Hi all and happy new year!
I'm playing around with my network logs and was puzzled to find we don't have any
Hi all and happy new year!
I'm playing around with my network logs and was puzzled to find we don't have any
Best answer by Rene_Figueroa
I should have said - I was looking at NETWORK_CONNECTION, NETWORK_DNS like you said and I was wondering why I didn't see any NETWORK_FLOW or netflow logs .
In this context I'm understanding netflow logs as logs from routers, devices, the network fabric within my external firewalls.
This is prolly a simple matter that we're not onboarding device logs in the manner I want to yet.
Hi @Chris_B, correct. Different parsers do different mapping according to the logs that come in. Internally, I can see parsers such as CISCO_ISE, CISCO_VPN, CISCO_MERAKI and a few others create UDM events of NETWORK_FLOW type.
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.