Cisco Asa connector the oms agent is not receiving cef logs.

Georges Hayek 46 Reputation points
2023-05-09T12:28:10.0266667+00:00

Dears,

I am trying to integrate the cisco asa connector to get the logs into sentinel. when I ran the troubleshooring script I am getting that the agent is not able to locate CEF logs. Moreover, I am receiving syslog.

I tried to enable logs in cef format in cisco asa. However, this option is not feasible.

can anyone help with the above?

thanks,

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,179 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Georges Hayek 46 Reputation points
    2023-05-22T13:17:29.9666667+00:00

    Hello,

    yes of course I took a look to the documentation, there are only three steps that I did them for multiple times.

    Regards,

    0 comments No comments

  2. Georges Hayek 46 Reputation points
    2023-05-22T13:21:11.07+00:00

    Is there a place to find other instructions. The agent is receiving the logs. However, it is not saving in the rsyslog.log folder and am still getting that the agent is not CEF logs.

    can anyone please help me with the above?

    Regards,

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.