Cisco Live SOC adapted Splunk ESCU detections for Cisco Secure Firewall syslog. Learn to modify macros and promote EVE events to incidents for enhanced threat visibility and response.
Adam Kilgore
Source: cisco
Source Link: https://blogs.cisco.com/security/splunk-escu-firewall-syslog/