<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hello, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/syslog-server-in-sourcefire-firepower/m-p/2982647#M1029305</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;The intrusion events log received from Syslog server. However, there are not contain interface info. &lt;SPAN&gt;May I know is there any way to configure the Syslog to contain the interface info?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Best Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thaung&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 25 May 2017 05:34:18 GMT</pubDate>
    <dc:creator>thaungtunzaw</dc:creator>
    <dc:date>2017-05-25T05:34:18Z</dc:date>
    <item>
      <title>syslog server in sourcefire/firepower</title>
      <link>https://community.cisco.com/t5/network-security/syslog-server-in-sourcefire-firepower/m-p/2982643#M1029301</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: 'courier new', courier, monospace;"&gt;How to configure syslog server in sourcefire/firepower?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:09:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-server-in-sourcefire-firepower/m-p/2982643#M1029301</guid>
      <dc:creator>John</dc:creator>
      <dc:date>2019-03-12T13:09:16Z</dc:date>
    </item>
    <item>
      <title>Hello John,</title>
      <link>https://community.cisco.com/t5/network-security/syslog-server-in-sourcefire-firepower/m-p/2982644#M1029302</link>
      <description>&lt;P&gt;Hello John,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Refer the following link and let us know if that helps you.&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118464-configure-firesight-00.html&lt;/P&gt;
&lt;P&gt;Rate and mark the answers correct and posts that helps you.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2016 07:44:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-server-in-sourcefire-firepower/m-p/2982644#M1029302</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2016-10-07T07:44:33Z</dc:date>
    </item>
    <item>
      <title>we need to create syslog per</title>
      <link>https://community.cisco.com/t5/network-security/syslog-server-in-sourcefire-firepower/m-p/2982645#M1029303</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt; font-family: 'courier new', courier, monospace;"&gt;we need to create syslog per policy?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2016 07:54:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-server-in-sourcefire-firepower/m-p/2982645#M1029303</guid>
      <dc:creator>John</dc:creator>
      <dc:date>2016-10-07T07:54:29Z</dc:date>
    </item>
    <item>
      <title>Hello John,</title>
      <link>https://community.cisco.com/t5/network-security/syslog-server-in-sourcefire-firepower/m-p/2982646#M1029304</link>
      <description>&lt;P&gt;Hello John,&lt;/P&gt;
&lt;P&gt;After configuring the syslog server, you just have to enable the loggings to send the log to Syslog server in Access control - Rules.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Oct 2016 08:14:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-server-in-sourcefire-firepower/m-p/2982646#M1029304</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2016-10-07T08:14:14Z</dc:date>
    </item>
    <item>
      <title>Hello,</title>
      <link>https://community.cisco.com/t5/network-security/syslog-server-in-sourcefire-firepower/m-p/2982647#M1029305</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;The intrusion events log received from Syslog server. However, there are not contain interface info. &lt;SPAN&gt;May I know is there any way to configure the Syslog to contain the interface info?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;Best Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thaung&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 05:34:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-server-in-sourcefire-firepower/m-p/2982647#M1029305</guid>
      <dc:creator>thaungtunzaw</dc:creator>
      <dc:date>2017-05-25T05:34:18Z</dc:date>
    </item>
    <item>
      <title>You are not going to be able</title>
      <link>https://community.cisco.com/t5/network-security/syslog-server-in-sourcefire-firepower/m-p/2982648#M1029306</link>
      <description>&lt;P&gt;You are not going to be able to change the built-in syslog format from the UI. &amp;nbsp;The list of fields available is fixed. &amp;nbsp;However, the eStreamer API has a much more robust set of fields. &amp;nbsp;Using an eStreamer client to pull events from the FMC you can get a ton (literally) more data. &amp;nbsp;If you really, really need it in syslog you could create an eStreamer client that pulls data from the FMC and then sends it via syslog wherever you want. &amp;nbsp;Then you can pick whatever data you want to send in your syslog message. &amp;nbsp;The latest integration guide is here&amp;nbsp;&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/firepower/620/api/eStreamer/EventStreamerIntegrationGuide/IS-DCRecords.html. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, there is an eStreamer SDK&amp;nbsp;(Perl) you can download that includes some sample code as well as the Integration Guide.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jun 2017 02:17:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-server-in-sourcefire-firepower/m-p/2982648#M1029306</guid>
      <dc:creator>atatistc</dc:creator>
      <dc:date>2017-06-01T02:17:04Z</dc:date>
    </item>
  </channel>
</rss>

