<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using Identity Awareness Collector with Cisco FTD Syslogging in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Using-Identity-Awareness-Collector-with-Cisco-FTD-Syslogging/m-p/258342#M43602</link>
    <description>&lt;P&gt;Ended up creating a custom syslog parser. Here are the settings:&lt;/P&gt;&lt;P&gt;Parser Name : "Cisco FTD (7.6)"&lt;BR /&gt;Message Subject : "&amp;lt;148&amp;gt;"&lt;BR /&gt;Event Type : "Login"&lt;BR /&gt;Delimiter : "&amp;gt;"&lt;BR /&gt;Username Prefix : " User &amp;lt;"&lt;BR /&gt;Username : "([^&amp;gt;]*)"&lt;BR /&gt;Address Prefix : " IPv4 Address &amp;lt;"&lt;BR /&gt;Address : "(\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})"&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Picture1adfas.png" style="width: 487px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31549i378B07065FE18BCD/image-size/large?v=v2&amp;amp;px=999" role="button" title="Picture1adfas.png" alt="Picture1adfas.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 26 Sep 2025 20:23:48 GMT</pubDate>
    <dc:creator>Heath</dc:creator>
    <dc:date>2025-09-26T20:23:48Z</dc:date>
    <item>
      <title>Using Identity Awareness Collector with Cisco FTD Syslogging</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Using-Identity-Awareness-Collector-with-Cisco-FTD-Syslogging/m-p/257656#M43443</link>
      <description>&lt;P&gt;We currently have Cisco ASA's as VPN Concentrators and have syslogging to a CP IDA Collector to populate the identities for access rules on our CP firewalls.&lt;/P&gt;&lt;P&gt;We are migrating from the Cisco ASA's to Cisco FTD's and are having issues. We've verified the IPs and verified the traffic is getting allowed to the IDA Collector but it doesn't look like the CP IDA Collector is parsing out any identities from the Cisco FTD's syslogs. When migrating to the Cisco FTD's we are using the same syslog events as was configured and working on the ASA's as well.&lt;/P&gt;&lt;P&gt;In CP IDA there is only the option for Cisco ASA 9.1 on the syslog options and not anything for the FTD but I'd be surprised if there are differences in the format as you can still get to the ASA CLI under the hood of the FTD code.&lt;/P&gt;&lt;P&gt;I'm only assuming that we aren't the only ones to do this as the FTD's have been out there for a good bit.&lt;/P&gt;&lt;P&gt;Has anyone else got experience with this setup?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 18:04:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Using-Identity-Awareness-Collector-with-Cisco-FTD-Syslogging/m-p/257656#M43443</guid>
      <dc:creator>Heath</dc:creator>
      <dc:date>2025-09-18T18:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: Using Identity Awareness Collector with Cisco FTD Syslogging</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Using-Identity-Awareness-Collector-with-Cisco-FTD-Syslogging/m-p/257672#M43447</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-09-18 165601.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31495i4249501B3B0AC293/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2025-09-18 165601.png" alt="Screenshot 2025-09-18 165601.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 21:56:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Using-Identity-Awareness-Collector-with-Cisco-FTD-Syslogging/m-p/257672#M43447</guid>
      <dc:creator>Heath</dc:creator>
      <dc:date>2025-09-18T21:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: Using Identity Awareness Collector with Cisco FTD Syslogging</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Using-Identity-Awareness-Collector-with-Cisco-FTD-Syslogging/m-p/257937#M43495</link>
      <description>&lt;P&gt;No one using IDA Collectors with Cisco FTDs?&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2025 17:42:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Using-Identity-Awareness-Collector-with-Cisco-FTD-Syslogging/m-p/257937#M43495</guid>
      <dc:creator>Heath</dc:creator>
      <dc:date>2025-09-22T17:42:57Z</dc:date>
    </item>
    <item>
      <title>Re: Using Identity Awareness Collector with Cisco FTD Syslogging</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Using-Identity-Awareness-Collector-with-Cisco-FTD-Syslogging/m-p/257949#M43498</link>
      <description>&lt;P&gt;Have you tried creating a new Syslog Parser for the FTD?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CPIDC_SysLog.png" style="width: 412px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31510i6C7E6A03AC4B8C83/image-size/large?v=v2&amp;amp;px=999" role="button" title="CPIDC_SysLog.png" alt="CPIDC_SysLog.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CPIDC_SysLog2.png" style="width: 555px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31511iC1CC4C019C9F33DF/image-size/large?v=v2&amp;amp;px=999" role="button" title="CPIDC_SysLog2.png" alt="CPIDC_SysLog2.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2025 20:09:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Using-Identity-Awareness-Collector-with-Cisco-FTD-Syslogging/m-p/257949#M43498</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2025-09-22T20:09:20Z</dc:date>
    </item>
    <item>
      <title>Re: Using Identity Awareness Collector with Cisco FTD Syslogging</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Using-Identity-Awareness-Collector-with-Cisco-FTD-Syslogging/m-p/257950#M43499</link>
      <description>&lt;P&gt;That would certainly be my last resort. No, we have not gone down that road yet. We were hoping this was something someone had already overcame and we just had a setting wrong or something. I can't see anything wrong except for, like you were saying, maybe we need a custom parser for this.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Sep 2025 20:11:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Using-Identity-Awareness-Collector-with-Cisco-FTD-Syslogging/m-p/257950#M43499</guid>
      <dc:creator>Heath</dc:creator>
      <dc:date>2025-09-22T20:11:47Z</dc:date>
    </item>
    <item>
      <title>Re: Using Identity Awareness Collector with Cisco FTD Syslogging</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Using-Identity-Awareness-Collector-with-Cisco-FTD-Syslogging/m-p/258342#M43602</link>
      <description>&lt;P&gt;Ended up creating a custom syslog parser. Here are the settings:&lt;/P&gt;&lt;P&gt;Parser Name : "Cisco FTD (7.6)"&lt;BR /&gt;Message Subject : "&amp;lt;148&amp;gt;"&lt;BR /&gt;Event Type : "Login"&lt;BR /&gt;Delimiter : "&amp;gt;"&lt;BR /&gt;Username Prefix : " User &amp;lt;"&lt;BR /&gt;Username : "([^&amp;gt;]*)"&lt;BR /&gt;Address Prefix : " IPv4 Address &amp;lt;"&lt;BR /&gt;Address : "(\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})"&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Picture1adfas.png" style="width: 487px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/31549i378B07065FE18BCD/image-size/large?v=v2&amp;amp;px=999" role="button" title="Picture1adfas.png" alt="Picture1adfas.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Sep 2025 20:23:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Using-Identity-Awareness-Collector-with-Cisco-FTD-Syslogging/m-p/258342#M43602</guid>
      <dc:creator>Heath</dc:creator>
      <dc:date>2025-09-26T20:23:48Z</dc:date>
    </item>
  </channel>
</rss>

