IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
Expand all | Collapse all

Collecting Cisco Firepower Management Center(v.7.0.1) events by using the eStreamer

  • 1.  Collecting Cisco Firepower Management Center(v.7.0.1) events by using the eStreamer

    Posted Wed December 07, 2022 08:15 AM
    Edited by Thomas Jaeger Wed December 07, 2022 10:11 PM
    Hello, 
    I have configured the Cisco FMC v.7.0.1 integration with QRadar by using the eStreamer. All tests successfully passed, but there are not any events from it. Although, FMC generates events and there are some in FMC. According to the documentation QRadar supports Cisco Firepower Management Center V 5.2 to V 6.4. Does it mean that QRadar will receive events from FMC 7.x  but will not parse them or it will not receive them at all?


  • 2.  RE: Collecting Cisco Firepower Management Center(v.7.0.1) events by using the eStreamer

    Posted Thu December 08, 2022 05:28 PM

    @Thomas Jaeger I looked in to this question and it support for Cisco FMC does not currently support 7.0.1 or 7.1 yet. It is something that development is currently working on and we have work items open for this to support newer FMC versions with the Cisco. There are some new data structures in 7.1 that the protocol needs to handle in updates and we are seeing errors versus what is documented in the FMC connection guide. The integration is not expected to work until there is a new protocol update that can handle the updated fields.

    Stay tuned for more info.



    ------------------------------
    Jonathan Pechta
    QRadar Support Content Lead
    Support forums: ibm.biz/qradarforums
    jonathan.pechta1@ibm.com
    ------------------------------



  • 3.  RE: Collecting Cisco Firepower Management Center(v.7.0.1) events by using the eStreamer

    Posted Thu December 08, 2022 10:10 PM
    Thanks a lot for your response!

    ------------------------------
    Thomas Jaeger
    ------------------------------