Integrating Cisco ESA Email Security Appliance Logfiles - Filebeat or Elastic agent #9763
-
Hi, Had anyone integrated ESA logs into SO in the past? I there a timeline for supporting elastic agents in SO? |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
Unfortunately, it doesn't look like the Cisco module for Filebeat supports ESA logs (https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-cisco.html), but you're right, there is an Elastic Agent integration for it (https://docs.elastic.co/integrations/cisco_secure_email_gateway). Elastic Agent will be supported in the new Security Onion 2.4 -- we're planning to have a beta available for public release soon so that people can start testing use cases like this. |
Beta Was this translation helpful? Give feedback.
Unfortunately, it doesn't look like the Cisco module for Filebeat supports ESA logs (https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-cisco.html), but you're right, there is an Elastic Agent integration for it (https://docs.elastic.co/integrations/cisco_secure_email_gateway).
Elastic Agent will be supported in the new Security Onion 2.4 -- we're planning to have a beta available for public release soon so that people can start testing use cases like this.