Forum Discussion

Md Zahid Dewan's avatar
Md Zahid Dewan
Copper Contributor
Jun 07, 2017

Integrate ATA with Cisco ASA firewall logs

Hi there,

I have a quick question about Microsoft Advanced Threat Analytics (ATA), How we can integrate ATA with Cisco ASA( Adaptive Security Appliance) Firewall Logs? and if it's possible what will be the implementation requirements for any organization?

 

Thanks in Advanced!

 

 

7 Replies

  • Hi,

    ATA does not integrate with FW logs from any vendor. Today it only collects windows event logs from the DCs which can be captured using a supported SIEM or Windows Event Fowarding.

    • Artom Harchenko's avatar
      Artom Harchenko
      Copper Contributor

      This is now possible. ATA can receive VPN accounting logs from Cisco ASA. It is using RADIUS accounting events forwarded to ATA.

      See this article:

      https://docs.microsoft.com/en-us/advanced-threat-analytics/vpn-integration-install-step

       

      • hongtao jiang's avatar
        hongtao jiang
        Copper Contributor
        Hi Artom,

        the article is for the windows side configuration, do you have a reference for the ASA end configuration?