<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how to change intrusion event syslog port from 514 to 1515 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-change-intrusion-event-syslog-port-from-514-to-1515/m-p/4812325#M1099419</link>
    <description>&lt;P&gt;So you have syslog Server setup done using 1515&lt;/P&gt;
&lt;P&gt;your Syslog server can able receive the messages&amp;nbsp;&lt;SPAN&gt;message ID (430002, and 430003) ? but not 430001 ? Please confirm this&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;and give more details what is the device model/ what FTD version running. is this managed by&amp;nbsp; FMC?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;can you post the screenshot of the Syslog server config?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Apr 2023 01:00:12 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2023-04-12T01:00:12Z</dc:date>
    <item>
      <title>how to change intrusion event syslog port from 514 to 1515</title>
      <link>https://community.cisco.com/t5/network-security/how-to-change-intrusion-event-syslog-port-from-514-to-1515/m-p/4812177#M1099411</link>
      <description>&lt;P&gt;Hi, Everyone:&lt;/P&gt;&lt;P&gt;After done some troubleshooting and data capture, and found out Intrusion event syslog for message ID 430001 is sending to destination port (udp 514), I could see other message ID (430002, and 430003) are sending to udp port 1515, since external syslog is using udp port 1515, Is there a way to change syslog for message ID 430001 to destination port 1515 from 514?&lt;/P&gt;&lt;P&gt;Thanks for any suggestion&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 20:25:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-change-intrusion-event-syslog-port-from-514-to-1515/m-p/4812177#M1099411</guid>
      <dc:creator>jameslee43329</dc:creator>
      <dc:date>2023-04-11T20:25:37Z</dc:date>
    </item>
    <item>
      <title>Re: how to change intrusion event syslog port from 514 to 1515</title>
      <link>https://community.cisco.com/t5/network-security/how-to-change-intrusion-event-syslog-port-from-514-to-1515/m-p/4812185#M1099412</link>
      <description>&lt;P&gt;what is the level appear in 430002 and 430003 and 430001&amp;nbsp;&lt;BR /&gt;I think the level is issue here not the log message-d&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 20:34:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-change-intrusion-event-syslog-port-from-514-to-1515/m-p/4812185#M1099412</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-04-11T20:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: how to change intrusion event syslog port from 514 to 1515</title>
      <link>https://community.cisco.com/t5/network-security/how-to-change-intrusion-event-syslog-port-from-514-to-1515/m-p/4812195#M1099413</link>
      <description>&lt;P&gt;Hello, MHM:&lt;/P&gt;&lt;P&gt;They all level 6, starting with %FTD-6-43000x, and I remember you change change what level of the syslog you want, that will not change syslog destination port.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 21:00:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-change-intrusion-event-syslog-port-from-514-to-1515/m-p/4812195#M1099413</guid>
      <dc:creator>jameslee43329</dc:creator>
      <dc:date>2023-04-11T21:00:06Z</dc:date>
    </item>
    <item>
      <title>Re: how to change intrusion event syslog port from 514 to 1515</title>
      <link>https://community.cisco.com/t5/network-security/how-to-change-intrusion-event-syslog-port-from-514-to-1515/m-p/4812207#M1099414</link>
      <description>&lt;H3 id="configure-syslog-alerting-for-intrusion-events"&gt;Configure Syslog Alerting for Intrusion Events&lt;/H3&gt;
&lt;P&gt;You must configure syslog alerting for intrusion events.&lt;/P&gt;
&lt;P&gt;To do so, follow Cisco's documentation at:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Configuring_External_Alerting_for_Intrusion_Rules.html#ID-2212-000001bf" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Configuring_External_Alerting_for_Intrusion_Rules.html#ID-2212-000001bf&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This configuration shows the event ids 430001, 430002, and 430003 in your syslog settings, and sends them to InsightIDR for parsing.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 21:00:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-change-intrusion-event-syslog-port-from-514-to-1515/m-p/4812207#M1099414</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2023-04-11T21:00:33Z</dc:date>
    </item>
    <item>
      <title>Re: how to change intrusion event syslog port from 514 to 1515</title>
      <link>https://community.cisco.com/t5/network-security/how-to-change-intrusion-event-syslog-port-from-514-to-1515/m-p/4812234#M1099416</link>
      <description>&lt;P&gt;Thanks MHM:&lt;/P&gt;&lt;P&gt;I don't see there is any requirement to setup for MID 430002 and 430003, only for 430001, there is no specific explanation&amp;nbsp; what facility should be used? will local4 or syslog use different destination port?&lt;/P&gt;&lt;P&gt;Changed snort2 for IDS policy in advanced setting, change facility, no help!&lt;/P&gt;&lt;P&gt;regards,&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;</description>
      <pubDate>Tue, 11 Apr 2023 23:50:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-change-intrusion-event-syslog-port-from-514-to-1515/m-p/4812234#M1099416</guid>
      <dc:creator>jameslee43329</dc:creator>
      <dc:date>2023-04-11T23:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: how to change intrusion event syslog port from 514 to 1515</title>
      <link>https://community.cisco.com/t5/network-security/how-to-change-intrusion-event-syslog-port-from-514-to-1515/m-p/4812325#M1099419</link>
      <description>&lt;P&gt;So you have syslog Server setup done using 1515&lt;/P&gt;
&lt;P&gt;your Syslog server can able receive the messages&amp;nbsp;&lt;SPAN&gt;message ID (430002, and 430003) ? but not 430001 ? Please confirm this&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;and give more details what is the device model/ what FTD version running. is this managed by&amp;nbsp; FMC?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;can you post the screenshot of the Syslog server config?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 01:00:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-change-intrusion-event-syslog-port-from-514-to-1515/m-p/4812325#M1099419</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-04-12T01:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: how to change intrusion event syslog port from 514 to 1515</title>
      <link>https://community.cisco.com/t5/network-security/how-to-change-intrusion-event-syslog-port-from-514-to-1515/m-p/4812357#M1099421</link>
      <description>&lt;P&gt;I just tested this and it works fine:&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-04-11 at 19.57.44.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/181589iBA649843C2B2F335/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2023-04-11 at 19.57.44.png" alt="Screenshot 2023-04-11 at 19.57.44.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-04-11 at 19.59.04.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/181590iF35590974F9C452E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2023-04-11 at 19.59.04.png" alt="Screenshot 2023-04-11 at 19.59.04.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;The port will be reflected on&amp;nbsp;/var/sf/detection_engines/xxxxxx/ids_alert.conf&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-04-11 at 20.00.10.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/181592i2040FBE89827A819/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2023-04-11 at 20.00.10.png" alt="Screenshot 2023-04-11 at 20.00.10.png" /&gt;&lt;/span&gt;&lt;BR /&gt;Just make sure you are running a version with the fix for&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvt13301" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvt13301&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 02:02:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-change-intrusion-event-syslog-port-from-514-to-1515/m-p/4812357#M1099421</guid>
      <dc:creator>Gustavo Medina</dc:creator>
      <dc:date>2023-04-12T02:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: how to change intrusion event syslog port from 514 to 1515</title>
      <link>https://community.cisco.com/t5/network-security/how-to-change-intrusion-event-syslog-port-from-514-to-1515/m-p/4812972#M1099449</link>
      <description>&lt;P&gt;Hi, Gustavo and MHM:&lt;/P&gt;&lt;P&gt;After removed IP address in logging hosts in snort2, that fixed the issue, I think there was too much influences on snort2 documentation, and I could see the pain from snort2 to snort3, platform setting is the better choice. and thanks for the help.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Apr 2023 15:44:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-change-intrusion-event-syslog-port-from-514-to-1515/m-p/4812972#M1099449</guid>
      <dc:creator>jameslee43329</dc:creator>
      <dc:date>2023-04-12T15:44:43Z</dc:date>
    </item>
  </channel>
</rss>

