cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
230
Views
2
Helpful
1
Replies

Change facility for intrution event logs via LinaConfigTool on FTD

Pennerborn
Level 1
Level 1

Hello,

I'm trying to change the facility via LinaConfigTool on a Cisco 2100 FTD, 7.0 for intrution event logs. 

I've used this command to change the facility for syslogs:

/usr/local/sf/bin/LinaConfigTool "logging facility 19"

Is there any similar for intrution event logs? Or can you do it any other way without FMC?

 

Kind regards,

Tom Pennerborn

1 Accepted Solution

Accepted Solutions

Pennerborn
Level 1
Level 1

I've found the soulution

In the file /ngfw/var/sf/detection_engines/YOUR-OWN/ids_alert.conf

Under intrution change facility to one from this document: external_alerting_for_intrusion_events.pdf (cisco.com)

 

View solution in original post

1 Reply 1

Pennerborn
Level 1
Level 1

I've found the soulution

In the file /ngfw/var/sf/detection_engines/YOUR-OWN/ids_alert.conf

Under intrution change facility to one from this document: external_alerting_for_intrusion_events.pdf (cisco.com)