Cisco Firepower Integration (FTD)with Microsoft Sentinel

Aksoy, Mehmet 30 Reputation points
2025-10-24T18:26:31.7833333+00:00

Dear Microsoft Support,

I am currently working to integrate Microsoft Sentinel with Cisco Firepower using the recommended Cisco Firepower eStreamer data connector. As part of the setup, Microsoft’s documentation references the use of the Cisco eStreamer eNcore client to forward logs to Sentinel.

However, I’ve discovered that the eNcore client officially reached end-of-life (EOL) as of July 1, 2024, and is no longer supported by Cisco (Cisco Community Reference). This presents a significant challenge, as the integration relies on a deprecated tool that may no longer function reliably or securely in modern environments.

Additionally, if you follow the first link under the “Set up the connection” section in Microsoft’s own guide, it leads to outdated Cisco documentation. Those links have since been redirected to a new GitHub page, which clearly states that the eNcore client has reached EOL and is no longer maintained.

Could you please advise on the following:

  • Is there a supported replacement for the eStreamer eNcore client?
  • Are there any recommended best practices or alternative methods for forwarding Cisco Firepower logs to Microsoft Sentinel post-EOL?

Your guidance on how to proceed with a secure and supported integration path would be greatly appreciated.

Microsoft Security | Microsoft Sentinel

1 answer

Sort by: Most helpful
  1. Aksoy, Mehmet 30 Reputation points
    2025-10-28T14:18:47.8133333+00:00

    Hello Monalisha,

    Thank you so much for your detailed reply to my question. I appreciate the effort you put into explaining the process. You suggested using the CEF via the AMA Connector to ingest logs from the Cisco Firepower Firewall(FTD OS). However, I have a few clarifications.

     

    From my understanding, Cisco generates syslog and eStreamer logs, and there doesn't seem to be a way to configure the Firepower Management Center (FMC) to send the logs in CEF format directly to a Linux VM. My question is, does the AMA Connector have the capability to convert the syslog data into the CEF format for further processing?

    Thanks again for your assistance!

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.