<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sending Cisco Device Syslog in CEF into Microsoft Sentinel in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sending-cisco-device-syslog-in-cef-into-microsoft-sentinel/m-p/5344482#M1123391</link>
    <description>&lt;DIV class=""&gt;These are the 2 documentations that we followed to ingest Cisco device syslog into our Sentinel instance:&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;U&gt;&lt;A title="https://learn.microsoft.com/en-us/azure/sentinel/forward-syslog-monitor-agent" href="https://learn.microsoft.com/en-us/azure/sentinel/forward-syslog-monitor-agent" target="_blank" rel="noopener"&gt;https://learn.microsoft.com/en-us/azure/sentinel/forward-syslog-monitor-agent&lt;/A&gt;&lt;/U&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;U&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/670/api/eStreamer_enCore/eStreamereNcoreSentinelOperationsGuide_409.html" target="_blank" rel="noopener"&gt;eStreamer eNcore for Sentinel Operations Guide v4.0.9 - Cisco&lt;/A&gt;&lt;/U&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;Issue 1:&lt;/STRONG&gt; The problem with our current working setup is that the syslog is not in Common Event Format (CEF). What I understand is that the Microsoft Azure Monitoring Agent (AMA) only collects/monitors/ingests syslog into Microsoft Sentinel. The Microsoft AMA does not convert the syslog into CEF. The formatting of Cisco device syslog has always been determined at the Cisco device end.&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;Issue 2:&lt;/STRONG&gt;&amp;nbsp;In our case, we want CEF format and Cisco has always utilized the Cisco eStreamer integration to send its Cisco devices' syslog in CEF into 3rd&amp;nbsp;party SIEMs (like Splunk, Sentinel, etc...). The issue is that Cisco eStreamer (eNcore client) solution is EOL and unsupported, is there a plan to replace Cisco's ability to send its device syslog in CEF?&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;Cisco eStreamer (eNcore client) solution is EOL/unsupported and we need a solution to ingest Cisco syslog in CEF into our Microsoft Sentinel. Is there a way to do this?&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Thanks in advance.&lt;/DIV&gt;</description>
    <pubDate>Tue, 04 Nov 2025 19:16:08 GMT</pubDate>
    <dc:creator>grant-luong</dc:creator>
    <dc:date>2025-11-04T19:16:08Z</dc:date>
    <item>
      <title>Sending Cisco Device Syslog in CEF into Microsoft Sentinel</title>
      <link>https://community.cisco.com/t5/network-security/sending-cisco-device-syslog-in-cef-into-microsoft-sentinel/m-p/5344482#M1123391</link>
      <description>&lt;DIV class=""&gt;These are the 2 documentations that we followed to ingest Cisco device syslog into our Sentinel instance:&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;U&gt;&lt;A title="https://learn.microsoft.com/en-us/azure/sentinel/forward-syslog-monitor-agent" href="https://learn.microsoft.com/en-us/azure/sentinel/forward-syslog-monitor-agent" target="_blank" rel="noopener"&gt;https://learn.microsoft.com/en-us/azure/sentinel/forward-syslog-monitor-agent&lt;/A&gt;&lt;/U&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;U&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/670/api/eStreamer_enCore/eStreamereNcoreSentinelOperationsGuide_409.html" target="_blank" rel="noopener"&gt;eStreamer eNcore for Sentinel Operations Guide v4.0.9 - Cisco&lt;/A&gt;&lt;/U&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;Issue 1:&lt;/STRONG&gt; The problem with our current working setup is that the syslog is not in Common Event Format (CEF). What I understand is that the Microsoft Azure Monitoring Agent (AMA) only collects/monitors/ingests syslog into Microsoft Sentinel. The Microsoft AMA does not convert the syslog into CEF. The formatting of Cisco device syslog has always been determined at the Cisco device end.&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;Issue 2:&lt;/STRONG&gt;&amp;nbsp;In our case, we want CEF format and Cisco has always utilized the Cisco eStreamer integration to send its Cisco devices' syslog in CEF into 3rd&amp;nbsp;party SIEMs (like Splunk, Sentinel, etc...). The issue is that Cisco eStreamer (eNcore client) solution is EOL and unsupported, is there a plan to replace Cisco's ability to send its device syslog in CEF?&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;STRONG&gt;Cisco eStreamer (eNcore client) solution is EOL/unsupported and we need a solution to ingest Cisco syslog in CEF into our Microsoft Sentinel. Is there a way to do this?&lt;/STRONG&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Thanks in advance.&lt;/DIV&gt;</description>
      <pubDate>Tue, 04 Nov 2025 19:16:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sending-cisco-device-syslog-in-cef-into-microsoft-sentinel/m-p/5344482#M1123391</guid>
      <dc:creator>grant-luong</dc:creator>
      <dc:date>2025-11-04T19:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: Sending Cisco Device Syslog in CEF into Microsoft Sentinel</title>
      <link>https://community.cisco.com/t5/network-security/sending-cisco-device-syslog-in-cef-into-microsoft-sentinel/m-p/5345528#M1123431</link>
      <description>&lt;P&gt;There are no current plans to support&amp;nbsp;CEF format for Syslog. If this is an important functionality, please reach out to your Cisco account team and request that they file and enhancement request on your behalf.&amp;nbsp;&lt;/P&gt;
&lt;DIV id="bodyDisplay_3" class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;
&lt;DIV class="lia-message-body-content"&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Sat, 08 Nov 2025 15:13:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sending-cisco-device-syslog-in-cef-into-microsoft-sentinel/m-p/5345528#M1123431</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2025-11-08T15:13:46Z</dc:date>
    </item>
  </channel>
</rss>

