Forum Discussion
AngeloDC
Nov 28, 2023Copper Contributor
Cisco ASA | SIEM Log filtering Best Practice
Hey all you SIEM and SecDevOPs Engineers. Currently having major ingestion issues with Events logged from CISCO ASA.The problem: Even with filtering limited to Notification L5 events we accidently i...
AngeloDC
Nov 29, 2023Copper Contributor
Well I've come up with this so far.
If you have any input please feel free to share.
Here are some of the events we chose to filter.
| Filter Rule |
| ------------------------------ |
| :msg, contains, "ASA-4-733100" |
| :msg, contains, "ASA-4-733101" |
| :msg, contains, "ASA-4-733102" |
| :msg, contains, "ASA-4-733103" |
| :msg, contains, "ASA-4-733104" |
| :msg, contains, "ASA-4-733105" |
| :msg, contains, "ASA-6-106100" |
| :msg, contains, "ASA-4-106023" |
| :msg, contains, "ASA-5-713041" |
| :msg, contains, "ASA-6-109001" |
If you have any input please feel free to share.
Here are some of the events we chose to filter.
| Filter Rule |
| ------------------------------ |
| :msg, contains, "ASA-4-733100" |
| :msg, contains, "ASA-4-733101" |
| :msg, contains, "ASA-4-733102" |
| :msg, contains, "ASA-4-733103" |
| :msg, contains, "ASA-4-733104" |
| :msg, contains, "ASA-4-733105" |
| :msg, contains, "ASA-6-106100" |
| :msg, contains, "ASA-4-106023" |
| :msg, contains, "ASA-5-713041" |
| :msg, contains, "ASA-6-109001" |