Skip to content
Discussion options

You must be logged in to vote

Unfortunately, it doesn't look like the Cisco module for Filebeat supports ESA logs (https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-cisco.html), but you're right, there is an Elastic Agent integration for it (https://docs.elastic.co/integrations/cisco_secure_email_gateway).

Elastic Agent will be supported in the new Security Onion 2.4 -- we're planning to have a beta available for public release soon so that people can start testing use cases like this.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@mnasec
Comment options

Answer selected by cm-ops
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants