The tags beginning with firewall.cisco identify log events generated by the following Cisco technologies:
- Cisco ASA
- Cisco PIX
- Cisco Firewall Services Module
The full tag must have at least three levels. The first two are fixed as firewall.cisco. The third level identifies the technology type and must be one of asa, pix, or fwsm. The fourth element is not required and you are free to define it as you like.
||free and not required|
Therefore, the valid tags include:
For more information, read more about Devo tags.
The Cisco firewall can be configured to report its logs to a remote syslog server. To configure this using Cisco's Adaptive Security Device Manager (ASDM), follow the vendor instructions.
Since there is no facility for tagging the events before sending, they should be sent to the Devo In-House Relay to apply the tag and forward them to the Devo Cloud.
Besides the syslog logs, this kind of devices usually provide the ability to export statistics of the traffic that is managed by the machine through the NetFlow protocol.