Forum Discussion
Md Zahid Dewan
Jun 07, 2017Copper Contributor
Integrate ATA with Cisco ASA firewall logs
Hi there,
I have a quick question about Microsoft Advanced Threat Analytics (ATA), How we can integrate ATA with Cisco ASA( Adaptive Security Appliance) Firewall Logs? and if it's possible what will be the implementation requirements for any organization?
Thanks in Advanced!
7 Replies
- Nicholas DiCola (SECURITY JEDI)Former Employee
Hi,
ATA does not integrate with FW logs from any vendor. Today it only collects windows event logs from the DCs which can be captured using a supported SIEM or Windows Event Fowarding.
- Artom HarchenkoCopper Contributor
This is now possible. ATA can receive VPN accounting logs from Cisco ASA. It is using RADIUS accounting events forwarded to ATA.
See this article:
https://docs.microsoft.com/en-us/advanced-threat-analytics/vpn-integration-install-step
- hongtao jiangCopper ContributorHi Artom,
the article is for the windows side configuration, do you have a reference for the ASA end configuration?