<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firepower IPS logging - syslog vs estreamer in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-ips-logging-syslog-vs-estreamer/m-p/4454830#M1083147</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it be possible to collect Firepower IPS connection events via syslog rather than estreamer (FMC)? If yes, is there any info that may be missed (e.g. security intelligence events, any potential interesting fields within the connection event?)&lt;/P&gt;&lt;P&gt;My understanding is that the FMC/estreamer adds some correlation/enrichments to the connection events.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
    <pubDate>Wed, 25 Aug 2021 16:16:49 GMT</pubDate>
    <dc:creator>sindandoh</dc:creator>
    <dc:date>2021-08-25T16:16:49Z</dc:date>
    <item>
      <title>Firepower IPS logging - syslog vs estreamer</title>
      <link>https://community.cisco.com/t5/network-security/firepower-ips-logging-syslog-vs-estreamer/m-p/4454830#M1083147</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is it be possible to collect Firepower IPS connection events via syslog rather than estreamer (FMC)? If yes, is there any info that may be missed (e.g. security intelligence events, any potential interesting fields within the connection event?)&lt;/P&gt;&lt;P&gt;My understanding is that the FMC/estreamer adds some correlation/enrichments to the connection events.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 16:16:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-ips-logging-syslog-vs-estreamer/m-p/4454830#M1083147</guid>
      <dc:creator>sindandoh</dc:creator>
      <dc:date>2021-08-25T16:16:49Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower IPS logging - syslog vs estreamer</title>
      <link>https://community.cisco.com/t5/network-security/firepower-ips-logging-syslog-vs-estreamer/m-p/4454977#M1083158</link>
      <description>&lt;P&gt;As far as I know you need to use estreamer to get IPS, security intelligence, (etc.) type events.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Aug 2021 20:15:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-ips-logging-syslog-vs-estreamer/m-p/4454977#M1083158</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2021-08-25T20:15:47Z</dc:date>
    </item>
  </channel>
</rss>

