<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Syslog configuration in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/syslog-configuration/m-p/4425954#M1081891</link>
    <description>&lt;P&gt;Its all depends how bit network and how many devices Logs you want to sent to Azure, do you have express route to Azure or using Public Internet to sending Logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this is large environment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would advise to setup a Local syslog server, from that syslog server push all the Logs to cloud is best option and secure.&lt;/P&gt;</description>
    <pubDate>Wed, 30 Jun 2021 09:16:49 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2021-06-30T09:16:49Z</dc:date>
    <item>
      <title>Syslog configuration</title>
      <link>https://community.cisco.com/t5/network-security/syslog-configuration/m-p/4425871#M1081886</link>
      <description>&lt;P&gt;guys..&lt;/P&gt;&lt;P&gt;what is the recommended syslog configuration if i want to send all logs to azure sentinel?&lt;/P&gt;&lt;P&gt;i mean do i need to include the uplinks in the command? eg below:-&lt;/P&gt;&lt;P&gt;logging facility syslog&lt;/P&gt;&lt;P&gt;logging source-interface "uplink-ports"&lt;/P&gt;&lt;P&gt;logging host "ip add of syslog server"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 06:18:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-configuration/m-p/4425871#M1081886</guid>
      <dc:creator>shaikh.zaid22</dc:creator>
      <dc:date>2021-06-30T06:18:35Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog configuration</title>
      <link>https://community.cisco.com/t5/network-security/syslog-configuration/m-p/4425954#M1081891</link>
      <description>&lt;P&gt;Its all depends how bit network and how many devices Logs you want to sent to Azure, do you have express route to Azure or using Public Internet to sending Logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If this is large environment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would advise to setup a Local syslog server, from that syslog server push all the Logs to cloud is best option and secure.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 09:16:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-configuration/m-p/4425954#M1081891</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-06-30T09:16:49Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog configuration</title>
      <link>https://community.cisco.com/t5/network-security/syslog-configuration/m-p/4425975#M1081894</link>
      <description>&lt;P&gt;Thanks Balaji&lt;/P&gt;&lt;P&gt;We have 4 pairs of stack switches and a core sw in vss.&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have expressroute in place.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i want to know about the command "&lt;SPAN&gt;logging source-interface "uplink-ports"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;if i put an uplink interface here does all the logs will pass through it ? or i donot have to put anything?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 10:01:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-configuration/m-p/4425975#M1081894</guid>
      <dc:creator>shaikh.zaid22</dc:creator>
      <dc:date>2021-06-30T10:01:44Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog configuration</title>
      <link>https://community.cisco.com/t5/network-security/syslog-configuration/m-p/4426006#M1081897</link>
      <description>&lt;P&gt;yes it uses the source interface to send Logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"logging source-interface "uplink-ports"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;make sure that uplink(layer3 has rechability to Azure IP address).&amp;nbsp; (i mean it allowed your any EDGE FW interface facing or express routing facing)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 11:21:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-configuration/m-p/4426006#M1081897</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-06-30T11:21:25Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog configuration</title>
      <link>https://community.cisco.com/t5/network-security/syslog-configuration/m-p/4426513#M1081917</link>
      <description>&lt;P&gt;Thanks Balaji,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually i have tested the config and logs are successfully being sent to sentinel. However i included source-interface as gig1/0/1 for testing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now i will update it with the uplink port to send all ports and other system logs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 06:06:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/syslog-configuration/m-p/4426513#M1081917</guid>
      <dc:creator>shaikh.zaid22</dc:creator>
      <dc:date>2021-07-01T06:06:51Z</dc:date>
    </item>
  </channel>
</rss>

