Forum Discussion

Susantha Silva's avatar
Susantha Silva
Copper Contributor
Aug 27, 2021

How to connect CISCO switches logs to Sentinel

I have a customer who requires collecting logs from above devices, firewalls and Windows, Linux servers. I'm ok with later components but couldn't figure out a way to collect logs from switches. Do we go with Linux syslog and collect the logs from cisco devices and forward to Sentinel? If that the case how to query them?

6 Replies

    • Susantha Silva's avatar
      Susantha Silva
      Copper Contributor
      GaryA thank you for the quick response. CISCO connectors available in the Sentinel talk about CISCO firewalls and above. Anyway I found out best option is to setup Linux syslog server and forward switches logs to that and forward to Sentinel. But I still didn't see much documentation about these process and how to query data out of Sentinel. Let me see further since I'm also exploring Sentinel at this stage.
      • wabarahona's avatar
        wabarahona
        Copper Contributor

        Susantha Silva 

         

        Hi, I hope you are doing ok, I was wondering if you can help me with the setup you did to send Cisco logs to Linux and then to Azure.

         

        thank you in advance for your help, my email mailto:email address removed for privacy reasons or mailto:email address removed for privacy reasons

         

Resources