<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Estreamer vs syslog from ASA firewalls in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Estreamer-vs-syslog-from-ASA-firewalls/m-p/369764#M44664</link>
    <description>&lt;P&gt;I've a table comparing syslog vs estreamer options. But not sure if I can paste that into splunk answers. Let me try finding a place I can put it or a screenshot&lt;/P&gt;</description>
    <pubDate>Mon, 30 Apr 2018 16:25:59 GMT</pubDate>
    <dc:creator>koshyk</dc:creator>
    <dc:date>2018-04-30T16:25:59Z</dc:date>
    <item>
      <title>Estreamer vs syslog from ASA firewalls</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Estreamer-vs-syslog-from-ASA-firewalls/m-p/369761#M44661</link>
      <description>&lt;P&gt;Do Cisco ASA NGFWs aka X-series and firepower series sending logs to FMC and collecting via estreamer provide equal or greater logging within Splunk over syslog from the ASA?&lt;/P&gt;

&lt;P&gt;Meaning everything event visible in syslog can be seen in the estreamer feed in some way.  &lt;/P&gt;

&lt;P&gt;One of the other concerning issues is the size of the events syslog is 200bytes/event while estreamer is 2000bytes for connection events.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Apr 2018 20:42:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Estreamer-vs-syslog-from-ASA-firewalls/m-p/369761#M44661</guid>
      <dc:creator>kevinmanson</dc:creator>
      <dc:date>2018-04-27T20:42:16Z</dc:date>
    </item>
    <item>
      <title>Re: Estreamer vs syslog from ASA firewalls</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Estreamer-vs-syslog-from-ASA-firewalls/m-p/369762#M44662</link>
      <description>&lt;P&gt;Hi, kevinmanson,&lt;/P&gt;

&lt;P&gt;Is there a question here that needs answering?&lt;/P&gt;</description>
      <pubDate>Sat, 28 Apr 2018 21:54:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Estreamer-vs-syslog-from-ASA-firewalls/m-p/369762#M44662</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2018-04-28T21:54:49Z</dc:date>
    </item>
    <item>
      <title>Re: Estreamer vs syslog from ASA firewalls</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Estreamer-vs-syslog-from-ASA-firewalls/m-p/369763#M44663</link>
      <description>&lt;P&gt;Reformatted sentence into question.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Apr 2018 14:42:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Estreamer-vs-syslog-from-ASA-firewalls/m-p/369763#M44663</guid>
      <dc:creator>kevinmanson</dc:creator>
      <dc:date>2018-04-30T14:42:54Z</dc:date>
    </item>
    <item>
      <title>Re: Estreamer vs syslog from ASA firewalls</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Estreamer-vs-syslog-from-ASA-firewalls/m-p/369764#M44664</link>
      <description>&lt;P&gt;I've a table comparing syslog vs estreamer options. But not sure if I can paste that into splunk answers. Let me try finding a place I can put it or a screenshot&lt;/P&gt;</description>
      <pubDate>Mon, 30 Apr 2018 16:25:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Estreamer-vs-syslog-from-ASA-firewalls/m-p/369764#M44664</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2018-04-30T16:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: Estreamer vs syslog from ASA firewalls</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Estreamer-vs-syslog-from-ASA-firewalls/m-p/369765#M44665</link>
      <description>&lt;P&gt;Koshyk,&lt;/P&gt;

&lt;P&gt;Any luck on being able to send over that table?&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 12:54:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Estreamer-vs-syslog-from-ASA-firewalls/m-p/369765#M44665</guid>
      <dc:creator>kevinmanson</dc:creator>
      <dc:date>2018-05-01T12:54:16Z</dc:date>
    </item>
    <item>
      <title>Re: Estreamer vs syslog from ASA firewalls</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Estreamer-vs-syslog-from-ASA-firewalls/m-p/369766#M44666</link>
      <description>&lt;P&gt;Thx.  I sort of figured that was the question, but wanted to make sure.&lt;/P&gt;

&lt;P&gt;I'm not an expert, and my memory might be foggy, but IIRC the new firewalls we deployed at $job-1 we still collected both data - there were some pieces of estreamer that weren't there even though generally it's a better, higher quality data stream.  &lt;/P&gt;

&lt;P&gt;I've love to reinvestigate - as I was leaving there we were finally getting the rest of the new FW infrastructure into place, so we'd have ISE, AMP, all NGFWs and a lot of other things.  I may ping some folks back there to find out how that went, or maybe give them a hand getting it sorted out.&lt;/P&gt;</description>
      <pubDate>Tue, 01 May 2018 13:07:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Estreamer-vs-syslog-from-ASA-firewalls/m-p/369766#M44666</guid>
      <dc:creator>Richfez</dc:creator>
      <dc:date>2018-05-01T13:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: Estreamer vs syslog from ASA firewalls</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Estreamer-vs-syslog-from-ASA-firewalls/m-p/369767#M44667</link>
      <description>&lt;P&gt;hi Kevin,&lt;BR /&gt;
I've put a screenshot here. Also put into &lt;A href="https://github.com/getkub/SplunkScriplets/blob/master/notes/estreamer_vs_syslog.md"&gt;github&lt;/A&gt; with details. Please note, this is from my experience and may have changed&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/4860iB655412E0BD400FD/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 May 2018 08:30:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Estreamer-vs-syslog-from-ASA-firewalls/m-p/369767#M44667</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2018-05-02T08:30:03Z</dc:date>
    </item>
    <item>
      <title>Re: Estreamer vs syslog from ASA firewalls</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Estreamer-vs-syslog-from-ASA-firewalls/m-p/369768#M44668</link>
      <description>&lt;P&gt;i've attached below&lt;/P&gt;</description>
      <pubDate>Wed, 02 May 2018 13:17:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Estreamer-vs-syslog-from-ASA-firewalls/m-p/369768#M44668</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2018-05-02T13:17:10Z</dc:date>
    </item>
  </channel>
</rss>

