Cisco Firepower Connection Logging - [syslog vs eStreamer]
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-22-2022 07:29 PM
Can I use syslog for collecting connection events [eg. Connection event, IPS event, SI event, Malware event etc] instead of eStreamer ? Are there any connection log events that may be missed if I use syslog ?
My understanding is that the FMC/estreamer adds some correlation/enrichments to the connection events.

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-24-2022 02:49 AM
Hi,
You should check this section of user guide:
BR,
Octavian
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-24-2022 07:18 PM
Hey there,
Could you share what configuration you ended up deploying? Just syslog or just eStreamer or a combination? It's been hard to get definitive answers from Cisco on the long term future of eStreamer, but it's enriched events are very useful.
Tim.
