<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic If you need to see whats in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/logging-recommendations/m-p/2895708#M1030716</link>
    <description>&lt;P&gt;If you need to see whats going on in the network and keep track, you can have logging enabled.&lt;/P&gt;
&lt;P&gt;I would suggest to use &lt;SPAN style="color: #333333; font-family: Arial; font-size: 12pt; font-style: normal; font-weight: normal; line-height: 15px; text-align: left; text-transform: none; float: none; background-color: #ffffff;"&gt; End-of-Connection in there as well.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial; font-size: 12pt; font-style: normal; font-weight: normal; line-height: 15px; text-align: left; text-transform: none; float: none; background-color: #ffffff;"&gt;For SSL policy you can&amp;nbsp; have it with end of connection as the SSL policy needs to make decision and then log which will be better.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial; font-size: 12pt; font-style: normal; font-weight: normal; line-height: 15px; text-align: left; text-transform: none; float: none; background-color: #ffffff;"&gt;Rate if helps.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial; font-size: 12pt; font-style: normal; font-weight: normal; line-height: 15px; text-align: left; text-transform: none; float: none; background-color: #ffffff;"&gt;Yogesh&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 24 May 2016 18:17:53 GMT</pubDate>
    <dc:creator>yogdhanu</dc:creator>
    <dc:date>2016-05-24T18:17:53Z</dc:date>
    <item>
      <title>Logging recommendations</title>
      <link>https://community.cisco.com/t5/network-security/logging-recommendations/m-p/2895705#M1030713</link>
      <description>&lt;P&gt;Are there any recommendations as to when you should choose to log at the beginning or end? &amp;nbsp;I know in some circumstances, the only option is at the beginning due to the packet being dropped, but what about in other situations? &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;For example, I have an access-control rule that has the Balanced Security and Connectivity IPS policy set and a custom File Policy. &amp;nbsp;The action is set to Allow which should still block bad stuff if it goes through. &amp;nbsp;Is it better to log at the beginning or end?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;My default action for this policy is Network Discovery only. &amp;nbsp;Is it better to log at the beginning or end?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The only other place I have logging enabled is in the SSL policies and you can only log at the end.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The problem is that I ran into an issue where FMC seemed to have very few events (like maybe an hours worth) whereas previously I had days worth so I have a feeling I have too much logging toggled now. &amp;nbsp;Running the virtual appliance which looks like it maxes at 10M connection events.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:01:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/logging-recommendations/m-p/2895705#M1030713</guid>
      <dc:creator>m.yost</dc:creator>
      <dc:date>2019-03-12T13:01:21Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/logging-recommendations/m-p/2895706#M1030714</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;Hi&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial; font-size: 12pt; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 15px; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; display: inline ! important; float: none; background-color: #ffffff;"&gt;For a single connection, the end-of-connection event contains all of the information in the beginning-of-connection event as well as information that was gathered over the duration of the session. For Trust and Allow rules, it is recommended that End-of-Connection is used.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial; font-size: 12pt; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 15px; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; display: inline ! important; float: none; background-color: #ffffff;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial; font-size: 12pt; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 15px; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; display: inline ! important; float: none; background-color: #ffffff;"&gt;Rate if helps.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial; font-size: 12pt; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 15px; text-align: left; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; display: inline ! important; float: none; background-color: #ffffff;"&gt;Yogesh&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2016 16:02:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/logging-recommendations/m-p/2895706#M1030714</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2016-05-24T16:02:11Z</dc:date>
    </item>
    <item>
      <title>What if Network Discovery</title>
      <link>https://community.cisco.com/t5/network-security/logging-recommendations/m-p/2895707#M1030715</link>
      <description>&lt;P&gt;What if Network Discovery Only is your default action in the access policy? &amp;nbsp;Should that be logged or not and if so, at the beginning or end?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2016 18:09:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/logging-recommendations/m-p/2895707#M1030715</guid>
      <dc:creator>m.yost</dc:creator>
      <dc:date>2016-05-24T18:09:42Z</dc:date>
    </item>
    <item>
      <title>If you need to see whats</title>
      <link>https://community.cisco.com/t5/network-security/logging-recommendations/m-p/2895708#M1030716</link>
      <description>&lt;P&gt;If you need to see whats going on in the network and keep track, you can have logging enabled.&lt;/P&gt;
&lt;P&gt;I would suggest to use &lt;SPAN style="color: #333333; font-family: Arial; font-size: 12pt; font-style: normal; font-weight: normal; line-height: 15px; text-align: left; text-transform: none; float: none; background-color: #ffffff;"&gt; End-of-Connection in there as well.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial; font-size: 12pt; font-style: normal; font-weight: normal; line-height: 15px; text-align: left; text-transform: none; float: none; background-color: #ffffff;"&gt;For SSL policy you can&amp;nbsp; have it with end of connection as the SSL policy needs to make decision and then log which will be better.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial; font-size: 12pt; font-style: normal; font-weight: normal; line-height: 15px; text-align: left; text-transform: none; float: none; background-color: #ffffff;"&gt;Rate if helps.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #333333; font-family: Arial; font-size: 12pt; font-style: normal; font-weight: normal; line-height: 15px; text-align: left; text-transform: none; float: none; background-color: #ffffff;"&gt;Yogesh&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2016 18:17:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/logging-recommendations/m-p/2895708#M1030716</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2016-05-24T18:17:53Z</dc:date>
    </item>
    <item>
      <title>Thanks for the info.  I made</title>
      <link>https://community.cisco.com/t5/network-security/logging-recommendations/m-p/2895709#M1030717</link>
      <description>&lt;P&gt;Thanks for the info. &amp;nbsp;I made the necessary tweaks and I'm only getting ~20 hours of connection events. &amp;nbsp;If I look at the # of rows in Connection events, its only a little over 1 million and the virtual FMC appliance should be able to do 10 Million between connection events and Security Intelligence Events (there are no events in here). &amp;nbsp;I have a TAC case open to see what the deal is.&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2016 13:37:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/logging-recommendations/m-p/2895709#M1030717</guid>
      <dc:creator>m.yost</dc:creator>
      <dc:date>2016-05-26T13:37:30Z</dc:date>
    </item>
  </channel>
</rss>

