FortiSIEM
FortiSIEM provides Security Information and Event Management (SIEM) and User and Entity Behavior Analytics (UEBA)
Andy_G
Staff
Staff
Article Id 189869

Description

 

This article describes a configured netflow on the Cisco ASA to send to AO but it is impossible to find the events in AO.  

 

Solution

 

Summary of Topic.

This can happen if the NetFlow template is not sent frequently enough to the 'collector', which in this case is AccelOps.  If AO does not know how to parse the NetFlow events, which requires the NetFlow template, then AO discards the events.

 

Often it is possible to resolve this problem by increasing the frequency of sending the Netflow template.

The command to run on your Cisco ASA to increase the frequency is:

 

flow-export template timeout-rate 1

 

Additional Resources:

Netflow on ASA

  

Version application:

All.