Configure Cisco ASA Collector

The Alert Logic Cisco ASA collector is designed to enable Alert Logic to run our common firewall analytics on data from your Cisco ASA devices. These analytics identify suspicious communication with internet hosts which Alert Logic considers threat actors. Significant security findings from your Cisco ASA devices will result in the creation of incidents that can be managed in the Alert Logic console.

You must complete the following to send data from your Cisco ASA device(s) to Alert Logic:

  1. Download and install the remote collector
  2. Configure Cisco ASA device
  3. Verify log collection

Download and install the remote collector

To send data from your Cisco ASA device(s) to Alert Logic, you must first download and install the remote collector in the same network as the Cisco ASA device(s).

To download and install the remote collector:

  1. Review the requirements for the remote collector as outlined in Requirements for the Alert Logic Remote Collector and ensure all requirements are met.
  2. Complete the following instructions for Linux or Windows, making sure to choose a host in the same network as the Cisco ASA device(s).
  3. While installing the remote collector, note the IP of the host where the collector is installed. This IP will be needed when configuring the Cisco ASA device.

Configure Cisco ASA device

Once the remote collector is installed, the Cisco ASA device needs to be configured to send data to the collector. This process requires three key steps - creating a server profile, creating a log forwarding profile, and applying the log forwarding profile.

To configure the Cisco ASA device, enter the following commands on your Cisco ASA:

logging enable
logging host <interface_name> <remote_collector_ip> [tcp[/port] | udp[/port]] [format emblem]
logging trap 6
logging device-id <hostname or ip address>
 

Verify log collection

Once you have installed the remote collector and configured the Cisco ASA device, it is recommended to verify that log collection is successful. It may take up to 15 minutes for Alert Logic to begin receiving logs.

  1. Log in to the Alert Logic console and use one of the following links to access the Search console with criteria already entered:
  2. Uncomment either of the two commented lines with SQL parameters and replace either $COLLECTOR_ID or $COLLECTOR_IP with your preferred identifier for the remote collector.
  3. Click Search.
  4. Verify logs display for the remote collector.