cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1497
Views
0
Helpful
2
Replies

Cisco Firepower external DBs supported

AlexPi
Level 1
Level 1

I am relatively new in using Firepower IPS and clearly using the internal/local database for all the logs makes the whole system too slow to search for events and obviously the window of backlog is too small. I would like to push all these logs to an external DB.

 

What are the supported SQL versions for Firepower Management 6.2.1?

 

Also it is my understanding that going with MSSQL is out of the window, which is bad since we have extensive MSSQL clustered environments.

 

Any advice would be greatly appreciated!


------------------------------------------------------------------
If this was helpful, please vote as helpful by clicking on the star icon below.
-------------------------------------
2 Replies 2

mikael.lahtela
Level 4
Level 4
Hi,

I would want to suggest you to look at eStreamer to send events to an external event logging.
https://www.cisco.com/c/en/us/td/docs/security/firepower/620/api/eStreamer/EventStreamerIntegrationGuide/Intro.html

br, Micke

Thanks for the suggestion! That looks pretty cool. 

 

I guess I could keep a much longer backlog there, since ideally we want to be able to search up to 6 months back. 

------------------------------------------------------------------
If this was helpful, please vote as helpful by clicking on the star icon below.
-------------------------------------
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card