Documentation Index

Fetch the complete documentation index at: https://docs.hunters.ai/llms.txt

Use this file to discover all available pages before exploring further.

📢 Read the latest Release Notes to learn what's new on Hunters! 💡

Cisco FMC

Prev Next
Self Service Ingestion

Connect this data source on your own, using the Hunters platform.

TL;DR

Supported data types

3rd party detection

Hunters detection

IOC search

Search

Table name

Log format

Collection method

Cisco FMC Logs

✅

✅

✅

cisco_fmc_logs

TEXT

S3



Overview

Cisco Secure Firewall Management Center (FMC) is Cisco's centralized management platform for Secure Firewall deployments. It provides a single interface to configure, monitor, and manage multiple firewalls across an organization.

  • Centralizes firewall policy creation and deployment.

  • Manages security features such as Intrusion Prevention System (IPS), application control, and URL filtering.

  • Provides real-time visibility into network traffic, users, applications, and security events.

  • Collects and correlates threat intelligence to help identify and investigate security incidents.

  • Offers detailed dashboards, alerts, reports, and compliance monitoring capabilities.

  • Simplifies administration by allowing policy changes to be pushed to multiple devices from one console.

  • Supports both on-premises and virtual firewall environments.

  • Available as a physical appliance, virtual appliance, or cloud-delivered service (cdFMC).

  • Integrates with other Cisco security solutions for broader security operations.

  • Helps organizations improve security posture while reducing operational complexity.

In summary, FMC serves as the centralized command center for managing Cisco firewalls, security policies, threat detection, and network visibility at scale.

Supported data types

Cisco FMC Logs

Table name: cisco_fmc_logs

A centralized management platform for Cisco Secure Firewall deployments that provides a unified interface to configure, monitor, and manage security policies across physical and virtual environments. It streamlines administration by enabling organizations to deploy intrusion prevention, application control, and URL filtering at scale, while delivering real-time network visibility, threat intelligence Correlation, and detailed reporting to improve overall security posture and reduce operational complexity.

Send data to Hunters

Hunters supports the Ingestion of Cisco FMC logs via an intermediary AWS S3 bucket.

To connect Cisco FMC Logs:

  1. Export your logs from Cisco to an AWS S3 bucket by following this guide.

  2. Once the export is completed and the logs are collected to S3, follow the steps in this section.

Expected format

Logs are expected in TEXT format.

<155>1 2020-01-03T01:35:30+00:00 HOST-NAME-01 SF-IMS[4737]: sfmbservice[4975]: Jan 03 01:35:29  SF-IMS[4975]: [5250] sfmbservice:sfmb_service [INFO] Start getting MB messages for xx.xx.xx.xx
<142>1 2020-01-03T01:35:35+00:00 HOST-NAME-01 sftunneld[4971]: [117255] sftunneld:stream_file [INFO] File copy success : Stat for destination file /mnt/remote-storage/sf-storage/11111111-1111-1111-1111-111111111111/remote-backups/FMC_PATH-01_Primary_20203013003.tar final size is 1112233456 and total is 1112233456
<190>May 25 22:21:11 name.domain.com: [AWS_FWSF_Logs] sfdccsm: @ANBIIS:system-user@127.0.0.1, API, GET https://localhost/api/local/v1/info OK (200) - The request has succeeded