<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FMC: Connection Events not being sent to external Syslog in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-connection-events-not-being-sent-to-external-syslog/m-p/4619318#M1090456</link>
    <description>I did it but without success &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;BR /&gt;</description>
    <pubDate>Fri, 27 May 2022 14:07:19 GMT</pubDate>
    <dc:creator>juanc</dc:creator>
    <dc:date>2022-05-27T14:07:19Z</dc:date>
    <item>
      <title>FMC: Connection Events not being sent to external Syslog</title>
      <link>https://community.cisco.com/t5/network-security/fmc-connection-events-not-being-sent-to-external-syslog/m-p/4613426#M1090232</link>
      <description>&lt;P&gt;I've configured FMC to send Connection Events to an external syslog but not everything is being sent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've taken some tcpdumps and only the events with some relevant impact are sent. I'm interested in sending every event, even the allowed ones.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 18:14:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-connection-events-not-being-sent-to-external-syslog/m-p/4613426#M1090232</guid>
      <dc:creator>juanc</dc:creator>
      <dc:date>2022-05-19T18:14:41Z</dc:date>
    </item>
    <item>
      <title>Re: FMC: Connection Events not being sent to external Syslog</title>
      <link>https://community.cisco.com/t5/network-security/fmc-connection-events-not-being-sent-to-external-syslog/m-p/4613583#M1090238</link>
      <description>&lt;P&gt;Can you share the screenshot of your syslog configuration and is this syslog server selected globally for the ACP or individual rules?&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2022 00:54:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-connection-events-not-being-sent-to-external-syslog/m-p/4613583#M1090238</guid>
      <dc:creator>Udupi Krishna.</dc:creator>
      <dc:date>2022-05-20T00:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: FMC: Connection Events not being sent to external Syslog</title>
      <link>https://community.cisco.com/t5/network-security/fmc-connection-events-not-being-sent-to-external-syslog/m-p/4613601#M1090239</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Follow this doc :&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200479-Configure-Logging-on-FTD-via-FMC.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200479-Configure-Logging-on-FTD-via-FMC.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Also as Krishna said, you need to provide the screenshot so we can understand what are you doing.&lt;/P&gt;&lt;P&gt;there are multiple places you can do the logging from like Platform Settings, each rule in ACP or globally under the ACP [logging Tab]&lt;/P&gt;&lt;P&gt;IPS are done under IPS Section etc&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2022 02:14:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-connection-events-not-being-sent-to-external-syslog/m-p/4613601#M1090239</guid>
      <dc:creator>SinghRaminder</dc:creator>
      <dc:date>2022-05-20T02:14:34Z</dc:date>
    </item>
    <item>
      <title>Re: FMC: Connection Events not being sent to external Syslog</title>
      <link>https://community.cisco.com/t5/network-security/fmc-connection-events-not-being-sent-to-external-syslog/m-p/4614085#M1090270</link>
      <description>&lt;P&gt;I'm doing it on an individual rule but it's the only rule that is logging on the ACP. See the attachment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And I'm getting some of the events, just not the allowed events which I also want to send. So the connection is established, might it be something with the logging level I'm using?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, I'm using 2 ASA 5515X with Firepower software module and 4 ASA 5585X with Firepower hardware module. No FTD devices. So the FTD Platform Settings policy do not apply in my case.&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2022 13:24:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-connection-events-not-being-sent-to-external-syslog/m-p/4614085#M1090270</guid>
      <dc:creator>juanc</dc:creator>
      <dc:date>2022-05-20T13:24:31Z</dc:date>
    </item>
    <item>
      <title>Re: FMC: Connection Events not being sent to external Syslog</title>
      <link>https://community.cisco.com/t5/network-security/fmc-connection-events-not-being-sent-to-external-syslog/m-p/4614174#M1090276</link>
      <description>&lt;P&gt;So you are trying to Get IPS/IDS Events? The one you are doing is Screenshot is Syslogs/Connection&lt;/P&gt;&lt;P&gt;Intrusion you do not get here,&lt;/P&gt;&lt;P&gt;Go to Intrusion Policies&amp;gt;Edit your Policy&amp;gt;Select AdvancedSettings on the left&amp;gt;Enable Sylog ALerting&lt;/P&gt;&lt;P&gt;You may need click back on the right hand side and commit it&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or the moment you enable the syslog you will see Syslog Alerting on the left and add the server there&lt;/P&gt;&lt;P&gt;You still need to commit changes, also be careful, changes to IPS policy and deploy can result in few pings loss&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And make sure you select the IPS policy under the inspection tab of the screenshot you provided&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 May 2022 15:15:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-connection-events-not-being-sent-to-external-syslog/m-p/4614174#M1090276</guid>
      <dc:creator>SinghRaminder</dc:creator>
      <dc:date>2022-05-20T15:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: FMC: Connection Events not being sent to external Syslog</title>
      <link>https://community.cisco.com/t5/network-security/fmc-connection-events-not-being-sent-to-external-syslog/m-p/4615791#M1090338</link>
      <description>&lt;P&gt;I do not see an option "Advanced Settings" when I edit my Intrusion Policy. I'm going into Policies&amp;gt;Intrusion&amp;gt;Edit and I see the attached window.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To clarify, I want to forward all the events generated to my configured syslog server.&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 21:27:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-connection-events-not-being-sent-to-external-syslog/m-p/4615791#M1090338</guid>
      <dc:creator>juanc</dc:creator>
      <dc:date>2022-05-23T21:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: FMC: Connection Events not being sent to external Syslog</title>
      <link>https://community.cisco.com/t5/network-security/fmc-connection-events-not-being-sent-to-external-syslog/m-p/4615799#M1090339</link>
      <description>&lt;P&gt;Do not directly edit there, click on the version you are using like snort 2 or snort 3 highlighted, then it will take you to your policy.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 21:44:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-connection-events-not-being-sent-to-external-syslog/m-p/4615799#M1090339</guid>
      <dc:creator>SinghRaminder</dc:creator>
      <dc:date>2022-05-23T21:44:47Z</dc:date>
    </item>
    <item>
      <title>Re: FMC: Connection Events not being sent to external Syslog</title>
      <link>https://community.cisco.com/t5/network-security/fmc-connection-events-not-being-sent-to-external-syslog/m-p/4615805#M1090340</link>
      <description>&lt;P&gt;Great, I found the option and made the change as you said but I'm still not getting the events sent. Maybe I'm using the wrong facility(Local0)? I set the level to Debug everywhere but the amount of logs do not change.&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 22:38:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-connection-events-not-being-sent-to-external-syslog/m-p/4615805#M1090340</guid>
      <dc:creator>juanc</dc:creator>
      <dc:date>2022-05-23T22:38:34Z</dc:date>
    </item>
    <item>
      <title>Re: FMC: Connection Events not being sent to external Syslog</title>
      <link>https://community.cisco.com/t5/network-security/fmc-connection-events-not-being-sent-to-external-syslog/m-p/4615857#M1090341</link>
      <description>&lt;P&gt;It is possible, i just compared mine and we are using the default LOCAL4 facility, and we do receive all the IPS/IDS alerts&lt;/P&gt;&lt;P&gt;Can you set up yours and give it a shot&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 01:40:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-connection-events-not-being-sent-to-external-syslog/m-p/4615857#M1090341</guid>
      <dc:creator>SinghRaminder</dc:creator>
      <dc:date>2022-05-24T01:40:43Z</dc:date>
    </item>
    <item>
      <title>Re: FMC: Connection Events not being sent to external Syslog</title>
      <link>https://community.cisco.com/t5/network-security/fmc-connection-events-not-being-sent-to-external-syslog/m-p/4619318#M1090456</link>
      <description>I did it but without success &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 27 May 2022 14:07:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-connection-events-not-being-sent-to-external-syslog/m-p/4619318#M1090456</guid>
      <dc:creator>juanc</dc:creator>
      <dc:date>2022-05-27T14:07:19Z</dc:date>
    </item>
  </channel>
</rss>

