The Security Management Appliance (SMA) is used to centralize services from Email Security Appliances (ESAs) and Web Security Appliances (WSAs).
Integration:
The Cisco Security Management Appliance (SMA) is used to centralize services from Email Security Appliances (ESAs).
What does this pack do?
- Retrieve spam quarantined messages.
- Release and delete messages from spam quarantine.
- Retrieve, add, append, edit, or delete a list entry - blocklist and safelist of spam quarantine.
- Centralized tracking messages.
- Retrieve tracking messages enrichment summaries - AMP, DLP, URL.
- Centralized Reporting - get Cisco SMA's statistics reports.
- Fetch quarantine messages as incidents.
Syslog Collection
Follow the below step to collect Cisco SMA logs via syslog.
Data normalization capabilities:
- Rules for parsing and modeling on Cortex XSIAM.
- The ingested Cisco SMA logs can be queried in XQL Search using the
Cisco_SMA_raw
dataset.
Configuration on Server Side
Please follow the steps described here
Note:
The logs will receive the correct timezone only when the UTC timezone is set.
This pack contains an integration, whose main purpose is to centralize services from Cisco Email Security Appliances (ESAs) in Cisco Security Management Appliance services.
Broker VM
You will need to use the information described here.\
You can configure the specific vendor and product for this instance.
- Navigate to Settings -> Configuration -> Data Broker -> Broker VMs.
- Right-click, and select Syslog Collector -> Configure.
- When configuring the Syslog Collector, set:
- vendor as -> Cisco
- product as -> SMA
Integration:
The Cisco Security Management Appliance (SMA) is used to centralize services from Email Security Appliances (ESAs).
What does this pack do?
- Retrieve spam quarantined messages.
- Release and delete messages from spam quarantine.
- Retrieve, add, append, edit, or delete a list entry - blocklist and safelist of spam quarantine.
- Centralized tracking messages.
- Retrieve tracking messages enrichment summaries - AMP, DLP, URL.
- Centralized Reporting - get Cisco SMA's statistics reports.
- Fetch quarantine messages as incidents.
Syslog Collection
Follow the below step to collect Cisco SMA logs via syslog.
Data normalization capabilities:
- Rules for parsing and modeling on Cortex XSIAM.
- The ingested Cisco SMA logs can be queried in XQL Search using the
Cisco_SMA_raw
dataset.
Configuration on Server Side
Please follow the steps described here
Note:
The logs will receive the correct timezone only when the UTC timezone is set.
This pack contains an integration, whose main purpose is to centralize services from Cisco Email Security Appliances (ESAs) in Cisco Security Management Appliance services.
Broker VM
You will need to use the information described here.\
You can configure the specific vendor and product for this instance.
- Navigate to Settings -> Configuration -> Data Broker -> Broker VMs.
- Right-click, and select Syslog Collector -> Configure.
- When configuring the Syslog Collector, set:
- vendor as -> Cisco
- product as -> SMA