<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FMC Audit Logs - username missing in syslog payload in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-audit-logs-username-missing-in-syslog-payload/m-p/3707841#M1014288</link>
    <description>&lt;P&gt;Hi All&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just curious if anyone has encountered the similar situation before.&lt;/P&gt;
&lt;P&gt;I have configured the FMC's Management/Audit logs to be sent to a SIEM via syslog.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(System &amp;gt; Configuration &amp;gt; Audit Logs)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem I have encountered is that the username&amp;nbsp;is not present in syslog payload. Some of the sample syslog payload is as below.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sep 17 01:51:35 0M-FMCv Login[23783]: Login Failed&lt;BR /&gt;Sep 17 01:53:46 0M-FMCv Login[24333]: Login Success&lt;BR /&gt;Sep 17 01:31:57 0M-FMCv System &amp;gt; Users &amp;gt; User Roles &amp;gt; User Role Editor[26824]: Page View&lt;BR /&gt;Sep 17 01:31:52 0M-FMCv System &amp;gt; Users &amp;gt; User Roles[26825]: Page View&lt;BR /&gt;Sep 17 01:31:42 0M-FMCv System &amp;gt; Users &amp;gt; Users[19589]: Page View&lt;BR /&gt;Sep 17 01:31:10 0M-FMCv System &amp;gt; Users &amp;gt; User Roles[26825]: Page View&lt;BR /&gt;Sep 17 01:30:55 0M-FMCv System &amp;gt; Users &amp;gt; Users &amp;gt; Edit User[19317]: Page View&lt;BR /&gt;Sep 17 01:29:31 0M-FMCv Login[18816]: Login Success&lt;BR /&gt;Sep 17 01:29:19 0M-FMCv Logout[18701]: Logout Success&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have tried using different users, but we can't distinguish between user activities as the username is not there.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 16:14:58 GMT</pubDate>
    <dc:creator>osama.mehtab.ga</dc:creator>
    <dc:date>2020-02-21T16:14:58Z</dc:date>
    <item>
      <title>FMC Audit Logs - username missing in syslog payload</title>
      <link>https://community.cisco.com/t5/network-security/fmc-audit-logs-username-missing-in-syslog-payload/m-p/3707841#M1014288</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just curious if anyone has encountered the similar situation before.&lt;/P&gt;
&lt;P&gt;I have configured the FMC's Management/Audit logs to be sent to a SIEM via syslog.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(System &amp;gt; Configuration &amp;gt; Audit Logs)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem I have encountered is that the username&amp;nbsp;is not present in syslog payload. Some of the sample syslog payload is as below.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sep 17 01:51:35 0M-FMCv Login[23783]: Login Failed&lt;BR /&gt;Sep 17 01:53:46 0M-FMCv Login[24333]: Login Success&lt;BR /&gt;Sep 17 01:31:57 0M-FMCv System &amp;gt; Users &amp;gt; User Roles &amp;gt; User Role Editor[26824]: Page View&lt;BR /&gt;Sep 17 01:31:52 0M-FMCv System &amp;gt; Users &amp;gt; User Roles[26825]: Page View&lt;BR /&gt;Sep 17 01:31:42 0M-FMCv System &amp;gt; Users &amp;gt; Users[19589]: Page View&lt;BR /&gt;Sep 17 01:31:10 0M-FMCv System &amp;gt; Users &amp;gt; User Roles[26825]: Page View&lt;BR /&gt;Sep 17 01:30:55 0M-FMCv System &amp;gt; Users &amp;gt; Users &amp;gt; Edit User[19317]: Page View&lt;BR /&gt;Sep 17 01:29:31 0M-FMCv Login[18816]: Login Success&lt;BR /&gt;Sep 17 01:29:19 0M-FMCv Logout[18701]: Logout Success&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have tried using different users, but we can't distinguish between user activities as the username is not there.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:14:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-audit-logs-username-missing-in-syslog-payload/m-p/3707841#M1014288</guid>
      <dc:creator>osama.mehtab.ga</dc:creator>
      <dc:date>2020-02-21T16:14:58Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Audit Logs - username missing in syslog payload</title>
      <link>https://community.cisco.com/t5/network-security/fmc-audit-logs-username-missing-in-syslog-payload/m-p/3707868#M1014289</link>
      <description>&lt;P&gt;You're right - that's a shortcoming in the current syslog functionality on FMC. I just confirmed it on my system running the latest 6.2.3.5 release.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Even a login success event doesn't provide the username via syslog (even though the syslog view in FMC does include the username). Below you can see both the FMC view as well as a packet capture the actual syslog message received on my target syslog host:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FMC - Syslog.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/18727i079674931382DF1A/image-size/large?v=v2&amp;amp;px=999" role="button" title="FMC - Syslog.PNG" alt="FMC - Syslog.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 05:52:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-audit-logs-username-missing-in-syslog-payload/m-p/3707868#M1014289</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2018-09-17T05:52:32Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Audit Logs - username missing in syslog payload</title>
      <link>https://community.cisco.com/t5/network-security/fmc-audit-logs-username-missing-in-syslog-payload/m-p/3707869#M1014291</link>
      <description>&lt;P&gt;Yes Marvin,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I did the same to check. I think&amp;nbsp;username and IP address&amp;nbsp;were there in earlier versions but I am not sure about it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, I found&amp;nbsp;a file /var/log/CSMAgent.log in which we can see the successful login and logout event but its not very helpful for my case. Anyways thanks for your response, really appreciate that you took to respond.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Sep 2018 06:02:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-audit-logs-username-missing-in-syslog-payload/m-p/3707869#M1014291</guid>
      <dc:creator>osama.mehtab.ga</dc:creator>
      <dc:date>2018-09-17T06:02:35Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Audit Logs - username missing in syslog payload</title>
      <link>https://community.cisco.com/t5/network-security/fmc-audit-logs-username-missing-in-syslog-payload/m-p/3817405#M1014292</link>
      <description>&lt;P&gt;Has this been resolved in 6.3?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 13:59:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-audit-logs-username-missing-in-syslog-payload/m-p/3817405#M1014292</guid>
      <dc:creator>boecknerm@bhc.edu</dc:creator>
      <dc:date>2019-03-11T13:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Audit Logs - username missing in syslog payload</title>
      <link>https://community.cisco.com/t5/network-security/fmc-audit-logs-username-missing-in-syslog-payload/m-p/3817786#M1014293</link>
      <description>&lt;P&gt;Yes - I am running 6.3.0.1. We now see the syslog messages with the username and source IP address from which the user logged in is included in the syslog messages:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FMC syslog with username.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/31759i996407CC0F71628D/image-size/large?v=v2&amp;amp;px=999" role="button" title="FMC syslog with username.PNG" alt="FMC syslog with username.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:14:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-audit-logs-username-missing-in-syslog-payload/m-p/3817786#M1014293</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-03-12T04:14:37Z</dc:date>
    </item>
  </channel>
</rss>

