling us the CX and migrating us to FirePower.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I like it 10x better than the 80/443 appliances we had been using before like WebSense. What I don't like are suprises.&lt;/P&gt;
&lt;P&gt;If they would have told us we needed a syslog on day one not only would I have bought Splunk but I probably would have tied it into the services engagement.&lt;/P&gt;
&lt;P&gt;Instead I'm moving the consulting to a different partner.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2016 13:56:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-event-log-archival/m-p/2849599#M1031947</guid>
      <dc:creator>nrunge1</dc:creator>
      <dc:date>2016-03-09T13:56:02Z</dc:date>
    </item>
    <item>
      <title>I understand. I'm sure that</title>
      <link>https://community.cisco.com/t5/network-security/firesight-event-log-archival/m-p/2849600#M1031958</link>
      <description>&lt;P&gt;I understand. &lt;BR /&gt;I'm sure that you will find a way with a partner you can trust. You can always find guidance here at the support forums, or in the Cisco communities. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Mar 2016 14:05:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-event-log-archival/m-p/2849600#M1031958</guid>
      <dc:creator>Dennis Perto</dc:creator>
      <dc:date>2016-03-09T14:05:48Z</dc:date>
    </item>
  </channel>
</rss>

