cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1293
Views
0
Helpful
1
Replies

[ESA] Custom Log Fields per Syslog (CEF)

I am looking for a way to transmit Custom Log Fields via Syslog (CEF format).

Currently it seems that you can only transfer the default log fields:
But I would like to transfer additional log information, which I write e.g. via a content filter or message filter.
As a workaround it would be sufficient if I could see in the transmitted log which content filter is '"matched", but this is apparently not possible, because you can only see if a CF is matched (ESACFVerdict=MATCH).

Please let me know if there are possibilities.

 

 

1 Reply 1

Libin Varghese
Cisco Employee
Cisco Employee

This is being tracked under the below enhancement.

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvv65368

 

Regards,

Libin