<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Event definition and capacity calculation in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/event-definition-and-capacity-calculation/m-p/1541600#M923053</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Due to the implementation of a CSM, there are a couple of things that I need to clarify in order to be sure about the Server requirements.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. What is the definition of an event in a security device? Is it a violation to rules? Is it a connection fail??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. How could I posibbly know the storage capacity required to handle the events send by an ASA? Is there an especific size for this logs/packets???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your comments.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 12:04:21 GMT</pubDate>
    <dc:creator>dbarboza27</dc:creator>
    <dc:date>2020-02-21T12:04:21Z</dc:date>
    <item>
      <title>Event definition and capacity calculation</title>
      <link>https://community.cisco.com/t5/network-security/event-definition-and-capacity-calculation/m-p/1541600#M923053</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Due to the implementation of a CSM, there are a couple of things that I need to clarify in order to be sure about the Server requirements.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. What is the definition of an event in a security device? Is it a violation to rules? Is it a connection fail??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. How could I posibbly know the storage capacity required to handle the events send by an ASA? Is there an especific size for this logs/packets???&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your comments.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:04:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-definition-and-capacity-calculation/m-p/1541600#M923053</guid>
      <dc:creator>dbarboza27</dc:creator>
      <dc:date>2020-02-21T12:04:21Z</dc:date>
    </item>
    <item>
      <title>Re: Event definition and capacity calculation</title>
      <link>https://community.cisco.com/t5/network-security/event-definition-and-capacity-calculation/m-p/1541601#M923054</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Douglas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The events from the ASA are simply the syslogs that are generated by the firewall. However, certain syslogs are "deeply parsed" by CSM to provide additional details. Here is a list of syslogs that are deeply parsed (the rest are displayed as raw syslog data):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/security_management/cisco_security_manager/security_manager/4.0/user/guide/evntchap.html#wp191617"&gt;http://www.cisco.com/en/US/docs/security/security_management/cisco_security_manager/security_manager/4.0/user/guide/evntchap.html#wp191617&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As for the storage requirements, this will depend on the amount/level of logs that are generated by your ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Sep 2010 19:53:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-definition-and-capacity-calculation/m-p/1541601#M923054</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2010-09-03T19:53:47Z</dc:date>
    </item>
    <item>
      <title>Re: Event definition and capacity calculation</title>
      <link>https://community.cisco.com/t5/network-security/event-definition-and-capacity-calculation/m-p/1541602#M923055</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi mirober2,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the link,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found the following reference:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;A 2TB disk can store less than eight weeks of events at the rate of &lt;/EM&gt;&lt;EM&gt;5,000 events/sec. with an average size of 250 bytes compressed per &lt;/EM&gt;&lt;EM&gt;event.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will use this info to define the server to install the CSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Regards&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Sep 2010 22:20:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/event-definition-and-capacity-calculation/m-p/1541602#M923055</guid>
      <dc:creator>dbarboza27</dc:creator>
      <dc:date>2010-09-03T22:20:57Z</dc:date>
    </item>
  </channel>
</rss>

