cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
413
Views
0
Helpful
1
Replies

Best Cisco Logs for SIEM Nexus OS Switches

kabip7
Level 1
Level 1

I have been asked by our Security Team to send my Logs to a Syslog server for them to keep data. When i asked them what Logs they would like they said "Send us the Logs" When i asked what Facility logs they wanted they said all the buildings. The Suborn part of me wants to just go set level 7 on all logs and send them to them and fill their Syslog server up. But at the same time it will mess up my logging, What logs do you send to your Security team to keep them happy and at what level?

1 Reply 1

balaji.bandi
Hall of Fame
Hall of Fame

Its all depends what you like to achieve, and depends on the device models like router / FW /. Switches / WLC so on the list go on.

SIEM is planning what logs to monitor to get out of the product best to achieve.

exmaple : we setup a all the logs, you may have 1000 of logs, but in between you may have 1 log that is important, so take time to analyse that, instead, first send all logs and then trim down what logs you do not need to send from your syslog to SIEM product.

Example i use Graylog - we do pipeline stream the Logs based on the inputs.

there is good video :

https://www.youtube.com/watch?v=6pEK0rlsCMk

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Solutions Engineer Joel Duffield runs you through the important food for your SIEM. Planning to feed your first SIEM? There are many things to think about and in this video you will be able to see some of the considerations you could make when sending data to your Log Management and SIEM.