All Apps and Add-ons

Estreamer vs syslog from ASA firewalls

kevinmanson
Explorer

Do Cisco ASA NGFWs aka X-series and firepower series sending logs to FMC and collecting via estreamer provide equal or greater logging within Splunk over syslog from the ASA?

Meaning everything event visible in syslog can be seen in the estreamer feed in some way.

One of the other concerning issues is the size of the events syslog is 200bytes/event while estreamer is 2000bytes for connection events.

0 Karma

koshyk
Super Champion

hi Kevin,
I've put a screenshot here. Also put into github with details. Please note, this is from my experience and may have changed

alt text

0 Karma

koshyk
Super Champion

I've a table comparing syslog vs estreamer options. But not sure if I can paste that into splunk answers. Let me try finding a place I can put it or a screenshot

0 Karma

kevinmanson
Explorer

Koshyk,

Any luck on being able to send over that table?

0 Karma

koshyk
Super Champion

i've attached below

0 Karma

Richfez
SplunkTrust
SplunkTrust

Hi, kevinmanson,

Is there a question here that needs answering?

kevinmanson
Explorer

Reformatted sentence into question.

0 Karma

Richfez
SplunkTrust
SplunkTrust

Thx. I sort of figured that was the question, but wanted to make sure.

I'm not an expert, and my memory might be foggy, but IIRC the new firewalls we deployed at $job-1 we still collected both data - there were some pieces of estreamer that weren't there even though generally it's a better, higher quality data stream.

I've love to reinvestigate - as I was leaving there we were finally getting the rest of the new FW infrastructure into place, so we'd have ISE, AMP, all NGFWs and a lot of other things. I may ping some folks back there to find out how that went, or maybe give them a hand getting it sorted out.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...