<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Yog, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/question-sourcefire-firesight-syslog-to-include-inline-result/m-p/2859038#M1037749</link>
    <description>&lt;P&gt;Hi Yog,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I check the documentation you provided, I have successfully retrieved the syslog from sourcefire, problem is the syslog does not have the inline result / action ( dropped or permitted ).&lt;/P&gt;
&lt;P&gt;correct me if i am wrong, I don't think changing the severity and priority will have any effect on that granularity of the syslog, that is only to mark the syslog sent with&amp;nbsp;selected sev and priorioty&amp;nbsp;and only effect how the syslog server process it.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Wed, 18 May 2016 05:49:30 GMT</pubDate>
    <dc:creator>filterfilter</dc:creator>
    <dc:date>2016-05-18T05:49:30Z</dc:date>
    <item>
      <title>[Question] Sourcefire/Firesight Syslog to include inline result</title>
      <link>https://community.cisco.com/t5/network-security/question-sourcefire-firesight-syslog-to-include-inline-result/m-p/2859036#M1037719</link>
      <description>&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Hi Guys,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;I have setup a syslog alerting on Firesight Virtual Defense Center but i am unable to get the inline result for the events.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Below is the sample raw event i received&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P style="background: white none repeat scroll 0% 0%; padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'Courier New'; color: black;"&gt;Apr 14 01:09:20 XXXX XXX : [Primary Detection Engine (a9d9147e-dd96-11e2-a935-a6cb913df812)][XXXX][1:34463:2] "APP-DETECT TeamViewer remote administration tool outbound connection attempt" [Classification: Potential Corporate Policy Violation] User: Unknown, Application: TeamViewer, Client: Internet Explorer, App Protocol: HTTPInterface Ingress: s1p2, Interface Egress: s1p1, Security Zone Ingress: External, Security Zone Egress: Internal, [Priority: 1] {TCP} &lt;A href="https://community.cisco.com/UrlBlockedError.aspx" target="_blank"&gt;x.x.x.x:51355&lt;/A&gt; -&amp;gt; &lt;A href="https://community.cisco.com/UrlBlockedError.aspx" target="_blank"&gt;x.x.x.x:80&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="background: white none repeat scroll 0% 0%; padding-left: 30px;"&gt;&lt;SPAN style="font-family: 'Courier New'; color: black;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="background: white none repeat scroll 0% 0%;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; color: black;"&gt;There we could see the snort ID, source, destination, port but not the inline result (whether it is dropped or not)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="background: white none repeat scroll 0% 0%;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; color: black;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="background: white none repeat scroll 0% 0%;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; color: black;"&gt;Is there anyway to change and include those inline result using syslog.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="background: white none repeat scroll 0% 0%;"&gt;&lt;SPAN style="font-family: 'Courier New'; color: black;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="background: white none repeat scroll 0% 0%;"&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; color: black;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:00:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-sourcefire-firesight-syslog-to-include-inline-result/m-p/2859036#M1037719</guid>
      <dc:creator>filterfilter</dc:creator>
      <dc:date>2019-03-12T13:00:58Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/question-sourcefire-firesight-syslog-to-include-inline-result/m-p/2859037#M1037738</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Check this out. Should be able to help.&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118464-configure-firesight-00.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Rate if helps.&lt;/P&gt;
&lt;P&gt;Yogesh&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 May 2016 11:25:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-sourcefire-firesight-syslog-to-include-inline-result/m-p/2859037#M1037738</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2016-05-17T11:25:54Z</dc:date>
    </item>
    <item>
      <title>Hi Yog,</title>
      <link>https://community.cisco.com/t5/network-security/question-sourcefire-firesight-syslog-to-include-inline-result/m-p/2859038#M1037749</link>
      <description>&lt;P&gt;Hi Yog,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I check the documentation you provided, I have successfully retrieved the syslog from sourcefire, problem is the syslog does not have the inline result / action ( dropped or permitted ).&lt;/P&gt;
&lt;P&gt;correct me if i am wrong, I don't think changing the severity and priority will have any effect on that granularity of the syslog, that is only to mark the syslog sent with&amp;nbsp;selected sev and priorioty&amp;nbsp;and only effect how the syslog server process it.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2016 05:49:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-sourcefire-firesight-syslog-to-include-inline-result/m-p/2859038#M1037749</guid>
      <dc:creator>filterfilter</dc:creator>
      <dc:date>2016-05-18T05:49:30Z</dc:date>
    </item>
    <item>
      <title>HI ,</title>
      <link>https://community.cisco.com/t5/network-security/question-sourcefire-firesight-syslog-to-include-inline-result/m-p/2859039#M1037761</link>
      <description>&lt;P&gt;HI ,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Yes you are right changing the severity and priority wont make any changes.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Check : https://bst.cloudapps.cisco.com/bugsearch/bug/CSCux57517/?reffering_site=dumpcr&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Apparently in 5.4 and 6.0 as per the user guide as well only below parameters will be seen in syslog :&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;-date and time of alert generation&lt;BR /&gt;&lt;BR /&gt;-event message&lt;BR /&gt;&lt;BR /&gt;-event data&lt;BR /&gt;&lt;BR /&gt;-generator ID of the triggering event&lt;BR /&gt;&lt;BR /&gt;-Snort ID of the triggering event&lt;BR /&gt;&lt;BR /&gt;-revision&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Aastha Bhardwaj&lt;/P&gt;
&lt;P&gt;Rate if that helps!!!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 May 2016 13:47:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/question-sourcefire-firesight-syslog-to-include-inline-result/m-p/2859039#M1037761</guid>
      <dc:creator>Aastha Bhardwaj</dc:creator>
      <dc:date>2016-05-18T13:47:27Z</dc:date>
    </item>
  </channel>
</rss>

