<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FMC Logging Best Practises in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-logging-best-practises/m-p/3372188#M924032</link>
    <description>&lt;P&gt;Thanks Mikael, very helpful!&lt;/P&gt;</description>
    <pubDate>Tue, 24 Apr 2018 19:20:39 GMT</pubDate>
    <dc:creator>de1denta</dc:creator>
    <dc:date>2018-04-24T19:20:39Z</dc:date>
    <item>
      <title>FMC Logging Best Practises</title>
      <link>https://community.cisco.com/t5/network-security/fmc-logging-best-practises/m-p/3370030#M924030</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I just wanted to check what the best practises are with logging against access control policy rules, specifically logging at the beginning of a connection vs logging at the end of a connection? I know that its not recommend to log both beginning and the end to reduce the number of connection events.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also understand that blocked rules should log at the beginning of a connection as there is no end connection, however, with trust and allowed rules that we use (and that we need to log for compliance reasons) is there a preference to use one over the other?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:39:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-logging-best-practises/m-p/3370030#M924030</guid>
      <dc:creator>de1denta</dc:creator>
      <dc:date>2020-02-21T15:39:31Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Logging Best Practises</title>
      <link>https://community.cisco.com/t5/network-security/fmc-logging-best-practises/m-p/3372148#M924031</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;Logging at the end of connection will give more information about the connection.&lt;BR /&gt;Don't know if there is a best practices except the one you wrote, not to log both.&lt;BR /&gt;As the FMC event logging rotates fast I would try to log as little as possible in the connection event just for troubleshooting purposes and use external logging for archive.&lt;BR /&gt;Read somewhere that maybe disable logging for DNS request if that is not important for you, as DNS pretty log heavy.&lt;BR /&gt;&lt;BR /&gt;Here is some more information about logging:&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/601/configuration/guide/fpmc-config-guide-v601/Connection_Logging.pdf" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/601/configuration/guide/fpmc-config-guide-v601/Connection_Logging.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://supportforums.cisco.com/t5/firesight-system-3d-system/logging-recommendations/td-p/2895705" target="_blank"&gt;https://supportforums.cisco.com/t5/firesight-system-3d-system/logging-recommendations/td-p/2895705&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;br, Micke&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 17:50:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-logging-best-practises/m-p/3372148#M924031</guid>
      <dc:creator>mikael.lahtela</dc:creator>
      <dc:date>2018-04-24T17:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Logging Best Practises</title>
      <link>https://community.cisco.com/t5/network-security/fmc-logging-best-practises/m-p/3372188#M924032</link>
      <description>&lt;P&gt;Thanks Mikael, very helpful!&lt;/P&gt;</description>
      <pubDate>Tue, 24 Apr 2018 19:20:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-logging-best-practises/m-p/3372188#M924032</guid>
      <dc:creator>de1denta</dc:creator>
      <dc:date>2018-04-24T19:20:39Z</dc:date>
    </item>
  </channel>
</rss>

