<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Firepower URL Logging to Syslog in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-url-logging-to-syslog/m-p/3405585#M44067</link>
    <description>&lt;P&gt;Was there ever a solution found for this?&lt;/P&gt;
&lt;P&gt;We are experiencing the same problem... basically only blocked traffic is being sent to our Syslog server, and our Defense Center logs roll fairly quickly so troubleshooting is nearly impossible.&lt;/P&gt;</description>
    <pubDate>Tue, 26 Jun 2018 12:28:24 GMT</pubDate>
    <dc:creator>dncl</dc:creator>
    <dc:date>2018-06-26T12:28:24Z</dc:date>
    <item>
      <title>Firepower URL Logging to Syslog</title>
      <link>https://community.cisco.com/t5/network-security/firepower-url-logging-to-syslog/m-p/2886635#M44063</link>
      <description>&lt;P&gt;Would appreciate if someone could give me a pointer.&lt;/P&gt;
&lt;P&gt;I have a 5525X running Firepower (Protection, URL, Malware and Control licence). I have a basic Access Contol policy with a few URL's Categories defined and a seperate URL I defined for testing. I have a default policy underneath that calls a base Intrusion policy. The URL policy and Base Intrusion policy are set to Log to a syslog server.&lt;/P&gt;
&lt;P&gt;I don't see URL's logged on the syslog although they do appear in the Management Centre. The IPS policies log to the syslog.&lt;/P&gt;
&lt;P&gt;The Access Control policy does have the syslog defined and the box for 'log at the beginning of the connection' is checked. I went thought the config guide (v6.X) and picked out those items that referred to syslog. I'm not sure why the URL logging isn't working.&lt;/P&gt;
&lt;P&gt;All I want to see is the URL's (IP and URL info) information on the syslog, currently syslog is set to facility: Local 1 and severity: info as requested by my Linux admin.&lt;/P&gt;
&lt;P&gt;Note the device is in monitor mode only at present.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Darren&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:35:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-url-logging-to-syslog/m-p/2886635#M44063</guid>
      <dc:creator>darreng</dc:creator>
      <dc:date>2019-03-10T13:35:32Z</dc:date>
    </item>
    <item>
      <title>Try making a rule at the very</title>
      <link>https://community.cisco.com/t5/network-security/firepower-url-logging-to-syslog/m-p/2886636#M44065</link>
      <description>&lt;P&gt;Try making a rule at the very top of your access control policy with the action of "Monitor".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Under the URL tab you add a single URL like "dummy.url".&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Remember to log to both event viewer and syslog. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2016 17:55:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-url-logging-to-syslog/m-p/2886636#M44065</guid>
      <dc:creator>Dennis Perto</dc:creator>
      <dc:date>2016-11-17T17:55:51Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower URL Logging to Syslog</title>
      <link>https://community.cisco.com/t5/network-security/firepower-url-logging-to-syslog/m-p/3405585#M44067</link>
      <description>&lt;P&gt;Was there ever a solution found for this?&lt;/P&gt;
&lt;P&gt;We are experiencing the same problem... basically only blocked traffic is being sent to our Syslog server, and our Defense Center logs roll fairly quickly so troubleshooting is nearly impossible.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jun 2018 12:28:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-url-logging-to-syslog/m-p/3405585#M44067</guid>
      <dc:creator>dncl</dc:creator>
      <dc:date>2018-06-26T12:28:24Z</dc:date>
    </item>
  </channel>
</rss>

