<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Send Aggregate Logs from FMC to SIEM in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/send-aggregate-logs-from-fmc-to-siem/m-p/4737736#M1095894</link>
    <description>&lt;P&gt;was there any response to this. im looking for the same thing&lt;/P&gt;</description>
    <pubDate>Tue, 13 Dec 2022 10:03:22 GMT</pubDate>
    <dc:creator>michael18</dc:creator>
    <dc:date>2022-12-13T10:03:22Z</dc:date>
    <item>
      <title>Send Aggregate Logs from FMC to SIEM</title>
      <link>https://community.cisco.com/t5/network-security/send-aggregate-logs-from-fmc-to-siem/m-p/4458978#M1083297</link>
      <description>&lt;P&gt;Is there a way to send connection events and IPS logs from the FMC instead of configuring each FTD to send to a SIEM?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Sep 2021 18:08:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/send-aggregate-logs-from-fmc-to-siem/m-p/4458978#M1083297</guid>
      <dc:creator>Scott_22</dc:creator>
      <dc:date>2021-09-02T18:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: Send Aggregate Logs from FMC to SIEM</title>
      <link>https://community.cisco.com/t5/network-security/send-aggregate-logs-from-fmc-to-siem/m-p/4737736#M1095894</link>
      <description>&lt;P&gt;was there any response to this. im looking for the same thing&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 10:03:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/send-aggregate-logs-from-fmc-to-siem/m-p/4737736#M1095894</guid>
      <dc:creator>michael18</dc:creator>
      <dc:date>2022-12-13T10:03:22Z</dc:date>
    </item>
    <item>
      <title>Re: Send Aggregate Logs from FMC to SIEM</title>
      <link>https://community.cisco.com/t5/network-security/send-aggregate-logs-from-fmc-to-siem/m-p/4737923#M1095914</link>
      <description>&lt;P&gt;This is possible if SIEM supports eStreamer protocol:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/admin/710/management-center-admin-71/analysis-external-tools.html#id_85394" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/admin/710/management-center-admin-71/analysis-external-tools.html#id_85394&lt;/A&gt;&lt;/P&gt;&lt;P&gt;For syslog there always be at least two sources of messages: managed devices and FMC. Further, managed devices send both Lina (ASA) syslogs and Snort syslogs (e.g. connection and intrusion events). As of 6.3 syslog server can be configured in a single place (under Platform Settings) and used by both of them.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/710/management-center-device-config-71/interfaces-settings-platform.html#task_88952FB807AB4D43B0894F99B215EDD4" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/710/management-center-device-config-71/interfaces-settings-platform.html#task_88952FB807AB4D43B0894F99B215EDD4&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/710/management-center-device-config-71/access-policies.html#AC_Policy_Syslog_Settings" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/710/management-center-device-config-71/access-policies.html#AC_Policy_Syslog_Settings&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Dec 2022 15:14:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/send-aggregate-logs-from-fmc-to-siem/m-p/4737923#M1095914</guid>
      <dc:creator>tvotna</dc:creator>
      <dc:date>2022-12-13T15:14:36Z</dc:date>
    </item>
  </channel>
</rss>

