<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Open Cybersecurity Schema Framework (OCSF) Firepower ASA log examples? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/open-cybersecurity-schema-framework-ocsf-firepower-asa-log/m-p/4837738#M1100487</link>
    <description>&lt;P&gt;I have some Cisco ASA and Firepower logs, and I am attempting to ingest these into the Amazon data lake. To ingest these logs into the Amazon Data lake they must be converted to the Open Cybersecurity Schema Framework (OCSF) format.&amp;nbsp;There Great blog here on the Cisco and Amazon partnership with more background:&amp;nbsp;&lt;A href="https://blogs.cisco.com/security/cisco-joins-amazon-web-services-aws-for-the-launch-of-security-lake" target="_blank" rel="noopener"&gt;https://blogs.cisco.com/security/cisco-joins-amazon-web-services-aws-for-the-launch-of-security-lake&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;To ingest these into the Amazon data lake, they first must be converted into the OCSF log format which has definitions defined here:&amp;nbsp;&lt;A href="https://schema.ocsf.io/" target="_blank" rel="noopener"&gt;https://schema.ocsf.io/&lt;/A&gt;&amp;nbsp;. The OCSF log is a JSON based log and the organization has provided a sample log for an Amazon VPC Log.&amp;nbsp;&lt;A href="https://github.com/ocsf/examples/blob/main/Network%20Activity/Network%20Activity/AWS/VPC%20Flowlogs/vpcflowlog.json" target="_blank" rel="noopener"&gt;https://github.com/ocsf/examples/blob/main/Network%20Activity/Network%20Activity/AWS/VPC%20Flowlogs/vpcflowlog.json&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The problem is I do not have any examples of a Firepower and ASA log converted into the OCSF format. Does anyone have any examples/field mappings/schemas of what a Cisco ASA/Firepower log would look like when converted into OCSF?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 17 May 2023 15:04:25 GMT</pubDate>
    <dc:creator>Bronette</dc:creator>
    <dc:date>2023-05-17T15:04:25Z</dc:date>
    <item>
      <title>Open Cybersecurity Schema Framework (OCSF) Firepower ASA log examples?</title>
      <link>https://community.cisco.com/t5/network-security/open-cybersecurity-schema-framework-ocsf-firepower-asa-log/m-p/4837738#M1100487</link>
      <description>&lt;P&gt;I have some Cisco ASA and Firepower logs, and I am attempting to ingest these into the Amazon data lake. To ingest these logs into the Amazon Data lake they must be converted to the Open Cybersecurity Schema Framework (OCSF) format.&amp;nbsp;There Great blog here on the Cisco and Amazon partnership with more background:&amp;nbsp;&lt;A href="https://blogs.cisco.com/security/cisco-joins-amazon-web-services-aws-for-the-launch-of-security-lake" target="_blank" rel="noopener"&gt;https://blogs.cisco.com/security/cisco-joins-amazon-web-services-aws-for-the-launch-of-security-lake&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;To ingest these into the Amazon data lake, they first must be converted into the OCSF log format which has definitions defined here:&amp;nbsp;&lt;A href="https://schema.ocsf.io/" target="_blank" rel="noopener"&gt;https://schema.ocsf.io/&lt;/A&gt;&amp;nbsp;. The OCSF log is a JSON based log and the organization has provided a sample log for an Amazon VPC Log.&amp;nbsp;&lt;A href="https://github.com/ocsf/examples/blob/main/Network%20Activity/Network%20Activity/AWS/VPC%20Flowlogs/vpcflowlog.json" target="_blank" rel="noopener"&gt;https://github.com/ocsf/examples/blob/main/Network%20Activity/Network%20Activity/AWS/VPC%20Flowlogs/vpcflowlog.json&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The problem is I do not have any examples of a Firepower and ASA log converted into the OCSF format. Does anyone have any examples/field mappings/schemas of what a Cisco ASA/Firepower log would look like when converted into OCSF?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 May 2023 15:04:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/open-cybersecurity-schema-framework-ocsf-firepower-asa-log/m-p/4837738#M1100487</guid>
      <dc:creator>Bronette</dc:creator>
      <dc:date>2023-05-17T15:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: Open Cybersecurity Schema Framework (OCSF) Firepower ASA log examp</title>
      <link>https://community.cisco.com/t5/network-security/open-cybersecurity-schema-framework-ocsf-firepower-asa-log/m-p/5023145#M1109383</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you ever come to any conclusion on this?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 02:40:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/open-cybersecurity-schema-framework-ocsf-firepower-asa-log/m-p/5023145#M1109383</guid>
      <dc:creator>bsaurusrex</dc:creator>
      <dc:date>2024-02-23T02:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: Open Cybersecurity Schema Framework (OCSF) Firepower ASA log examp</title>
      <link>https://community.cisco.com/t5/network-security/open-cybersecurity-schema-framework-ocsf-firepower-asa-log/m-p/5333449#M1122889</link>
      <description>&lt;P&gt;&lt;A href="https://github.com/ocsf/examples/tree/main/mappings/markdown/Cisco/v1.3.0/ASA" target="_blank"&gt;https://github.com/ocsf/examples/tree/main/mappings/markdown/Cisco/v1.3.0/ASA&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Sep 2025 13:02:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/open-cybersecurity-schema-framework-ocsf-firepower-asa-log/m-p/5333449#M1122889</guid>
      <dc:creator>lrypl</dc:creator>
      <dc:date>2025-09-25T13:02:15Z</dc:date>
    </item>
  </channel>
</rss>

