Forum Discussion

dnsrk's avatar
dnsrk
Brass Contributor
Dec 09, 2023
Solved

Connecting Cisco ASA via CEF AMA Connector

Hey,
I am trying to set up a collector machine to collect CEF logs and logs for Cisco ASA in Sentinel using the AMA. CEF logs seem to look just fine, but the ASA log collection does not work completely. Also, when running the verification script "sudo wget -O Sentinel_AMA_troubleshoot.py https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/DataConnectors/Syslog/Sentinel_AMA_troubleshoot.py&&sudo python Sentinel_AMA_troubleshoot.py --asa" https://github.com/MicrosoftDocs/azure-docs/blob/main/articles/sentinel/connect-cef-ama.md#set-up-the-connector I get the following error: verify_DCR_content_has_stream------------------> Failure.

Based on the verification script it expects "SECURITY_CISCO_ASA_BLOB" in the stream name. Unfortunately, I have no idea how to add this and could not find any documentation.

Many thanks for any help in advance.

  • For anybody interested... here is the solution
    https://github.com/MicrosoftDocs/azure-docs/issues/115048

2 Replies

  • dnsrk's avatar
    dnsrk
    Brass Contributor
    For anybody interested... here is the solution
    https://github.com/MicrosoftDocs/azure-docs/issues/115048
  • dnsrk's avatar
    dnsrk
    Brass Contributor
    One additional note I see ASA logs in Syslog, but not in CommonSecuirty Logs

Resources