Cisco cloud event settings
Cisco cloud event settings are firewall configurations that
-
enable devices to send firewall events to the Security Services Exchange (SSE),
-
allow external tools to investigate firewall incidents through cloud service integration, and
-
unify visibility and enhance threat investigations by forwarding events to various cloud services.
Prerequisites and integration requirements
To allow your devices to send firewall events to Cisco Security Cloud, you must either register the Firewall Management
Center with the smart license (System (
)) or enable Cisco Security Cloud integration.
Cisco Security Cloud integration associates the Firewall Management Center with your Security Cloud Control account and brings your secure firewall deployment onboard to the Cisco cloud tenancy, allowing it to connect to Cisco's integrated security cloud services.
For more information about integrating the Firewall Management Center with Cisco Security Cloud, refer to Enable Cisco Security Cloud Integration.
Security Services Exchange event consolidation parameters:
-
For identifying duplication of intrusion events, the system considers: Initiator IP, Initiator IP, SID, and GID.
-
For identifying duplication of connection events and security-related connection events, the system considers: Initiator IP, Initiator IP, and Security Intelligence Category.
-
For identifying duplication of file and malware events, all elements except Event Second are considered.
Note |
The Security Services Exchange does not display the complete list of events from the Firewall Management Center. Instead, it correlates and consolidates events, presenting only unique events. This approach reduces redundancy of events and enhances clarity. |
Enable sending events to the Cisco Security Cloud
The cloud region and event types that you configure in the Cisco Security Cloud Integration page can be used for multiple integrations when applicable and enabled.
Before you begin
-
Determine the Cisco regional cloud that you want to use for sending firewall events. While choosing a regional cloud, keep in mind that:
-
The regional cloud you select is also used for the Cisco Support Diagnostics and Cisco Support Network capabilities. This setting also governs the cloud region for the Secure Network Analytics cloud using Security Analytics and Logging (SaaS).
-
You cannot merge or aggregate data in different regional clouds. To aggregate data from multiple regions, devices in all the regions must send data to the same regional cloud.
-
-
Ensure that you register the management center with Smart License (System (
)) or enable Cisco Security Cloud integration to allow your devices to send firewall events to Cisco cloud.
Note
If you were already sending events to Cisco Security Cloud using a SecureX subscription prior to Version 7.6, you can continue to send events to Cisco Security Cloud services such as Cisco XDR. However, if you now register your management center to the cloud tenancy using your Security Cloud Control account, your Security Cloud Control account must have a Security Analytics and Logging license to forward events to Cisco Security Cloud services such as Cisco XDR.
-
In the Firewall Management Center:
-
Go to the System (
) page and give your Firewall Management Center a unique name to clearly identify it in the Devices list in the cloud.
-
Add your Firewall Threat Defense devices to the Firewall Management Center, assign licenses to them, and ensure that the system is working correctly. Ensure that you have created the necessary policies and that the generated events are displayed as expected in the Firewall Management Center UI under the Analysis menu.
-
-
Ensure that you have your Security Cloud Sign-On credentials and can sign in to the regional cloud in which your account was created.
For more information on regional cloud URLs and supported device versions, see Regional Clouds.
-
Ensure that you link your smart account or the Security Cloud Control tenant to your SSE account.
-
If you are currently sending events to the cloud using syslog, disable it to avoid duplication.
Follow these steps to enable sending events to the Cisco Security Cloud:
Procedure
|
Step 1 |
Determine the regional cloud that you want to use for sending firewall events. For more information about choosing a regional cloud, refer to Cisco Secure Firewall Threat Defense and Cisco XDR Integration Guide.
|
|||||||||||||||
|
Step 2 |
In your Firewall Management Center, choose . |
|||||||||||||||
|
Step 3 |
Choose a regional cloud from the Current Region drop-down list. |
|||||||||||||||
|
Step 4 |
Check the Send events to the cloud check box to enable the cloud event configuration. |
|||||||||||||||
|
Step 5 |
Select the event types that you want to send to the cloud.
|
|||||||||||||||
|
Step 6 |
Click Save. |
Analyze events using Cisco XDR
Cisco Extended Detection and Response (Cisco XDR) is a cloud-based solution that
-
unifies visibility by correlating detections across multiple telemetry sources,
-
enables security teams to detect, prioritize, and respond to the most sophisticated threats, and
-
integrates with Firewall Threat Defense to connect Cisco's integrated security portfolio for a consistent experience that strengthens security across network.
Cisco XDR licensing and migration information
For more information about Cisco XDR, refer to Cisco XDR Help Center.
Important |
|
To integrate Firewall Threat Defense with Cisco XDR, refer to Cisco Secure Firewall Threat Defense and Cisco XDR Integration Guide.
Note |
As of July 31, 2024, Cisco SecureX is phased out and no longer available. Cisco SecureX cannot be provisioned for users, and access to Cisco SecureX is not provided alongside Cisco Secure Firewall product purchases. Additionally, all existing Cisco SecureX environments are disabled, and all capabilities are made unavailable. If you are using Firefox, you should remove Cisco SecureX Ribbon browser extension. For more information, refer to Frequently Asked Questions. |
Analyze and Respond to Threats Using Cisco XDR Automation
Enable this setting to allow the automated workflows created by Cisco Extended Detection and Response (Cisco XDR) users to interact with your Firewall Management Center resources.
Cisco XDR automation provides a no-to-low code approach for building automated workflows. You can design your own workflows with the drag-and-drop interface, and they can be set to run in response to different schedules and events. Cisco XDR automation helps you to rectify threats using automation and guided response recommendations across all relevant control points.
Note |
Cisco XDR is a separately licensed product. It requires an additional subscription beyond the licenses for Cisco Secure Firewall products. For more information, refer to Cisco XDR Licenses. |
For more information about the Cisco XDR automation capabilities, refer to Cisco XDR documentation.
Before you begin
Enable Cisco Security Cloud and register your management center to the cloud. For more information, refer to Enable Cisco Security Cloud Integration.
Procedure
|
Step 1 |
Click . |
|
Step 2 |
Check the Enable Cisco XDR Automation checkbox. |
|
Step 3 |
Choose the Firewall Management Center user role that you want to assign to the Cisco XDR automation workflows. The Access Admin role is set as the default, allowing access to access control policy and associated functionality in the Policies menu. |
|
Step 4 |
Click Save. |





Feedback