cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4145
Views
0
Helpful
2
Replies

Cisco Firepower Connection Logging - [syslog vs eStreamer]

Can I use syslog for collecting connection events [eg. Connection event, IPS event, SI event, Malware event etc] instead of eStreamer ? Are there any connection log events that may be missed if I use syslog ?

My understanding is that the FMC/estreamer adds some correlation/enrichments to the connection events. 

2 Replies 2

tdavoren1
Level 1
Level 1

Hey there,

 

Could you share what configuration you ended up deploying? Just syslog or just eStreamer or a combination? It's been hard to get definitive answers from Cisco on the long term future of eStreamer, but it's enriched events are very useful. 

 

Tim.

Review Cisco Networking for a $25 gift card