<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IPS Create Syslog Alert but it appears Not Used in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ips-create-syslog-alert-but-it-appears-not-used/m-p/4122543#M1072171</link>
    <description>&lt;P&gt;Can you post the screenshot how you confgured :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or refer below document :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/external_alerting_for_intrusion_events.pdf" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/external_alerting_for_intrusion_events.pdf&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 21 Jul 2020 11:29:35 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2020-07-21T11:29:35Z</dc:date>
    <item>
      <title>IPS Create Syslog Alert but it appears Not Used</title>
      <link>https://community.cisco.com/t5/network-security/ips-create-syslog-alert-but-it-appears-not-used/m-p/4122483#M1072162</link>
      <description>Hi all, Today I create Syslog alert in IPS Firepower Managment Center and save. After save it appears Not Used. May I know how to make it In Use. The IP address of the Syslog server is a valid server. May I have your answer as soon as possible. Thanks! best regards, tangsuan</description>
      <pubDate>Tue, 21 Jul 2020 09:47:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-create-syslog-alert-but-it-appears-not-used/m-p/4122483#M1072162</guid>
      <dc:creator>Tang-Suan Tan</dc:creator>
      <dc:date>2020-07-21T09:47:43Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Create Syslog Alert but it appears Not Used</title>
      <link>https://community.cisco.com/t5/network-security/ips-create-syslog-alert-but-it-appears-not-used/m-p/4122543#M1072171</link>
      <description>&lt;P&gt;Can you post the screenshot how you confgured :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or refer below document :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/external_alerting_for_intrusion_events.pdf" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/external_alerting_for_intrusion_events.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jul 2020 11:29:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-create-syslog-alert-but-it-appears-not-used/m-p/4122543#M1072171</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-07-21T11:29:35Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Create Syslog Alert but it appears Not Used</title>
      <link>https://community.cisco.com/t5/network-security/ips-create-syslog-alert-but-it-appears-not-used/m-p/4122577#M1072173</link>
      <description>Hi Balji, I followed the step by Cisco document: &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/external_alerting_with_alert_responses.html#ID-2197-00000005" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/external_alerting_with_alert_responses.html#ID-2197-00000005&lt;/A&gt; at the portion of Creating a Syslog Alert Response. I refer to your link URL, I cannot find the below step: Step 1 In the intrusion policy editor's navigation pane, click Advanced Settings. The problem is where is "intrusion policy editor's navigation pane". I can't even start. Please advise. Thanks and regards, tangsuan</description>
      <pubDate>Tue, 21 Jul 2020 11:58:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-create-syslog-alert-but-it-appears-not-used/m-p/4122577#M1072173</guid>
      <dc:creator>Tang-Suan Tan</dc:creator>
      <dc:date>2020-07-21T11:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Create Syslog Alert but it appears Not Used</title>
      <link>https://community.cisco.com/t5/network-security/ips-create-syslog-alert-but-it-appears-not-used/m-p/4123133#M1072199</link>
      <description>&lt;P&gt;Hi Balaji and all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created the Syslog setting and the it was saved successfully. Attach is the picture for two Syslog. One of them is&lt;/P&gt;&lt;P&gt;"In Use" and another newly created one is "Not Used"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;May I know how to make the Not Used one to In Use?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks and hope to hear from you soon.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;tangsuan&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 03:06:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-create-syslog-alert-but-it-appears-not-used/m-p/4123133#M1072199</guid>
      <dc:creator>Tang-Suan Tan</dc:creator>
      <dc:date>2020-07-22T03:06:42Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Create Syslog Alert but it appears Not Used</title>
      <link>https://community.cisco.com/t5/network-security/ips-create-syslog-alert-but-it-appears-not-used/m-p/4123159#M1072200</link>
      <description>&lt;P&gt;Can you show us your access control policy where you have specified the new syslog setting to be used? Unless you have such a policy setting, the setting will continue to show as "not used".&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 03:49:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-create-syslog-alert-but-it-appears-not-used/m-p/4123159#M1072200</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-07-22T03:49:54Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Create Syslog Alert but it appears Not Used</title>
      <link>https://community.cisco.com/t5/network-security/ips-create-syslog-alert-but-it-appears-not-used/m-p/4123267#M1072206</link>
      <description>&lt;P&gt;Hi Mervin,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks to your suggestion. I find the access control policy and in the logging tab, I added in the new Syslog setting and now it becomes In Use.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks to your solution to resolve my problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;One more question now it is In Use. What is the effective way to show that the Syslog server actually got the logs from this IPS or FMC. Is the Tag at the Syslog setting can indicate some clue on the result?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regrads,&lt;/P&gt;&lt;P&gt;tangsuan&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 07:22:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-create-syslog-alert-but-it-appears-not-used/m-p/4123267#M1072206</guid>
      <dc:creator>Tang-Suan Tan</dc:creator>
      <dc:date>2020-07-22T07:22:25Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Create Syslog Alert but it appears Not Used</title>
      <link>https://community.cisco.com/t5/network-security/ips-create-syslog-alert-but-it-appears-not-used/m-p/4123299#M1072208</link>
      <description>&lt;P&gt;You have to use in the Policy for the syslog you have created, ACP you have Logging option tab to look.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 07:49:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-create-syslog-alert-but-it-appears-not-used/m-p/4123299#M1072208</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-07-22T07:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: IPS Create Syslog Alert but it appears Not Used</title>
      <link>https://community.cisco.com/t5/network-security/ips-create-syslog-alert-but-it-appears-not-used/m-p/4123302#M1072209</link>
      <description>&lt;P&gt;Syslog messages are normally sent via UDP so there's not guaranteed delivery. But if you see them coming into your syslog server at a regular rate then you can infer that you are getting them as they are sent.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 07:52:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ips-create-syslog-alert-but-it-appears-not-used/m-p/4123302#M1072209</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-07-22T07:52:51Z</dc:date>
    </item>
  </channel>
</rss>

