- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
Watch HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
We currently have Cisco ASA's as VPN Concentrators and have syslogging to a CP IDA Collector to populate the identities for access rules on our CP firewalls.
We are migrating from the Cisco ASA's to Cisco FTD's and are having issues. We've verified the IPs and verified the traffic is getting allowed to the IDA Collector but it doesn't look like the CP IDA Collector is parsing out any identities from the Cisco FTD's syslogs. When migrating to the Cisco FTD's we are using the same syslog events as was configured and working on the ASA's as well.
In CP IDA there is only the option for Cisco ASA 9.1 on the syslog options and not anything for the FTD but I'd be surprised if there are differences in the format as you can still get to the ASA CLI under the hood of the FTD code.
I'm only assuming that we aren't the only ones to do this as the FTD's have been out there for a good bit.
Has anyone else got experience with this setup?
Ended up creating a custom syslog parser. Here are the settings:
Parser Name : "Cisco FTD (7.6)"
Message Subject : "<148>"
Event Type : "Login"
Delimiter : ">"
Username Prefix : " User <"
Username : "([^>]*)"
Address Prefix : " IPv4 Address <"
Address : "(\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})"
No one using IDA Collectors with Cisco FTDs?
Have you tried creating a new Syslog Parser for the FTD?
That would certainly be my last resort. No, we have not gone down that road yet. We were hoping this was something someone had already overcame and we just had a setting wrong or something. I can't see anything wrong except for, like you were saying, maybe we need a custom parser for this.
Ended up creating a custom syslog parser. Here are the settings:
Parser Name : "Cisco FTD (7.6)"
Message Subject : "<148>"
Event Type : "Login"
Delimiter : ">"
Username Prefix : " User <"
Username : "([^>]*)"
Address Prefix : " IPv4 Address <"
Address : "(\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})"
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 14 | |
| 9 | |
| 7 | |
| 7 | |
| 7 | |
| 5 | |
| 4 | |
| 3 | |
| 3 | |
| 3 |
Thu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealThu 09 Jul 2026 @ 11:00 AM (CEST)
The Cloud Architects Series: Check Point Edge Protection SD-WAN & SASETue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeTue 14 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E11: READY OR NOT: Securing the AI Enterprise 3/5 - AI Workforce SecurityThu 30 Jul 2026 @ 10:00 AM (PDT)
AI Security Masters E12: READY OR NOT: Securing the AI Enterprise 4/5 - AI GatewayThu 20 Aug 2026 @ 10:00 AM (PDT)
AI Security Masters E13: READY OR NOT: Securing the AI Ent 5/5 - AI Research & Threat LandscapeThu 02 Jul 2026 @ 06:00 PM (CST)
Revolucionando la Seguridad con IA Generativa: Prevención Inteligente en Tiempo RealAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY