Hello,
Is it be possible to collect Firepower IPS connection events via syslog rather than estreamer (FMC)? If yes, is there any info that may be missed (e.g. security intelligence events, any potential interesting fields within the connection event?)
My understanding is that the FMC/estreamer adds some correlation/enrichments to the connection events.
Thanks,