This procedure helps you to connect your Cisco ASA via SIEM to the Expel Workbench. The procedure is to port in logs by creating a new Syslog source, configuring that source in Workbench, then your Cisco ASA through SIEM device in Workbench.

Note
Some steps in this procedure vary greatly depending upon the SIEM-based technology you use.

Quick Start

Step 1: Logging Cisco ASA to a desired SIEM

Refer to your SIEM documentation or work with your SIEM representative to port in Cisco ASA logs. You can also refer to the following web references for creating a new Syslog source:

Step 2: Configure the SIEM in Workbench

This link opens the Expel Knowledge Base section for connecting SIEM-based technology to Workbench. Follow the applicable article to configure your SIEM-based tech and confirm that Cisco ASA logs are flowing through and available.

Step 3: Configure Cisco ASA via SIEM in Workbench

  1. In a new browser tab, go to https://workbench.expel.io/settings/security-devices?setupIntegration=cisco_asa.

    Add Cisco ASA via SIEM security device
  2. Fill in the device fields like this:

    • For SIEM, select the SIEM that was onboarded in Step 2.

    • For Name, type the host name of the Cisco ASA device.

    • For Location, type the geographic location of the device.

  3. Fill in the Connection Settings fields based on the SIEM you selected:

    • For Source type, type the Splunk source type for this device.

    • For Source category, type the Sumo Logic source category for this device.

    • For Index, type in the Splunk index where the logs are located. By default this is filled in with a wildcard (*).