This procedure helps you to connect your Cisco FirePower via SIEM to the Expel Workbench. The procedure is to port in logs by creating a new Syslog source, configuring that source in Workbench, then configure your Cisco FirePower via SIEM device in Workbench.

Note
Some steps in this procedure vary greatly depending upon the SIEM-based technology you use.

Quick Start

Step 1: Logging Cisco FirePower to a desired SIEM

Refer to your SIEM documentation or work with your SIEM representative to port in Cisco FirePower logs. You can also refer to the following web references for creating a new Syslog source:

Step 2: Configure the SIEM in Workbench

This link opens the Expel Help Center section for connecting SIEM-based technology to Workbench. Follow the applicable article to configure your SIEM-based tech and confirm that Cisco FirePower logs are flowing through and available.

Step 3: Configure Cisco FirePower via SIEM in Workbench

  1. In a new browser tab, go to https://workbench.expel.io/settings/security-devices.

  2. Click +Add Security Device.

  3. Find and select Cisco FirePower (via SIEM).

    Screenshot 2025-04-22 at 4.41.30 PM.png
  4. Fill in the device fields like this:

    • SIEM - select the SIEM that was onboarded in Step 2.

    • Name - enter the host name of the Cisco FirePower device.

    • Location - enter the geographic location of the device.

  5. Fill in the Connection Settings fields based on the SIEM you selected:

    • Index - enter in the SIEM index.

    • Source type - enter the Splunk source type for this device.

    • Source category - enter the Sumo Logic source category.
    • Sumologic query indices - if you are subject to Sumo Logic’s Flex pricing, you will need to provide a comma-separated list of indexes you wish Expel to query in this field. If you are on the traditional Sumo Logic pricing model, do not use this field.

      If you are not sure if this applies to you or you need more information, see Considerations for Sumo Logic Flex Pricing Customers.