In this video, we’re going to configure our FTD device to send syslog data to Splunk. The reason this is important is that the Lina-level syslog will give us information about NAT sessions, stateful information, VPN, etc. This data can be used in multiple dashboards and apps in Splunk
Configuring the Cisco Network App in Splunk
Configuring the Cisco eStreamer eNcore Add-on for Splunk and Firepower
In this video, we’ll be configuring the Cisco eStreamer eNcore app that allows Splunk to ingest data from Cisco Firepower Management Center. My previous blog post on this subject was based on the previous app. This video should be followed instead of the previous blog post since the new app makes it much easier.