Forum Discussion

Jagadeesh_g900503's avatar
Jagadeesh_g900503
Copper Contributor
Sep 11, 2024

Cisco FTD logs to Sentinel without estreamer

HI Team,

 

We have an project related to sending Ciscon FTD logs to Sentinel ,

 

When we explore about the possibilities there is an additional functionalities which we need to create and maintain the server which is estreamer eNcore server.

 

Cisco is suggested the below operations guide for sending Cisco FTD logs.

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/670/api/eStreamer_enCore/eStreamereNcoreSentinelOperationsGuide_409.html

 

is there any aleternate solution available for ingesting Cisco FTD logs using Syslog itself via Sentinel.?

 

Appreciated your responses.

 

Regards,

Jagadeesh Gunasekaran

  • MHenshaw's avatar
    MHenshaw
    Brass Contributor
    Hi There, yes there is! You can simply just setup syslog forwarding on your FTDS and then use the Syslog via AMA connector on the a linux collector to forward the logs to sentinel, I've recently did this for a client as the estreamer wasnt working correctly due to some python updates that happened in august, the only downside to this is that the logs will not be in CEF format meaning you would probably need to create parser or tweak your rules. -https://support.auvik.com/hc/en-us/articles/360048078412-How-to-configure-syslog-on-Cisco-devices-with-Firepower-Management-Center

Resources