{
  "Name": "CiscoASA",
  "Author": "Microsoft - support@microsoft.com",
  "Logo": "<img src=\"https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Logos/cisco-logo-72px.svg\" width=\"75px\" height=\"75px\">",
  "Description": "The [Cisco ASA](https://www.cisco.com/c/en_in/products/security/adaptive-security-appliance-asa-software/index.html) solution for Microsoft Sentinel enables you to ingest [Cisco ASA logs](https://www.cisco.com/c/en/us/td/docs/security/asa/syslog/b_syslog/messages-listed-by-severity-level.html) into Microsoft Sentinel. \n\r\n**Cisco ASA/FTD via AMA** - This data connector helps in ingesting Cisco ASA logs into your Log Analytics Workspace using the new Azure Monitor Agent. Learn more about ingesting using the new Azure Monitor Agent [here](https://learn.microsoft.com/azure/sentinel/connect-cef-ama). \r\n\n</p>\n\n**Underlying Microsoft Technologies used:**\n\nThis solution takes a dependency on the following technologies, and some of these dependencies either may be in [Preview](https://azure.microsoft.com/support/legal/preview-supplemental-terms/) state or might result in additional ingestion or operational costs:\n\n a. [Agent-based log collection (Syslog)](https://docs.microsoft.com/azure/sentinel/connect-syslog)",
  "Workbooks": [
    "Solutions/CiscoASA/Workbooks/Cisco.json"
  ],
  "Data Connectors": [
    "Solutions/CiscoASA/Data Connectors/template_CiscoAsaAma.json"
  ],
  "Playbooks": [
    "Solutions/CiscoASA/Playbooks/CiscoASAConnector/azuredeploy.json",
    "Solutions/CiscoASA/Playbooks/CiscoASA-AddIPtoNetworkObjectGroup/azuredeploy.json",
    "Solutions/CiscoASA/Playbooks/CiscoASA-CreateACEInACL/azuredeploy.json",
    "Solutions/CiscoASA/Playbooks/CiscoASA-CreateInboundAccessRuleOnInterface/azuredeploy.json"
  ],
  "Analytic Rules": [
    "Solutions/CiscoASA/Analytic Rules/CiscoASA-ThreatDetectionMessage.yaml",
    "Solutions/CiscoASA/Analytic Rules/CiscoASA-PossibleDataExfiltration.yaml",
    "Solutions/CiscoASA/Analytic Rules/CiscoASA-AvgAttackDetectRateIncrease.yaml"
  ],
  "BasePath": "C:\\GitHub\\Azure-Sentinel\\",
  "Version": "3.0.8",
  "Metadata": "SolutionMetadata.json",
  "TemplateSpec": true,
  "Is1PConnector": false
}