<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to FMC Audit log to Syslog Server ? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-fmc-audit-log-to-syslog-server/m-p/4585851#M1088943</link>
    <description>&lt;P&gt;I'm sorry, I don't understand your information and you don't understand my issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please check this problem again.&lt;/P&gt;</description>
    <pubDate>Tue, 05 Apr 2022 02:49:12 GMT</pubDate>
    <dc:creator>simplewildstyle</dc:creator>
    <dc:date>2022-04-05T02:49:12Z</dc:date>
    <item>
      <title>How to FMC Audit log to Syslog Server ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-fmc-audit-log-to-syslog-server/m-p/4575775#M1088514</link>
      <description>&lt;P&gt;Dear sir,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want to collect the audit log of fmc to syslog.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is set as follows, but logs other than audit logs are being collected as below.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And i don't want see this logs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mar 22 01:25:46 firepower sudo: www : TTY=unknown ; PWD=/usr/local/sf/htdocs/platinum ; USER=root ; COMMAND=/etc/rc.d/init.d/syslog-ng restart&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mar 22 01:25:46 firepower sudo: www : TTY=unknown ; PWD=/usr/local/sf/htdocs/platinum ; USER=root ; COMMAND=/bin/chmod 0755 /etc/syslog-ng.d&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The method I would like to see is the following audit log. (Monitoring -&amp;gt; Audit on FMC)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="123.JPG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/147041i6FC909E94C64EF7F/image-size/large?v=v2&amp;amp;px=999" role="button" title="123.JPG" alt="123.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My Audit log to Syslog Settings is below.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="audit log to syslog.JPG" style="width: 603px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/147042i4E36BE71AF3837AA/image-size/large?v=v2&amp;amp;px=999" role="button" title="audit log to syslog.JPG" alt="audit log to syslog.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check settings and help me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;best regards.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 08:11:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-fmc-audit-log-to-syslog-server/m-p/4575775#M1088514</guid>
      <dc:creator>simplewildstyle</dc:creator>
      <dc:date>2022-03-22T08:11:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to FMC Audit log to Syslog Server ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-fmc-audit-log-to-syslog-server/m-p/4576534#M1088552</link>
      <description>&lt;P&gt;In Facility change that to: SYSLOG&lt;/P&gt;&lt;P&gt;In Tag change that to the DNS name of the FMC if you want or leave as is&lt;/P&gt;&lt;P&gt;Send Audit Log to HTTP Server we have ours set to "Disabled" if you have an HTTP server set it to that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the audit Log Certificate section:&lt;/P&gt;&lt;P&gt;Chose the check boxes that apply, Enable TLS and/or Enable Mutual authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For HTTPS Certificate:&lt;/P&gt;&lt;P&gt;If you plan on using a cert now but haven't in the past you will need to set that up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 20:50:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-fmc-audit-log-to-syslog-server/m-p/4576534#M1088552</guid>
      <dc:creator>Eric R. Jones</dc:creator>
      <dc:date>2022-03-22T20:50:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to FMC Audit log to Syslog Server ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-fmc-audit-log-to-syslog-server/m-p/4577506#M1088587</link>
      <description>&lt;P&gt;Dear sir,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks for your information, but it was same issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see below log (FPR Syslog) on logging server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mar 24 02:48:41 firepower sudo: www : TTY=unknown ; PWD=/usr/local/sf/htdocs/admin ; USER=root ; COMMAND=/etc/rc.d/init.d/syslog-ng restart&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Mar 24 02:48:41 firepower sudo: pam_unix(sudo:session): session opened for user root by (uid=0)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;but, I wnat to FMC audit log on logging server. (not syslog)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Please help me.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;thanks,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2022 02:54:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-fmc-audit-log-to-syslog-server/m-p/4577506#M1088587</guid>
      <dc:creator>simplewildstyle</dc:creator>
      <dc:date>2022-03-24T02:54:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to FMC Audit log to Syslog Server ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-fmc-audit-log-to-syslog-server/m-p/4577689#M1088595</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your settings look ok.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/system_configuration.html#ID-2258-00000149" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/system_configuration.html#ID-2258-00000149&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My understanding - in this case - is that Facility and Severity are helpful only for syslog filtering at destination, not at source. Your FMC should send all audit events like you want to (including GUI menus). Try running a tcpdump on FMC with a filter for that specific sylog or run the capture on the syslog itself with a filter for FMC source IP and look into it.&lt;BR /&gt;Maybe you applied some filters on syslog and that's why you don't see all logs/&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;BR,&lt;BR /&gt;Octavian&lt;/P&gt;</description>
      <pubDate>Thu, 24 Mar 2022 09:55:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-fmc-audit-log-to-syslog-server/m-p/4577689#M1088595</guid>
      <dc:creator>Octavian Szolga</dc:creator>
      <dc:date>2022-03-24T09:55:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to FMC Audit log to Syslog Server ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-fmc-audit-log-to-syslog-server/m-p/4578224#M1088609</link>
      <description>&lt;P&gt;Dear sir,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I checked received syslogs on logging server as below.&lt;/P&gt;&lt;P&gt;(tcpdump -i any port 514)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But, cannot see FMC audit log.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I want to FMC audit log on logging server. (not syslog)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sysloging.JPG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/147371i9134D28A6E78E648/image-size/large?v=v2&amp;amp;px=999" role="button" title="sysloging.JPG" alt="sysloging.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please help me,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Fri, 25 Mar 2022 01:19:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-fmc-audit-log-to-syslog-server/m-p/4578224#M1088609</guid>
      <dc:creator>simplewildstyle</dc:creator>
      <dc:date>2022-03-25T01:19:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to FMC Audit log to Syslog Server ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-fmc-audit-log-to-syslog-server/m-p/4579220#M1088658</link>
      <description>This link is pulled from within my FMC.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;log_from_fmc_61plus.html?highlight=stream%20aud&amp;gt; Stream Audit Logs to Syslog&lt;BR /&gt;(srf.local)&lt;BR /&gt;&lt;BR /&gt;You lost me when you said:&lt;BR /&gt;&lt;BR /&gt;"But, cannot see FMC audit log.&lt;BR /&gt;&lt;BR /&gt;I want to FMC audit log on logging server. (not syslog)"&lt;BR /&gt;&lt;BR /&gt;Are you trying to separate audit log data from syslog server collection into&lt;BR /&gt;a different location?&lt;BR /&gt;&lt;BR /&gt;Are you talking about event logs and system log data?&lt;BR /&gt;&lt;BR /&gt;We have configured ours to send all logs to an NFS location and to a SIEM&lt;BR /&gt;setup load balanced by A10 servers.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Sun, 27 Mar 2022 21:04:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-fmc-audit-log-to-syslog-server/m-p/4579220#M1088658</guid>
      <dc:creator>Eric R. Jones</dc:creator>
      <dc:date>2022-03-27T21:04:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to FMC Audit log to Syslog Server ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-fmc-audit-log-to-syslog-server/m-p/4585851#M1088943</link>
      <description>&lt;P&gt;I'm sorry, I don't understand your information and you don't understand my issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please check this problem again.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2022 02:49:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-fmc-audit-log-to-syslog-server/m-p/4585851#M1088943</guid>
      <dc:creator>simplewildstyle</dc:creator>
      <dc:date>2022-04-05T02:49:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to FMC Audit log to Syslog Server ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-fmc-audit-log-to-syslog-server/m-p/4596386#M1089368</link>
      <description>&lt;P&gt;Did you ever sort out this issue?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Apr 2022 22:04:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-fmc-audit-log-to-syslog-server/m-p/4596386#M1089368</guid>
      <dc:creator>Eric R. Jones</dc:creator>
      <dc:date>2022-04-20T22:04:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to FMC Audit log to Syslog Server ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-fmc-audit-log-to-syslog-server/m-p/4608714#M1089972</link>
      <description>&lt;P&gt;not yet..&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2022 04:02:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-fmc-audit-log-to-syslog-server/m-p/4608714#M1089972</guid>
      <dc:creator>simplewildstyle</dc:creator>
      <dc:date>2022-05-12T04:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to FMC Audit log to Syslog Server ?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-fmc-audit-log-to-syslog-server/m-p/4640791#M1091427</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I remember running some tests on a 6.6 FMC and I got same results as you did.&lt;/P&gt;
&lt;P&gt;No audit for GUI, just some linux syslog. &lt;BR /&gt;Now I'm running 7.2 and I can at least tell you that auditing works as expected.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;06-29-2022 15:53:13 System4.Info x.x.x.x Jun 29 12:50:24 index.cgi: [FMC_AUDIT] fmc.local.hostname: admin@x.x.x.x, System &amp;gt; Monitoring &amp;gt; Audit, Page View&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;BR,&lt;/P&gt;
&lt;P&gt;Octavian&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 12:55:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-fmc-audit-log-to-syslog-server/m-p/4640791#M1091427</guid>
      <dc:creator>Octavian Szolga</dc:creator>
      <dc:date>2022-06-29T12:55:00Z</dc:date>
    </item>
  </channel>
</rss>

