09-02-2021 11:08 AM
Is there a way to send connection events and IPS logs from the FMC instead of configuring each FTD to send to a SIEM?
12-13-2022 02:03 AM
was there any response to this. im looking for the same thing
12-13-2022 07:14 AM
This is possible if SIEM supports eStreamer protocol:
For syslog there always be at least two sources of messages: managed devices and FMC. Further, managed devices send both Lina (ASA) syslogs and Snort syslogs (e.g. connection and intrusion events). As of 6.3 syslog server can be configured in a single place (under Platform Settings) and used by both of them.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide