Introduces Cisco Security Analytics and Logging Software as a Service for Adaptive Security Appliance devices and guides through implementation methods for cloud-based logging and event analysis.
This chapter covers information on how to share events from your Secure Firewall ASA and view them in Security Cloud Control.
About Security Analytics and Logging (SAL SaaS) for ASA devices
An overview of security analytics and logging (sal SaaS) for ASA, including event details, device status, reporting views, and follow-up actions.
Implement secure logging analytics (SaaS) for ASA devices
Configure Secure Logging Analytics (SaaS) for ASA devices including SEC destinations, ports, severity levels, custom event lists, and cloud event delivery.
Send ASA syslog events to the Cisco Cloud using a Security Cloud Control macro
Explains how to send ASA syslog events to the Cisco cloud using a Security Cloud Control macro, including command entry, selected devices, preview, review, and deployment results.
Requirement: send ASA syslog events to the Cisco cloud using the command line interface
Outlines the procedure to forward ASA syslog events to a Secure Event Connector (SEC) and enable logging, including limitations on supported commands and message formats.
NetFlow secure event logging (NSEL) for ASA devices
Explains NetFlow Secure Event Logging (NSEL) for ASA devices, including NSEL destinations, class maps, policy maps, macros, packet capture, and event verification.
Parsed ASA syslog events
Explains parsed ASA syslog events, including SEC destinations, ports, severity levels, custom event lists, and cloud event delivery.