A cloud-native SIEM solution that provides intelligent security analytics and threat detection across systems
Hello Monalisha,
Thank you so much for your detailed reply to my question. I appreciate the effort you put into explaining the process. You suggested using the CEF via the AMA Connector to ingest logs from the Cisco Firepower Firewall(FTD OS). However, I have a few clarifications.
From my understanding, Cisco generates syslog and eStreamer logs, and there doesn't seem to be a way to configure the Firepower Management Center (FMC) to send the logs in CEF format directly to a Linux VM. My question is, does the AMA Connector have the capability to convert the syslog data into the CEF format for further processing?
Thanks again for your assistance!