Cisco FTD data connector

DG001 346 Reputation points Microsoft Employee
2024-03-27T22:50:54.9933333+00:00

Hello,

I have a customer that is configuring the CISCO FTD data connector.

But they say CISCO FTD documentation shows it support only syslog format. 

They would like some clarification on the following questions:

I. Clarify whether Cisco FTD supports CEF?

  1. If it supports only syslog format, are there any dependencies with the CISCO FTD version? 

Currently, they are ingesting in syslog format but says the syslog format is not the same even for the same type of logs.

  • Basically wants to know if it supports the new CISCO ASA/ FTD solution-based connector and does it support the CEF format?
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
986 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Andrew Blumhardt 9,496 Reputation points Microsoft Employee
    2024-03-29T14:51:10.3466667+00:00

    There are several connectors provided by Cisco. The Cisco ASA connector covers FTD. This does appear to be CEF-based solution.
    User's image