<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What add-on for Cisco Firepower syslog (excluding estreamer)? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-add-on-for-Cisco-Firepower-syslog-excluding-estreamer/m-p/590637#M103454</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I am ingesting Cisco FTD logs and currently using the Cisco ASA add-on which works fine for a lot of event messages.&lt;/P&gt;&lt;P&gt;Unfortunately it is not working perfect as there is one event message that is not getting recognized by the add-on.&lt;/P&gt;&lt;P&gt;What Splunk supported method is the best for a standardized onboarding with full CIM knowledge?&lt;/P&gt;&lt;P&gt;I do not want to use the estreamer as it is mostly creating issues and is not Splunk supported.&lt;/P&gt;&lt;P&gt;Currently used: "Splunk_TA_cisco-asa-4.2.0"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best&amp;nbsp;&lt;/P&gt;&lt;P&gt;O.&lt;/P&gt;</description>
    <pubDate>Thu, 24 Mar 2022 10:36:52 GMT</pubDate>
    <dc:creator>ojay</dc:creator>
    <dc:date>2022-03-24T10:36:52Z</dc:date>
    <item>
      <title>What add-on for Cisco Firepower syslog (excluding estreamer)?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-add-on-for-Cisco-Firepower-syslog-excluding-estreamer/m-p/590637#M103454</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I am ingesting Cisco FTD logs and currently using the Cisco ASA add-on which works fine for a lot of event messages.&lt;/P&gt;&lt;P&gt;Unfortunately it is not working perfect as there is one event message that is not getting recognized by the add-on.&lt;/P&gt;&lt;P&gt;What Splunk supported method is the best for a standardized onboarding with full CIM knowledge?&lt;/P&gt;&lt;P&gt;I do not want to use the estreamer as it is mostly creating issues and is not Splunk supported.&lt;/P&gt;&lt;P&gt;Currently used: "Splunk_TA_cisco-asa-4.2.0"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best&amp;nbsp;&lt;/P&gt;&lt;P&gt;O.&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2022 10:36:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-add-on-for-Cisco-Firepower-syslog-excluding-estreamer/m-p/590637#M103454</guid>
      <dc:creator>ojay</dc:creator>
      <dc:date>2022-03-24T10:36:52Z</dc:date>
    </item>
  </channel>
</rss>

