cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
162
Views
0
Helpful
2
Replies

Secure network analtics syslog

ahmedFawzy
Level 1
Level 1

can cisco secure network analytics use firewall syslog ingested from telemetry broker for analysis. and how can i configure SNA to receive syslog?

2 Replies 2

Cristian Matei
VIP Alumni
VIP Alumni

kegunner
Cisco Employee
Cisco Employee
Hi,
Yes SNA can ingest syslog from firewalls via CTB if using SNA with datastore. Create the rule in CTB to forward SAL using UDP/8514.
On your FlowCollector, access the appliance administration interface, head to Support, Advanced Settings and ensure that:
sal_syslog_port = 8514
sal_to_flow_cache = 1