CiscoSMA (v1.1.45)

The Security Management Appliance (SMA) is used to centralize services from Email Security Appliances (ESAs) and Web Security Appliances (WSAs).

Author
Cortex XSOAR
Support
xsoar
URL
https://www.paloaltonetworks.com/cortex
Categories
Email

Incident fields (1)

Integrations (1)

Layouts (1)

Modeling rules (1)

Parsing rules (1)

README

Integration

The Cisco Security Management Appliance (SMA) is used to centralize services from Email Security Appliances (ESAs).

What does this pack do?

Syslog Collection

Follow the below step to collect Cisco SMA logs via syslog.

Data normalization capabilities:

Configuration on Server Side

Please follow the steps described here

Note:
The logs will receive the correct timezone only when the UTC timezone is set.

This pack contains an integration, whose main purpose is to centralize services from Cisco Email Security Appliances (ESAs) in Cisco Security Management Appliance services.

Broker VM

You will need to use the information described here.\
You can configure the specific vendor and product for this instance.

  1. Navigate to Settings -> Configuration -> Data Broker -> Broker VMs.
  2. Right-click, and select Syslog Collector -> Configure.
  3. When configuring the Syslog Collector, set:
    • vendor as -> Cisco
    • product as -> SMA