Skip to content

Cisco ASA

You can integrate Cisco ASA with Sophos XDR so that it sends data to Sophos for analysis.

This page gives you an overview of the integration.

Cisco ASA product overview

Cisco ASA (Adaptive Security Appliance) is a security platform that combines stateful firewall, VPN concentrator, and network threat-defense capabilities in a single device, providing site-to-site and remote-access VPN alongside advanced firewall protection for enterprise networks.

What we ingest

Sophos XDR collects Cisco ASA syslog data by listening for messages your firewall forwards to a Sophos XDR data collector. The following log categories are collected:

  • Authentication and VPN: User and VPN authentication and session activity on the firewall.
  • DNS activity: DNS requests the firewall inspects.
  • Web activity: HTTP requests inspected by the firewall.
  • DHCP activity: DHCP address-assignment events.
  • Intrusion detections: Intrusion and threat-inspection events the firewall raises.
  • Configuration and management: Firewall configuration and management events.
  • Firewall traffic[^1]: Connection build and teardown and allow/deny decisions.

Event and data types

We ingest the following event and data types from Cisco ASA:

  • Authentication and VPN: User and VPN authentication and session events, including remote-access and site-to-site VPN, with user, source address, and result. Normalized to authentication telemetry.
  • DNS activity: DNS requests inspected by the firewall, including the queried domain. Normalized to DNS query telemetry.
  • Web activity: HTTP requests inspected by the firewall, including URL and method. Normalized to HTTP telemetry.
  • DHCP activity: DHCP lease and address-assignment events. Normalized to DHCP telemetry.
  • Intrusion detections: Intrusion and threat-inspection events the firewall flags on traffic. Normalized to network intrusion detection telemetry.
  • Configuration and management: Firewall configuration and operational management events. Normalized to management event telemetry.
  • Firewall traffic[^1]: Connection build and teardown and allow, deny, and drop decisions, including source and destination addresses and ports. Normalized to netflow telemetry.

Data provided by this integration

Data provided by Cisco ASA gets normalized to the following schemas:

  • auth
  • dhcp
  • dnsquery
  • http
  • managementevent
  • netflow [^1]
  • nids

For more information about using schemas in Data Lake Search, see Schemas and logical types.

Vendor documentation

Sophos Next-Gen SIEM subscription. See Sophos Next-Gen SIEM overview.