Connect this data source on your own, using the Hunters platform.
TL;DR
Supported data types | 3rd party detection | Hunters detection | IOC search | Search | Table name | Log format | Collection method |
|---|---|---|---|---|---|---|---|
Cisco FMC Logs | ✅ | ✅ | ✅ | cisco_fmc_logs | TEXT | S3 |
Overview
Cisco Secure Firewall Management Center (FMC) is Cisco's centralized management platform for Secure Firewall deployments. It provides a single interface to configure, monitor, and manage multiple firewalls across an organization.
Centralizes firewall policy creation and deployment.
Manages security features such as Intrusion Prevention System (IPS), application control, and URL filtering.
Provides real-time visibility into network traffic, users, applications, and security events.
Collects and correlates threat intelligence to help identify and investigate security incidents.
Offers detailed dashboards, alerts, reports, and compliance monitoring capabilities.
Simplifies administration by allowing policy changes to be pushed to multiple devices from one console.
Supports both on-premises and virtual firewall environments.
Available as a physical appliance, virtual appliance, or cloud-delivered service (cdFMC).
Integrates with other Cisco security solutions for broader security operations.
Helps organizations improve security posture while reducing operational complexity.
In summary, FMC serves as the centralized command center for managing Cisco firewalls, security policies, threat detection, and network visibility at scale.
Supported data types
Cisco FMC Logs
Table name: cisco_fmc_logs
A centralized management platform for Cisco Secure Firewall deployments that provides a unified interface to configure, monitor, and manage security policies across physical and virtual environments. It streamlines administration by enabling organizations to deploy intrusion prevention, application control, and URL filtering at scale, while delivering real-time network visibility, threat intelligence Correlation, and detailed reporting to improve overall security posture and reduce operational complexity.
Send data to Hunters
Hunters supports the Ingestion of Cisco FMC logs via an intermediary AWS S3 bucket.
To connect Cisco FMC Logs:
Export your logs from Cisco to an AWS S3 bucket by following this guide.
Once the export is completed and the logs are collected to S3, follow the steps in this section.
Expected format
Logs are expected in TEXT format.
<155>1 2020-01-03T01:35:30+00:00 HOST-NAME-01 SF-IMS[4737]: sfmbservice[4975]: Jan 03 01:35:29 SF-IMS[4975]: [5250] sfmbservice:sfmb_service [INFO] Start getting MB messages for xx.xx.xx.xx
<142>1 2020-01-03T01:35:35+00:00 HOST-NAME-01 sftunneld[4971]: [117255] sftunneld:stream_file [INFO] File copy success : Stat for destination file /mnt/remote-storage/sf-storage/11111111-1111-1111-1111-111111111111/remote-backups/FMC_PATH-01_Primary_20203013003.tar final size is 1112233456 and total is 1112233456
<190>May 25 22:21:11 name.domain.com: [AWS_FWSF_Logs] sfdccsm: @ANBIIS:system-user@127.0.0.1, API, GET https://localhost/api/local/v1/info OK (200) - The request has succeeded