Hi,
We have a cisco IPS module in ASA which supports SDEE. I would like to know if we can get the logs for configuration changes, user account creations etc using SDEE. Splunk is used to get the SDEE events and we are receiving only the intrusions and vulnerabilities. Cisco IPS manager express is showing the user creation logs but it doesn't come in splunk. Any help would be really appreciated.
Regards
Sajin