We need to filter out the below events IDs from SIEM as per CISCO's recommendation: https://www.cisco.com/c/dam/en/us/solutions/collateral/enterprise/design-zone-security-technology-partners/bn_cisco_siem.pdf
%ASA-6-305010: Teardown translation from interface_name to interface_name
%ASA-6-305011: Built translation from interface_name to interface_name
%ASA-6-305012: Teardown translation from interface_name to interface_name
%ASA-6-302014: Teardown TCP connection id for interface to interface
%ASA-6-302016: Teardown UDP connection number for interface to interface
%ASA-6-302013: Built TCP connection_id for interface to interface
Are there any other event IDs which can tell the communication between two hosts apart from the one mention above?
Or devices which can detect the communication between two hosts ?
Also what other event IDS or message log level we can drop from reaching towards our SIEM tool.
Thanks in advance.
Kind Regards,
Nikhil