Cisco Secure Firewall Management Center Audit
Cisco Secure Firewall Management Center (FMC) 7.4 audit Syslog records as ECS JSON for 24 administrator accounts: web-interface page views, network object creation, NAT policy saves and the system pre-deploy task records that follow a save. The FMC-originating line is kept verbatim in event.original, in the forms of Cisco TechNote 221019. About 1,250 records a day follow a working day in UTC. Recurring episodes show one account creating a network object, saving a NAT policy and saving the same policy again soon after.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/security-cisco-fmc-audit/generator.yml \
--id fmc \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| page-view: NGFW NAT Policy Editor | sfdccsm, Devices > NAT > NGFW NAT Policy Editor, Page View | 31.0% of records | web |
| page-view: NAT | sfdccsm, Devices > NAT, Page View | 18.9% of records | web |
| page-view: /ui/ddd/ | mojo_server.pl, /ui/ddd/, Page View (/ui/ddd/ page) | 13.3% of records | web |
| nat-policy-save | sfdccsm, Devices > NAT > NAT Policy Editor, Save Policy <policy> | 11.8% of records | configuration |
| login-success | ActionQueueScrape.pl, Login, Login Success (csm_processes@Default User IP) | 10.0% of records | authentication |
| task-completion | ActionQueueScrape.pl, Task Queue, Successful task completion : Pre-deploy Global Configuration Generation (admin@localhost) | 10.0% of records | configuration |
| network-object-create | sfdccsm, Objects > Object Management > NetworkObject, create <object> | 5.0% of records | configuration |
Realism Features
- Twenty-four administrator accounts work in web-interface sessions that open on the /ui/ddd/ page or the NAT list and hold one to about twenty actions seconds to minutes apart (most often a few), followed by a pause of about 17 minutes in median, up to several hours. The six busiest accounts write about 850 to 1,100 records in two weeks, the quietest about 250; about 15% of sessions come from a second address instead of the usual workstation.
- About 1,250 records a day, with 3% variation from day to day, follow a working day in UTC: activity rises from 04:00, peaks at about 130 records an hour around 11:00 and fades out by 20:00, with about 1-6 records an hour between 21:00 and 03:00. Configuration changes happen between 05:00 and 19:00 UTC; off-hours records are page views only. Sessions of several administrators overlap and their records interleave.
- More than half of object creations are followed later in the session by a NAT policy save. Saves of the ten NAT policies always come from the editor, which is shown again right after, and about a fifth of saves are saved again later in the session; after 85% of saves the system logs csm_processes Login Success and the pre-deploy task completion, as in the Cisco sample.
- Records that follow at once on a real FMC are further apart here: the editor view after a save and the task completion after the system login come a few seconds to about a minute and a half later (median about 25 seconds) instead of within a second, and the system login comes a median 1.7 minutes after the save instead of about 20 seconds. After an object is created, a later save in the hour goes to a different policy than the one already saved more often than on a real system. Rates, durations and the action mix are synthetic workload choices, not measured FMC production frequencies.
- Every line uses one of the seven forms of the eight Cisco TechNote 221019 (FMCv 7.4.0) lines; only user, address, object name, policy name and time vary. Other menus, object types, deletions, deployments and human logins and logouts are not generated, and failed logins are not modeled because their records carry neither user nor source address.
- The [FMC-AUDIT] tag is the one configured in the TechNote and is user-defined on a real FMC; the collector-side prefix is not emitted. The BSD header has no year or zone, one-second precision and a zero-padded day; @timestamp supplies the date and the time of day is UTC.
- cisco.fmc.audit.* is parsed from the line, while event.*, user.*, source.*, process.*, observer.* and related.* are ECS normalization, as no Elastic integration for FMC audit Syslog was found. The record never names the changed rule or object, so a revert is inferred from the repeated save. Compatibility with the KUMA CEF normalizer is not claimed, and no live capture was available for comparison.
Sample Output
{
"@timestamp": "2026-09-02T10:47:26+00:00",
"cisco": {
"fmc": {
"audit": {
"message": "Save Policy NATPolicy",
"policy": "NATPolicy",
"sender": "sfdccsm",
"subsystem": "Devices > NAT > NAT Policy Editor",
"tag": "FMC-AUDIT",
"user": "akumar",
"user_ip": "10.1.21.5"
}
}
},
"ecs": {
"version": "8.17.0"
},
"event": {
"action": "nat-policy-save",
"category": [
"configuration"
],
"dataset": "cisco_fmc.audit",
"kind": "event",
"module": "cisco_fmc",
"original": "Sep 02 10:47:26 firepower: [FMC-AUDIT] sfdccsm: akumar@10.1.21.5, Devices > NAT > NAT Policy Editor, Save Policy NATPolicy",
"type": [
"change"
]
},
"message": "Devices > NAT > NAT Policy Editor, Save Policy NATPolicy",
"observer": {
"hostname": "firepower",
"product": "Secure Firewall Management Center",
"vendor": "Cisco",
"version": "7.4.0"
},
"process": {
"name": "sfdccsm"
},
"related": {
"hosts": [
"firepower"
],
"ip": [
"10.1.21.5"
],
"user": [
"akumar"
]
},
"source": {
"ip": "10.1.21.5"
},
"user": {
"name": "akumar"
}
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Include periodic anomaly episodes; false gives background only |
| anomaly_interval_hours | 24 | Hours between episode starts; a multiple of 24 from 24 to 8,760, other values fail validation |
| management_center | firepower | FMC hostname in the Syslog header and observer.hostname |
Related Generators
Suricata IDS/IPS
Suricata EVE JSON output — IDS alerts with ET Open signatures, DNS/HTTP/TLS/SSH protocol logs, NetFlow records, and anomaly detections with correlated flow IDs and MITRE ATT&CK mapping.
Palo Alto Threat
Palo Alto PAN-OS Threat logs — IPS vulnerability exploits, antivirus detections, anti-spyware (DNS sinkhole and C2 callback), WildFire cloud verdicts, file type matching, and network scan detection with correlated severity, action, and threat category fields.
Palo Alto URL Filtering
Palo Alto PAN-OS URL Filtering logs — web browsing activity with 65+ URL categories, allow/block/continue/override actions, App-ID application attribution, and content type inspection.