5 Replies Latest reply on Dec 20, 2016 2:07 PM by sssyyy

    Setting up an alert for logs coming from a CISCO FW for a traffic combination.

    kenn1

      Is it possible to set up an alert for logs coming from a cisco FW to sees the following traffic combination in logging line:

       

       

      %ASA-6-302013: xxx.73.xxx.64 255.255.255.224 to xx.187.x.194 (Built TCP connection)

      %ASA-6-302014: xxx73.xxx.64 255.255.255.224 to xx.187.x.194 (Teardown TCP connection)

      %ASA-6-302013: xxx73.xxx.64.255.255.255.224 to xx.187.xx195 (Built TCP connection)

      %ASA-6-302014: xxx.73.xxx.64 255.255.255.224 to xx.187.x.195 (Teardown TCP connection)

      %ASA-6-302013: 1xx.x1x.39.0 255.255.255.224 to xx.187.x.194 (Built TCP connection)

      %ASA-6-302014: xxx.18xx.39.0 255.255.255.224 to xx.187.x.194 (Teardown TCP connection)

      %ASA-6-302013: xxx,x.39.0 255.255.255.224  to xx187.x.195 (Built TCP connection)

      %ASA-6-302014: 1xx.xxx.3.xx 255.255.255.224 to xxx.187.x.195 (Teardown TCP connection)