<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic If the syslog server is in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sourcefire-s-log-didn-t-send-to-syslog-server/m-p/2987449#M43621</link>
    <description>&lt;P&gt;If the syslog server is running with linux , you could use tcpdump command to make sure , is sourcefire not sending syslog , or the server syslog deamon not work?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;if it's running with windows, you could use wireshark for&amp;nbsp;&amp;nbsp;figure out.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Sep 2016 02:56:38 GMT</pubDate>
    <dc:creator>Hoyeh Tsai</dc:creator>
    <dc:date>2016-09-05T02:56:38Z</dc:date>
    <item>
      <title>Sourcefire 's log didn't send to syslog server</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-s-log-didn-t-send-to-syslog-server/m-p/2987448#M43620</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Dears&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I have Cisco AMP 8150(5.4.0.1) + Virtual Firepower Management Center Data(5.4.0-763)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;When I apply to device,and complete. my syslog server s&lt;/SPAN&gt;&lt;SPAN&gt;&lt;SPAN&gt;uccess received log.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;But &lt;SPAN&gt;short time&lt;/SPAN&gt;,mybe 1min,10min,30min...my syslog server not &lt;SPAN&gt;received log.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;untill I apply to device and complete again......&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Please HELP Me....&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks a lot &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;IMG src="http://i.imgur.com/E6pfov3.png" alt="" height="296" width="1039" /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;IMG src="http://i.imgur.com/B8dnrms.png" alt="" height="396" width="1039" /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;IMG src="http://i.imgur.com/qDSSy4z.png" alt="" height="491" width="1039" /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;IMG src="http://i.imgur.com/Dt5a4bN.png" alt="" height="478" width="1039" /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;IMG src="http://i.imgur.com/yCVn6No.png" alt="" height="453" width="1039" /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:40:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-s-log-didn-t-send-to-syslog-server/m-p/2987448#M43620</guid>
      <dc:creator>Bill_Yang1227</dc:creator>
      <dc:date>2019-03-10T13:40:35Z</dc:date>
    </item>
    <item>
      <title>If the syslog server is</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-s-log-didn-t-send-to-syslog-server/m-p/2987449#M43621</link>
      <description>&lt;P&gt;If the syslog server is running with linux , you could use tcpdump command to make sure , is sourcefire not sending syslog , or the server syslog deamon not work?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;if it's running with windows, you could use wireshark for&amp;nbsp;&amp;nbsp;figure out.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Sep 2016 02:56:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-s-log-didn-t-send-to-syslog-server/m-p/2987449#M43621</guid>
      <dc:creator>Hoyeh Tsai</dc:creator>
      <dc:date>2016-09-05T02:56:38Z</dc:date>
    </item>
    <item>
      <title>In fact,I have two syslog.</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-s-log-didn-t-send-to-syslog-server/m-p/2987450#M43623</link>
      <description>&lt;P&gt;In fact,I have two syslog.&lt;/P&gt;
&lt;P&gt;one syslog server run HP arcsight.&lt;/P&gt;
&lt;P&gt;another run 3CDaemon on windows is for test.&lt;/P&gt;
&lt;P&gt;Two syslog server &lt;SPAN id="result_box" class="short_text" lang="en"&gt;&lt;SPAN class=""&gt;situation&lt;/SPAN&gt;&lt;/SPAN&gt; are same.....&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Sep 2016 03:32:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-s-log-didn-t-send-to-syslog-server/m-p/2987450#M43623</guid>
      <dc:creator>Bill_Yang1227</dc:creator>
      <dc:date>2016-09-05T03:32:21Z</dc:date>
    </item>
    <item>
      <title>Could you see the log from</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-s-log-didn-t-send-to-syslog-server/m-p/2987451#M43624</link>
      <description>&lt;P&gt;Could you see the log from connection and intrusion analysis?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if it work , accroding to your pic, i think your are config fine.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;just make sure you've deploy the policy ,&amp;nbsp;and no firewall between sensor and syslog server,&lt;/P&gt;
&lt;P&gt;or open nessery port.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;if you do so , and still no log, i think you should open a case for troubleshooting.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2016 02:59:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-s-log-didn-t-send-to-syslog-server/m-p/2987451#M43624</guid>
      <dc:creator>Hoyeh Tsai</dc:creator>
      <dc:date>2016-09-06T02:59:56Z</dc:date>
    </item>
  </channel>
</rss>

