<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Integrating NSEL with SIEM in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/integrating-nsel-with-siem/m-p/3720426#M11889</link>
    <description>&lt;P&gt;Hi Balaji,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your inputs. I want to clarify a few things:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For question 2 you replied "&lt;SPAN&gt;Netflow will be enable in the device, but it sends more information to Log Server, i am sure you have good compute power to handle those logs." &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For question 3 y&lt;/SPAN&gt;ou said "&lt;SPAN&gt;Netflow give network flow information, not logs."&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;1)From your answers, Netflow is a flow information message, not a log message. Please correct me if i am wrong.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2)Does Netflow only give real-time info or is it possible to retrieve flow info after a week or month?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3) If Netflow cant help to retrieve Anyconnect user log information, what would be the best alternate solution?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 06 Oct 2018 17:44:32 GMT</pubDate>
    <dc:creator>abhijith891</dc:creator>
    <dc:date>2018-10-06T17:44:32Z</dc:date>
    <item>
      <title>Integrating NSEL with SIEM</title>
      <link>https://community.cisco.com/t5/network-security/integrating-nsel-with-siem/m-p/3719808#M11887</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am considering integrating NSEL with our SIEM.&amp;nbsp; We have already integrated our ASAs with our syslog server but I could see that there isnt clear visibility of traffic in our environment; hence thinking of going for Netflow. So I have a few queries regarding this:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) What is the packet size of a Netflow event? How does it hold against a syslog message? Is the difference in size too big?&lt;/P&gt;
&lt;P&gt;2) Will enabling Netflow affect the syslog server's performance(McAfee in our case) inspite of disabling redundant syslog messages?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3) Will enabling Netflow provide us greater visibility with respect to Anyconnect user logs and wireless guest user logs? If not, which other solution should we consider deploying?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help on these would be greatly appreciated.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:19:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integrating-nsel-with-siem/m-p/3719808#M11887</guid>
      <dc:creator>abhijith891</dc:creator>
      <dc:date>2020-02-21T16:19:39Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating NSEL with SIEM</title>
      <link>https://community.cisco.com/t5/network-security/integrating-nsel-with-siem/m-p/3720020#M11888</link>
      <description>&lt;P&gt;Netflow do not have any impact on the modern platform, but you need keep monitor all the time when new things deployed in the network and how it performing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;More information related to netflow can be found here.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://nsrc.org/workshops/2015/sanog25-nmm-tutorial/materials/netflow.pdf" target="_blank"&gt;https://nsrc.org/workshops/2015/sanog25-nmm-tutorial/materials/netflow.pdf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) What is the packet size of a Netflow event? How does it hold against a syslog message? Is the difference in size too big?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Netflow give network flow based in ingress and egress interface passing the traffic via that interface.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2) Will enabling Netflow affect the syslog server's performance(McAfee in our case) inspite of disabling redundant syslog messages?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Netflow will be enable in the device, but it sends more information to Log Server, i am sure you have good compute power to handle those logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3) Will enabling Netflow provide us greater visibility with respect to Anyconnect user logs and wireless guest user logs? If not, which other solution should we consider deploying?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Netflow give network flow information, not logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you looking more of Log process, you can use Prime for wireless.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Oct 2018 14:36:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integrating-nsel-with-siem/m-p/3720020#M11888</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2018-10-05T14:36:30Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating NSEL with SIEM</title>
      <link>https://community.cisco.com/t5/network-security/integrating-nsel-with-siem/m-p/3720426#M11889</link>
      <description>&lt;P&gt;Hi Balaji,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your inputs. I want to clarify a few things:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For question 2 you replied "&lt;SPAN&gt;Netflow will be enable in the device, but it sends more information to Log Server, i am sure you have good compute power to handle those logs." &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;For question 3 y&lt;/SPAN&gt;ou said "&lt;SPAN&gt;Netflow give network flow information, not logs."&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;1)From your answers, Netflow is a flow information message, not a log message. Please correct me if i am wrong.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2)Does Netflow only give real-time info or is it possible to retrieve flow info after a week or month?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3) If Netflow cant help to retrieve Anyconnect user log information, what would be the best alternate solution?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Oct 2018 17:44:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integrating-nsel-with-siem/m-p/3720426#M11889</guid>
      <dc:creator>abhijith891</dc:creator>
      <dc:date>2018-10-06T17:44:32Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating NSEL with SIEM</title>
      <link>https://community.cisco.com/t5/network-security/integrating-nsel-with-siem/m-p/3720440#M11891</link>
      <description>&lt;P&gt;1)From your answers, Netflow is a flow information message, not a log message. Please correct me if i am wrong.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This document give you full in depth information - ( i do not want to re-invent the wheel for that information).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/ios-netflow/prod_white_paper0900aecd80406232.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/ios-netflow/prod_white_paper0900aecd80406232.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;2)Does Netflow only give real-time info or is it possible to retrieve flow info after a week or month?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;yes it give both the information, real time and archive information for reporting - depends on what kind of netflow collector you use.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Example : Solarwinds NTA, PRTG, Elastic Stack can give you that features.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;3) If Netflow cant help to retrieve Anyconnect user log information, what would be the best alternate solution?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;what kind of user log information you looking for, login / Logout or explain more ? to understand better before suggesting.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Oct 2018 19:08:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integrating-nsel-with-siem/m-p/3720440#M11891</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2018-10-06T19:08:33Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating NSEL with SIEM</title>
      <link>https://community.cisco.com/t5/network-security/integrating-nsel-with-siem/m-p/3720455#M11893</link>
      <description>&lt;P&gt;Hi Balaji,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for your inputs. As far as 3rd question, here's the thing:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Say, I want a list of Anyconnect users or who had logged in for the last one week/month, how do I retrieve it? On the ASA, I could see it only stores active VPN sessions, and a session vanishes once the user logs out. I tried checking with our SIEM, but it was of no avail.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Oct 2018 20:40:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integrating-nsel-with-siem/m-p/3720455#M11893</guid>
      <dc:creator>abhijith891</dc:creator>
      <dc:date>2018-10-06T20:40:38Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating NSEL with SIEM</title>
      <link>https://community.cisco.com/t5/network-security/integrating-nsel-with-siem/m-p/3720458#M11896</link>
      <description>&lt;P&gt;How is your authentication method configured ? they authenticate with ACS / AD / or what method ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;couple good post for your reference :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/vpn-and-anyconnect/cisco-asa-5510-vpn-login-history/td-p/2090555" target="_blank"&gt;https://community.cisco.com/t5/vpn-and-anyconnect/cisco-asa-5510-vpn-login-history/td-p/2090555&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/vpn-and-anyconnect/monitoring-vpn-connection-attempts/td-p/1644157" target="_blank"&gt;https://community.cisco.com/t5/vpn-and-anyconnect/monitoring-vpn-connection-attempts/td-p/1644157&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/syslog/b_syslog.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/syslog/b_syslog.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Oct 2018 21:01:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integrating-nsel-with-siem/m-p/3720458#M11896</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2018-10-06T21:01:43Z</dc:date>
    </item>
    <item>
      <title>Re: Integrating NSEL with SIEM</title>
      <link>https://community.cisco.com/t5/network-security/integrating-nsel-with-siem/m-p/3720925#M11897</link>
      <description>&lt;P&gt;Hi Balaji,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are authenticating against the AD.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And thanks a lot for the links. I will look into these, try to implement it and then get back to you.&amp;nbsp; Grateful for&amp;nbsp;all your help and time so far.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Abhijit&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Oct 2018 11:17:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integrating-nsel-with-siem/m-p/3720925#M11897</guid>
      <dc:creator>abhijith891</dc:creator>
      <dc:date>2018-10-08T11:17:24Z</dc:date>
    </item>
  </channel>
</rss>

