<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I think its actually the in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-rule-connection-logging-to-syslog-question/m-p/3063120#M43038</link>
    <description>&lt;P&gt;I think its actually the sensor that will forward the connection event via syslog. I checked this in the lab with 6.2.0 and saw that syslog was sent directly and not from the FMC.&lt;/P&gt;</description>
    <pubDate>Sun, 19 Mar 2017 20:32:50 GMT</pubDate>
    <dc:creator>Oliver Kaiser</dc:creator>
    <dc:date>2017-03-19T20:32:50Z</dc:date>
    <item>
      <title>Firepower rule (connection) logging to Syslog question</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rule-connection-logging-to-syslog-question/m-p/3063118#M43036</link>
      <description>&lt;P&gt;Firepower rule (connection) logging to Syslog:&amp;nbsp; When configuring a rule and 'Send Connection Events to', and Syslog is selected, what is source IP of the host sending the Syslog message?&amp;nbsp; Is it the IP of the Firepower Management Center, or the source IP from the connection itself being logged?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:47:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rule-connection-logging-to-syslog-question/m-p/3063118#M43036</guid>
      <dc:creator>corpengineer818</dc:creator>
      <dc:date>2019-03-10T13:47:58Z</dc:date>
    </item>
    <item>
      <title>Your FirePOWER Management</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rule-connection-logging-to-syslog-question/m-p/3063119#M43037</link>
      <description>&lt;P&gt;Your &lt;SPAN style="text-decoration: line-through;"&gt;FirePOWER Management Center interface&lt;/SPAN&gt;&amp;nbsp;sensor's address will be the source IP in the syslog message header. The body of the message should have the addresses specific to the connection record.&lt;/P&gt;</description>
      <pubDate>Sun, 19 Mar 2017 20:32:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rule-connection-logging-to-syslog-question/m-p/3063119#M43037</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-03-19T20:32:49Z</dc:date>
    </item>
    <item>
      <title>I think its actually the</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rule-connection-logging-to-syslog-question/m-p/3063120#M43038</link>
      <description>&lt;P&gt;I think its actually the sensor that will forward the connection event via syslog. I checked this in the lab with 6.2.0 and saw that syslog was sent directly and not from the FMC.&lt;/P&gt;</description>
      <pubDate>Sun, 19 Mar 2017 20:32:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rule-connection-logging-to-syslog-question/m-p/3063120#M43038</guid>
      <dc:creator>Oliver Kaiser</dc:creator>
      <dc:date>2017-03-19T20:32:50Z</dc:date>
    </item>
    <item>
      <title>Thanks for the correction</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rule-connection-logging-to-syslog-question/m-p/3063121#M43039</link>
      <description>&lt;P&gt;Thanks for the correction Oliver. An ounce of data is more valuable than a pound of conjecture.&lt;/P&gt;
&lt;P&gt;I updated my earlier reply accordingly.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2017 02:04:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rule-connection-logging-to-syslog-question/m-p/3063121#M43039</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-03-20T02:04:51Z</dc:date>
    </item>
    <item>
      <title>That makes a lot more sense</title>
      <link>https://community.cisco.com/t5/network-security/firepower-rule-connection-logging-to-syslog-question/m-p/3063122#M43040</link>
      <description>&lt;P&gt;That makes a lot more sense (that&amp;nbsp;the source&amp;nbsp;is the device/sensor).&amp;nbsp; Wasn't seeing anything logged from the FMC.&amp;nbsp; I'll adjust my firewall rules to allow the sensor, and this should work now.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2017 18:22:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-rule-connection-logging-to-syslog-question/m-p/3063122#M43040</guid>
      <dc:creator>corpengineer818</dc:creator>
      <dc:date>2017-03-20T18:22:30Z</dc:date>
    </item>
  </channel>
</rss>

