<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Integration with Logrhythm in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/integration-with-logrhythm/m-p/3340523#M926366</link>
    <description>&lt;P&gt;Right, I believe that is correct. The issue is that this works fine on the other FMC going to LR. Its this one particular FMC and LR instance that is refusing to cooperate. any insight is very much appreciated. thanks!&lt;/P&gt;</description>
    <pubDate>Thu, 01 Mar 2018 16:05:07 GMT</pubDate>
    <dc:creator>jerm10201</dc:creator>
    <dc:date>2018-03-01T16:05:07Z</dc:date>
    <item>
      <title>Integration with Logrhythm</title>
      <link>https://community.cisco.com/t5/network-security/integration-with-logrhythm/m-p/3225709#M926364</link>
      <description>&lt;P&gt;***ERROR*** Error starting eStreamer source&amp;nbsp;xxxxxx eStreamer: SSL authentication failed - closing the connection: A call to SSPI failed, see inner exception.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am receiving this error on a SIEM when attempting to send logs from the estreamer to SIEM. i have recreated the host and tried the SSL cert with and without a password. Is there any known configuration item needed on the SIEM besides installation of the cert?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:53:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integration-with-logrhythm/m-p/3225709#M926364</guid>
      <dc:creator>jerm10201</dc:creator>
      <dc:date>2020-02-21T14:53:15Z</dc:date>
    </item>
    <item>
      <title>Re: Integration with Logrhythm</title>
      <link>https://community.cisco.com/t5/network-security/integration-with-logrhythm/m-p/3225802#M926365</link>
      <description>&lt;P&gt;I believe the SSL authentication is mutual - i.e. FMC must trust the LogRhythm certificate (and signing CA if it's not self-signed) and vice versa.&lt;/P&gt;</description>
      <pubDate>Sat, 02 Dec 2017 02:30:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integration-with-logrhythm/m-p/3225802#M926365</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-12-02T02:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: Integration with Logrhythm</title>
      <link>https://community.cisco.com/t5/network-security/integration-with-logrhythm/m-p/3340523#M926366</link>
      <description>&lt;P&gt;Right, I believe that is correct. The issue is that this works fine on the other FMC going to LR. Its this one particular FMC and LR instance that is refusing to cooperate. any insight is very much appreciated. thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 01 Mar 2018 16:05:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integration-with-logrhythm/m-p/3340523#M926366</guid>
      <dc:creator>jerm10201</dc:creator>
      <dc:date>2018-03-01T16:05:07Z</dc:date>
    </item>
    <item>
      <title>Re: Integration with Logrhythm</title>
      <link>https://community.cisco.com/t5/network-security/integration-with-logrhythm/m-p/3404879#M926367</link>
      <description>&lt;P&gt;Hey Guys,&lt;/P&gt;
&lt;P&gt;I need to integrate FMC&amp;nbsp; 4000 with LogRhythm , I have exported the cert from FMC.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you please brief me on the steps involved , like what all changes we need to make at server end etc?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Prashant&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 13:36:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integration-with-logrhythm/m-p/3404879#M926367</guid>
      <dc:creator>prashant dwivedi</dc:creator>
      <dc:date>2018-06-25T13:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: Integration with Logrhythm</title>
      <link>https://community.cisco.com/t5/network-security/integration-with-logrhythm/m-p/3404946#M926369</link>
      <description>&lt;P&gt;It's an eStreamer integration. The general process is the same for eStreamer clients.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is how you setup the FMC end:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/620/api/eStreamer/EventStreamerIntegrationGuide/ConfiguringEstreamer.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/620/api/eStreamer/EventStreamerIntegrationGuide/ConfiguringEstreamer.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is a blog article that is a couple of years old but still relevant covering both sides of a setup (albeit not LogRhythm):&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://popravak.wordpress.com/2015/07/29/connecting-sourcefire-to-siem-with-estreamer/" target="_blank"&gt;https://popravak.wordpress.com/2015/07/29/connecting-sourcefire-to-siem-with-estreamer/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jun 2018 14:45:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/integration-with-logrhythm/m-p/3404946#M926369</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-06-25T14:45:43Z</dc:date>
    </item>
  </channel>
</rss>

