cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
253
Views
0
Helpful
2
Replies

FMC / FTD Estreamer for basic reporting

Alex-Pr
Level 1
Level 1

I'm looking to get some basic reporting from FMC for things like top talkers but can't seem to do it in FMC because a lot of the logs are not going to the event viewer due to its limited size.  What is a simple tool that can be integrated to get reports and visualization for traffic and talkers?

I'm assuming the best bet is to setup something that can take the feed via eStreamer.

Thanks

2 Replies 2

FMC has some good graphs and reports even if the logs fill up.. have you looked at them ?

you can also get top talkers from FMC rest api

https://community.cisco.com/t5/network-security/how-to-fetch-the-top-talkers-from-fmc-via-rest-api/td-p/4887489

you can traffic from SNMP using regular polling on the managed devices will give you better insight.  But FMC also shows the traffic.

Estreamer is good if you are using app like splunk encore app, otherwise you would have to parse the files with raw data and visualize it. Not the easiest.  I would explore fmc itself and it can even email you the report.

Review Cisco Networking for a $25 gift card