Cisco FTD
Connect Cisco FTD to Radiant Security to forward firewall and intrusion event syslog for AI triage.
Cisco FTD forwards syslog to Radiant Security through the Radiant Agent. This guide covers adding the Cisco FTD data feed in Radiant, deploying the Radiant Agent as the syslog receiver, and configuring syslog forwarding from the Cisco FDM UI.
Prerequisites
Add the data connector in Radiant Security
Log in to Radiant Security.
From the navigation menu, click Settings > Data Connectors, then click + Add Connector.
Search for and select Radiant Agent, then click Data Feeds.
Under Select your data feeds, select Cisco FTD (syslog), then click Credentials.
Under Credential Name, enter an identifiable name for the Radiant Agent integration (e.g.,
Radiant Agent integration). To reuse an existing Radiant Agent credential, select it from the drop-down menu.Click Add Connector.
Configure Cisco FTD to forward syslog
Before starting, confirm the IP address of the Radiant Agent and the port configured to receive Cisco FTD data. If you do not know the port, contact your Customer Success representative.
Log in to the Cisco FDM UI with a config user.
From the top navigation bar, select the Cisco FTD device.
Under System Settings, select Logging Settings.
Enable Data Logging.
Under Message Filtering for Firepower Threat Defense, set Severity level for filtering all events to Information.

Under Syslog Servers, click the + button to add a new syslog server.
Click Create new Syslog Server.
Enter the IP address of the Radiant Agent.
For Protocol Type, select TCP.
For Port Number, enter the port configured on the Radiant Agent to receive Cisco FTD data.
Under Interface for Device Logs, select an interface with connectivity to the Radiant Agent.
Click OK, then select the newly created syslog server.
Click SAVE.

Click the deploy button to deploy the changes.

Verify ingestion
After Cisco FTD begins forwarding, confirm alerts and events are reaching Radiant.
In Radiant, navigate to Log Management.
Filter by
rs_connectorType:"cisco_firepower".Confirm recent alerts and events appear.
Allow several minutes for alerts and events to be parsed, indexed, and available for search.
Last updated
Was this helpful?