03-22-2022 07:29 PM
Can I use syslog for collecting connection events [eg. Connection event, IPS event, SI event, Malware event etc] instead of eStreamer ? Are there any connection log events that may be missed if I use syslog ?
My understanding is that the FMC/estreamer adds some correlation/enrichments to the connection events.
03-24-2022 02:49 AM
Hi,
You should check this section of user guide:
BR,
Octavian
05-24-2022 07:18 PM
Hey there,
Could you share what configuration you ended up deploying? Just syslog or just eStreamer or a combination? It's been hard to get definitive answers from Cisco on the long term future of eStreamer, but it's enriched events are very useful.
Tim.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide