<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SourceFire - External Syslog logging in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sourcefire-external-syslog-logging/m-p/3304460#M926299</link>
    <description>The screenshot that I provided is from v6.2.2 but the question was posted for v4. I don't think this option doesn't exists for FirePower but only for FTD.</description>
    <pubDate>Mon, 01 Jan 2018 13:59:23 GMT</pubDate>
    <dc:creator>True Warrior</dc:creator>
    <dc:date>2018-01-01T13:59:23Z</dc:date>
    <item>
      <title>SourceFire - External Syslog logging</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-external-syslog-logging/m-p/3296729#M926291</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Currently we have a customer who has SourceFire v4.10 and would like to configure the SourceFire devices to send syslog alerts to a syslog server. I have checked the Advanced Settings of the IPS Policy and there is no option to define if the syslog alerting should be done via TCP or UDP. Do you know if TCP syslog logging is supported by SourceFire devices.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:57:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-external-syslog-logging/m-p/3296729#M926291</guid>
      <dc:creator>True Warrior</dc:creator>
      <dc:date>2020-02-21T14:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: SourceFire - External Syslog logging</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-external-syslog-logging/m-p/3303552#M926292</link>
      <description>&lt;P&gt;SourceFire is able to log using TCP.&amp;nbsp; You are however using a very old version of Firepower so I am not certain what is supported on that version.&lt;/P&gt;
&lt;P&gt;However, in FMC you need to go to Devices &amp;gt; Platform Settings and create a platform settings policy.&amp;nbsp; In platform settings policy go to syslog and there under the Syslog Servers tab you can add an external syslog server and choose to use either TCP or UDP.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FYI: For us the FTD sends quite a bit of extra logs, so we had to rate limit the logs for the syslog server to start receiving the logs.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Dec 2017 20:24:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-external-syslog-logging/m-p/3303552#M926292</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2017-12-28T20:24:39Z</dc:date>
    </item>
    <item>
      <title>Re: SourceFire - External Syslog logging</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-external-syslog-logging/m-p/3304433#M926293</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I already have a System Policy under Platform Settings and under Audit Log, there isn't an option either to select UDP or TCP, the system by default uses UDP/514.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also I was looking for syslog logging via TCP for the intrusion policy but the Audit Log under Platform Settings is going to send the audit logs of the Operating System.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have created a syslog alert in intrusion policy but there is no where in the system (FMC or managed device) to pick TCP or UDP logging as the default syslog logging of UDP/514 is used.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jan 2018 11:14:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-external-syslog-logging/m-p/3304433#M926293</guid>
      <dc:creator>True Warrior</dc:creator>
      <dc:date>2018-01-01T11:14:56Z</dc:date>
    </item>
    <item>
      <title>Re: SourceFire - External Syslog logging</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-external-syslog-logging/m-p/3304438#M926294</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="logging1.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/5620i7C834514F44291CF/image-size/large?v=v2&amp;amp;px=999" role="button" title="logging1.png" alt="logging1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="logging2.png" style="width: 622px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/5619i2A1375C7A2C93AF4/image-size/large?v=v2&amp;amp;px=999" role="button" title="logging2.png" alt="logging2.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jan 2018 12:02:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-external-syslog-logging/m-p/3304438#M926294</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2018-01-01T12:02:15Z</dc:date>
    </item>
    <item>
      <title>Re: SourceFire - External Syslog logging</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-external-syslog-logging/m-p/3304449#M926295</link>
      <description>Thanks for this, but these aren't FTD devices, they are just FirePower 7000 and 8000 series devices. Can a FTD System Policy still work for just FirePower devices?</description>
      <pubDate>Mon, 01 Jan 2018 12:35:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-external-syslog-logging/m-p/3304449#M926295</guid>
      <dc:creator>True Warrior</dc:creator>
      <dc:date>2018-01-01T12:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: SourceFire - External Syslog logging</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-external-syslog-logging/m-p/3304450#M926296</link>
      <description>&lt;P&gt;Yes this will work also for FirePower.&amp;nbsp; When creating the policy you click New Policy and then select Firepower Settings for FirePower,&amp;nbsp; For FTD you would select Threat Defense Settings.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jan 2018 12:53:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-external-syslog-logging/m-p/3304450#M926296</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2018-01-01T12:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: SourceFire - External Syslog logging</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-external-syslog-logging/m-p/3304451#M926297</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I guess this is what my issue is, creating a FirePower Settings policy doesn't provide the syslog logging for TCP, please check the attached screenshot that I created for one of the FirePower Settings and under audit log settings, I don't have the option to select TCP or UDP so I would assume that its available only for FTD image and not for FirePower only image.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jan 2018 12:59:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-external-syslog-logging/m-p/3304451#M926297</guid>
      <dc:creator>True Warrior</dc:creator>
      <dc:date>2018-01-01T12:59:28Z</dc:date>
    </item>
    <item>
      <title>Re: SourceFire - External Syslog logging</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-external-syslog-logging/m-p/3304453#M926298</link>
      <description>&lt;P&gt;Have you considered upgrading your FirePower software? You are running a very old version and that might be the reason you are not seeing the syslog option in the platform settings policy.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jan 2018 13:15:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-external-syslog-logging/m-p/3304453#M926298</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2018-01-01T13:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: SourceFire - External Syslog logging</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-external-syslog-logging/m-p/3304460#M926299</link>
      <description>The screenshot that I provided is from v6.2.2 but the question was posted for v4. I don't think this option doesn't exists for FirePower but only for FTD.</description>
      <pubDate>Mon, 01 Jan 2018 13:59:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-external-syslog-logging/m-p/3304460#M926299</guid>
      <dc:creator>True Warrior</dc:creator>
      <dc:date>2018-01-01T13:59:23Z</dc:date>
    </item>
  </channel>
</rss>

