Cisco
StandardCisco allows you to monitor and identify threats to your organization using Cisco data. Logpoint aggregates and normalizes the Cisco logs so you can analyze the information through dashboards. Cisco dashboards visualize event details for network, user authentication, intrusion prevention systems, email security, VPN, endpoint security, wireless and other Cisco collaboration solutions.
Key Information
- When configuring the normalization policy, place specific normalization packages at the top of the policy, followed by generic normalization packages to prevent normalization issues. For example, while selecting a normalization package for Cisco PIXASA, select LP_Cisco PIXASA first and then select LP_Cisco_PIXASA_Generic, preserving their order.
- Activate the label packages to apply labels and group similar logs together. To learn how to activate the label package, go to Activating Labels Packages.
- The EmailParser should be configured in the device for using CiscoIronPortESGCompiledNormalizer.
Enhancement
PLUG - 16750, SR - 48990491
Cisco now includes CiscoIOSXECompiledNormalizer which normalizes some additional fields of Cisco Switch Logs.
Bug Fixes
PLUG-13274, PLUG-13244, PLUG-1618686208, 86076, 77731
Some Cisco Firepower logs were not normalized by CiscoFirepowerNormalizer
PLUG-1612878476
The firewall’s hostname was not extracted by the Cisco normalizers.
Past Releases
Cisco v5.6.0 ▾
Bug Fixes
PLUG-13274, PLUG-13244, PLUG-1618686208, 86076, 77731
Some Cisco Firepower logs were not normalized by CiscoFirepowerNormalizer
PLUG-1612878476
The firewall’s hostname was not extracted by the Cisco normalizers.
Cisco v5.5.0 ▾
Enhancement
PLUG-1199984859
For Cisco Identity Services Engine (ISE), the authentication and status fields were not normalized.
Cisco v5.4.0 ▾
Enhancement
KB-22622
Added Syslog Collector based Cisco and CiscoEmail log source templates, simplifying the log source configuration process. To learn more, go to Creating Log Source via a Template .
Support
If you have any questions or require assistance, create a support ticket.
Comments
Article is closed for comments.
Hi,
It says LogPoint v5.2 and later for Version 3.4.1.
But when I try to add it to logpoint version 6.5.3 it says, " only supported on 6.6.x".
Do you have one for version 6.x.x yet?
Best regards
Henrik Olsson