Forum Discussion
Susantha Silva
Aug 27, 2021Copper Contributor
How to connect CISCO switches logs to Sentinel
I have a customer who requires collecting logs from above devices, firewalls and Windows, Linux servers. I'm ok with later components but couldn't figure out a way to collect logs from switches. Do we go with Linux syslog and collect the logs from cisco devices and forward to Sentinel? If that the case how to query them?
- GaryBusheyBronze Contributor
Susantha Silva I am not that familiar with the Cisco naming, but have you looked at the connectors grand list to see if the product is listed there?
- Susantha SilvaCopper ContributorGaryA thank you for the quick response. CISCO connectors available in the Sentinel talk about CISCO firewalls and above. Anyway I found out best option is to setup Linux syslog server and forward switches logs to that and forward to Sentinel. But I still didn't see much documentation about these process and how to query data out of Sentinel. Let me see further since I'm also exploring Sentinel at this stage.
- wabarahonaCopper Contributor
Hi, I hope you are doing ok, I was wondering if you can help me with the setup you did to send Cisco logs to Linux and then to Azure.
thank you in advance for your help, my email email address removed for privacy reasons or email address removed for privacy reasons