on 06-01-2020 03:47 AM
Does anyone know if there is an easier way than the below
Q. I check connection events for IOC's when requested and sometimes i have to check many url's which i am presently doing one url at a time and is very time consuming, is there a way to check multiple URL's in connection events this would save some much time for me.
Thanks
im having same question and im looking for any opensource SIEM or external logging for the FMC since logs get rotated to fast. looking into ELK stack but having issue setting it up
You can check IOCs in groups using Cisco Threat Response if you've integrated your Firepower Management Center with CTR.
(By the way this should have been posted as a discussion, not a document.)
Hi Marvin
Thanks for the response how do I check if we have our FMC intergrated with CRT ??
apologies i didnt realise about this being posted incorrectly.
thanks
ctr
i think enabling Cisco Cloud but you need to register an account. im still a newbie with CTR.
https://visibility.amp.cisco.com/ link to CTR and remember to add Firepower module.
Yes, generally you should have 6.4 or later, preferably 6.5 or later.
See the following guide:
The integration is free and very powerful - especially for this use case - searching through a list of IOCs to see if your security product(s) have encountered any of them.
Google some of the great Youtube demos the Cisco product team has posted for CTR.
Thanks
Very helpful
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: