Idea ID 2809536
Older version of Cisco FTD were having same log format as ASA. So those logs were parsed by 'Syslog Daemon' Connector though ASA parsers. Now after version 6.3 FTD started to change ASA to FTD in the syslog messages. This just stopped parsing of FTD logs in ArcSight. A simple | pipe in ASA parser to have FTD or ASA, should solve this cocern.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.