MicrosoftDocs / azure-docs

Open source documentation of Microsoft Azure
https://docs.microsoft.com/azure
Creative Commons Attribution 4.0 International
10.23k stars 21.39k forks source link

CEF and Cisco ASA logs are no longer part of the same pipeline #120834

Closed susalgado closed 2 months ago

susalgado commented 6 months ago

Hi team,

In regard to point 2:

"Forward Cisco ASA logs to Syslog agent" "Configure Cisco ASA to forward Syslog messages in CEF format to your Microsoft Sentinel workspace via the Syslog agent."

While CEF (Common Event Format) is a log format used by many different security devices, including some Cisco devices, it's important to note that the Cisco ASA device does not use CEF for logging. Instead, it uses the Cisco ASA format. In the past, the Azure Log Analytics service (which is now part of Azure Monitor) used to collect both CEF and Cisco ASA logs through the same pipeline. This meant that both types of logs were processed and analyzed together in the same workspace. However, CEF and Cisco ASA logs are no longer part of the same pipeline.

Thank you, Kind regards Susana


Document Details

Do not edit this section. It is required for learn.microsoft.com ➟ GitHub issue linking.

ManoharLakkoju-MSFT commented 6 months ago

@susalgado Thanks for your feedback! We will investigate and update as appropriate.

ManoharLakkoju-MSFT commented 6 months ago

@susalgado Thank you for bringing this to our attention. I've delegated this to content author @cwatson-cat, who will review it and offer their insightful opinions.

batamig commented 6 months ago

Thank you for your comment! We'll investigate and get back to you.

label:"backlog-item-created"

batamig commented 2 months ago

label:"automated-data-connectors"

cwatson-cat commented 2 months ago

The referenced content is autogenerated content from the public repo: https://github.com/Azure/Azure-Sentinel/tree/master/Solutions/CiscoASA. Looks like it's since been updated. #please-close