<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco Firepower Logging in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-firepower-logging/m-p/4414102#M1081357</link>
    <description>&lt;P&gt;No, I using FMC. This screenshot is only example what I mean.&lt;/P&gt;&lt;P&gt;So if I enable Logging tab in Access Control Policy I also should enable Logging in Access Control Rule, yes ?&lt;/P&gt;</description>
    <pubDate>Mon, 07 Jun 2021 15:26:35 GMT</pubDate>
    <dc:creator>mikiNet</dc:creator>
    <dc:date>2021-06-07T15:26:35Z</dc:date>
    <item>
      <title>Cisco Firepower Logging</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-logging/m-p/4413993#M1081352</link>
      <description>&lt;P&gt;Hello Guys,&lt;/P&gt;&lt;P&gt;I have a question related to logging on Firepower. We have two option to configure it, first via Platform Setting, second via tab in Access Control Policy (this tab is near Security Intelligence, HTTP Response etc.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Question is: What is difference between logging on Platform Setting vs logging on ACP ? Pros and cons? When using ?&lt;/P&gt;&lt;P&gt;I can't find any good explanation about it.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jun 2021 12:41:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-logging/m-p/4413993#M1081352</guid>
      <dc:creator>mikiNet</dc:creator>
      <dc:date>2021-06-07T12:41:51Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower Logging</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-logging/m-p/4414004#M1081353</link>
      <description>&lt;P&gt;As per my understanding. here is what i can describe simple :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Platform Setting - Looging is more related to device logging like errors and events, you can select what kind of logs to be generated and logs to syslog server&lt;/P&gt;
&lt;P&gt;Access Control Policy&amp;nbsp; - Logging - more related to Policy logs ( accept or denined logs ..etc kind). ( you can beging of the connection or ending of the connection, or both)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jun 2021 13:01:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-logging/m-p/4414004#M1081353</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-06-07T13:01:16Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower Logging</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-logging/m-p/4414009#M1081354</link>
      <description>&lt;P&gt;No,&lt;/P&gt;&lt;P&gt;I mean this tab:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="loggg.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/122002iDAFCECAA6E3A14A0/image-size/large?v=v2&amp;amp;px=999" role="button" title="loggg.png" alt="loggg.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jun 2021 13:09:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-logging/m-p/4414009#M1081354</guid>
      <dc:creator>mikiNet</dc:creator>
      <dc:date>2021-06-07T13:09:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower Logging</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-logging/m-p/4414031#M1081355</link>
      <description>&lt;P&gt;Hope you are using FDM here ?&amp;nbsp; But yes that is for ACP Logging&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jun 2021 13:55:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-logging/m-p/4414031#M1081355</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-06-07T13:55:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower Logging</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-logging/m-p/4414102#M1081357</link>
      <description>&lt;P&gt;No, I using FMC. This screenshot is only example what I mean.&lt;/P&gt;&lt;P&gt;So if I enable Logging tab in Access Control Policy I also should enable Logging in Access Control Rule, yes ?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jun 2021 15:26:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-logging/m-p/4414102#M1081357</guid>
      <dc:creator>mikiNet</dc:creator>
      <dc:date>2021-06-07T15:26:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower Logging</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-logging/m-p/4414210#M1081362</link>
      <description>&lt;P&gt;The logging tab in your ACP screenshot primarily refers to syslog setting for those things that have associated syslog actions.&lt;/P&gt;
&lt;P&gt;All ACP entries, including the default action, need to have their settings individually set to log or not - it can be to the FMC Connection events, to syslog server or as an SNMP trap. We also choose to log at beginning or end of connection there.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jun 2021 17:56:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-logging/m-p/4414210#M1081362</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-06-07T17:56:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower Logging</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-logging/m-p/4414233#M1081363</link>
      <description>&lt;P&gt;Ok, so to log ACP entries I need to set syslog in Logging tab globaly in ACP and also set Logging to syslog server on&amp;nbsp;&lt;SPAN&gt;individual rule (ACE) ? This two configuration need to be done to send syslog messages to syslog server ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jun 2021 18:36:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-logging/m-p/4414233#M1081363</guid>
      <dc:creator>mikiNet</dc:creator>
      <dc:date>2021-06-07T18:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower Logging</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-logging/m-p/4414243#M1081364</link>
      <description>&lt;P&gt;Yes - but only if you want to use a external syslog server. The majority of my customers log primarily (and only) to the FMC.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jun 2021 19:06:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-logging/m-p/4414243#M1081364</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-06-07T19:06:01Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco Firepower Logging</title>
      <link>https://community.cisco.com/t5/network-security/cisco-firepower-logging/m-p/5245329#M1118662</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PeterKoltl_4-1736448256136.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237293i3B2EC193A93333AF/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PeterKoltl_4-1736448256136.png" alt="PeterKoltl_4-1736448256136.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/admin/760/management-center-admin-76/analysis-external-tools.html#id_102487" target="_blank"&gt;Best Practices for Configuring Security Event Syslog Messaging&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PeterKoltl_0-1736448060462.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237289i9978B4F2939C3501/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PeterKoltl_0-1736448060462.png" alt="PeterKoltl_0-1736448060462.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do not use&amp;nbsp;&lt;STRONG&gt;Policies &amp;gt; Actions &amp;gt; Alerts&lt;/STRONG&gt; if it is an FTD:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PeterKoltl_1-1736448060468.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237290i5894011433C8B0F3/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PeterKoltl_1-1736448060468.png" alt="PeterKoltl_1-1736448060468.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PeterKoltl_2-1736448060476.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237291iC981EC392BF599CE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PeterKoltl_2-1736448060476.png" alt="PeterKoltl_2-1736448060476.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="PeterKoltl_3-1736448060483.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/237292iFF98267E82C9958F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="PeterKoltl_3-1736448060483.png" alt="PeterKoltl_3-1736448060483.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/admin/760/management-center-admin-76/events-connect-logging.html#ID-2174-00000094" target="_blank"&gt;Beginning vs End-of-Connection Logging&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Jan 2025 18:45:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-firepower-logging/m-p/5245329#M1118662</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2025-01-09T18:45:14Z</dc:date>
    </item>
  </channel>
</rss>

