<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to export logs from FMC. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-export-logs-from-fmc/m-p/3477143#M133067</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;I have a small question about Firepower&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;My customer has some attack event last week. He wants us to export the Sourcefire logs that generate last week for them to analyze. They will import it to a new SIEM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;They don’t have any syslog server in their environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;Do you know how to export all the intrusion events or connection events from FMC?&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;Brian Li&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 12 Dec 2017 09:55:49 GMT</pubDate>
    <dc:creator>lanwei Li</dc:creator>
    <dc:date>2017-12-12T09:55:49Z</dc:date>
    <item>
      <title>How to export logs from FMC.</title>
      <link>https://community.cisco.com/t5/network-security/how-to-export-logs-from-fmc/m-p/3477143#M133067</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;I have a small question about Firepower&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;My customer has some attack event last week. He wants us to export the Sourcefire logs that generate last week for them to analyze. They will import it to a new SIEM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;They don’t have any syslog server in their environment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;Do you know how to export all the intrusion events or connection events from FMC?&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;&lt;/P&gt;&lt;P style="font-size: 12pt; font-family: Calibri, sans-serif; color: #000000;"&gt;Brian Li&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Dec 2017 09:55:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-export-logs-from-fmc/m-p/3477143#M133067</guid>
      <dc:creator>lanwei Li</dc:creator>
      <dc:date>2017-12-12T09:55:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to export logs from FMC.</title>
      <link>https://community.cisco.com/t5/network-security/how-to-export-logs-from-fmc/m-p/3477144#M133072</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I don't think there is a way to pull existing data out in any format for import into another tool. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will have to just use FMC for analysis of the existing data, and start sending syslog data to the SIEM from this point forward.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ryan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Dec 2017 18:28:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-export-logs-from-fmc/m-p/3477144#M133072</guid>
      <dc:creator>Ryan Wolfe</dc:creator>
      <dc:date>2017-12-15T18:28:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to export logs from FMC.</title>
      <link>https://community.cisco.com/t5/network-security/how-to-export-logs-from-fmc/m-p/3477145#M133079</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Brian,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition to what Ryan mentioned since we cannot export the logs into external tool. FMC does have the option of context explorer which give consolidated time line of what events took place for specific IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raghu&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Dec 2017 06:35:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-export-logs-from-fmc/m-p/3477145#M133079</guid>
      <dc:creator>Raghunath Kulkarni</dc:creator>
      <dc:date>2017-12-20T06:35:17Z</dc:date>
    </item>
  </channel>
</rss>

