Cisco FTD data connector

DG001 446 Reputation points Microsoft Employee
2024-03-27T22:50:54.9933333+00:00

Hello,

I have a customer that is configuring the CISCO FTD data connector.

But they say CISCO FTD documentation shows it support only syslog format. 

They would like some clarification on the following questions:

I. Clarify whether Cisco FTD supports CEF?

  1. If it supports only syslog format, are there any dependencies with the CISCO FTD version? 

Currently, they are ingesting in syslog format but says the syslog format is not the same even for the same type of logs.

  • Basically wants to know if it supports the new CISCO ASA/ FTD solution-based connector and does it support the CEF format?
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,182 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Andrew Blumhardt 9,866 Reputation points Microsoft Employee
    2024-03-29T14:51:10.3466667+00:00

    There are several connectors provided by Cisco. The Cisco ASA connector covers FTD. This does appear to be CEF-based solution.
    User's image


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.