How Firewall Threat Defense events are displayed in Security Cloud Control using a direct connection
This process describes how Firewall Threat Defense devices that are managed by Security Cloud Control shares security events (connection, security-related connection, intrusion, file, and malware events) with Security Cloud Control.
Summary
The key components involved in displaying Firewall Threat Defense events in Security Cloud Control are:
-
Firewall Threat Defense device: Generates and sends security events directly to Cisco cloud when logging is enabled
-
Security Services Exchange: Aggregates event data, converts it to JSON format, and forwards it for storage
-
Security Analytics and Logging: Processes and enriches event data using various classification services
-
Security Cloud Control: Queries stored data to provide SOC analysts with relevant information
Workflow
The process involves these stages:
- You configure the Firewall Threat Defense device to send security events directly to Cisco cloud. Security events are generated when logging is enabled on the Firewall Threat Defense device, and network traffic matches access control rule criteria. The Firewall Threat Defense device sends the events directly to Security Services Exchange.
- Security Services Exchange aggregates the event data from all the Firewall Threat Defense devices, converts it to JSON format, and sends it to Security Analytics and Logging for storage.
- Security Analytics and Logging process the event data using various services to classify and enrich it for use by the Security Cloud Control.
- Security Analytics and Logging stores the event data in the cloud data store. Security Cloud Control queries the stored data to provide SOC analysts with the relevant information.