...
Source port → 13007
Source data → %FTD-
Target tag →
firewall.cisco.ftd
Select the Stop processing and Sent without syslog tag checkboxes
...
Source port → 13007
Source data → FMC
Target tag →
firewall.cisco.fmc
Select the Stop processing and Sent without syslog tag checkboxes
...
Source port → 13007
Source data → %FWSM-
Target tag →
firewall.cisco.fwsm
Select the Stop processing and Sent without syslog tag checkboxes
...
Source port → 13007
Source data → %PIX-
Target tag →
firewall.cisco.pix
Select the Stop processing and Sent without syslog tag checkboxes
...
Source port → 13007
Source data → ASA-[0-9]+-(?:722010|722036|113039|716059|722012|716058|716002|722033|722034|722037|722023|722028|722032|722051|722055|722022|722041)
Target tag →
vpn.cisco.asa.anyconnect
Select the Stop processing and Sent without syslog tag checkboxes
...
All events received on this port that did not match any of the previous rules will be assigned the firewall.cisco.asa
tag.
Source port → 13007
Target tag →
firewall.cisco.asa
Select the Stop processing and Sent without syslog tag checkboxes
...
This technology uses a single tag to support all the Firepower Management Center events. The tag is simply firewall.cisco.fmc_estreamer
and the associated events are saved in Devo in a table of the same name.
...
Source port → 13011
Target tag →
firewall.cisco.fmc_estreamer
Select the Stop processing checkbox
...