Nov. 28, 2023, 11:26 a.m. | /u/angelopvtza

cybersecurity www.reddit.com

Hey all you SIEM and SecDevOPs Engineers.

Currently having major ingestion issues with Events logged from CISCO ASA.The problem: Even with filtering limited to Notification L5 events we accidently ingested 600M+ logs into Azure Sentinel via the CEF via AMA data-connector with the stream set to Microsoft-Ciscoasa

We need to drastically reduce the amount of logs coming in, however we're struggling to find resources/guides on best practice for event logging.

If there is a Cisco expert out there, can someone …

ama asa azure azure sentinel best practice cisco cisco asa connector cybersecurity data engineers events hey log logs major microsoft notification practice problem secdevops sentinel siem stream

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Sr. Staff Firmware Engineer – Networking & Firewall

@ Axiado | Bengaluru, India

Compliance Architect / Product Security Sr. Engineer/Expert (f/m/d)

@ SAP | Walldorf, DE, 69190

SAP Security Administrator

@ FARO Technologies | EMEA-Portugal