cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1004
Views
0
Helpful
2
Replies

appl logging to multiple rules

stuart.rock
Level 1
Level 1

Hi,

looking for some help.

i am working on a firewall with 750 rules. most of these rules are not set to log.

is there any way to apply logging (at end) to a select bunch of rules in one hit. or am i looking at clicking 750 rules one at a time to switch logging on.

also when logging is enabled (to event viewer) is this held in FMC? i want to send all rule hits to a syslog server - do i need to enable this per rule - as above? or will FMC do that for me?

thanks in advance

2 Replies 2

Abheesh Kumar
VIP Alumni
VIP Alumni
Hi,
There is no such option to edit multiple rules in a single shot. You need to edit each rule and enable logging.
You can configure syslog server from the Device > Platform Setting > Threat Defense Policy > Syslog
https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200479-Configure-Logging-on-FTD-via-FMC.html

Thanks,
Abheesh
PS: Please don't forget to rate and select as validated answer if this answered your question.

iabualna
Cisco Employee
Cisco Employee

There is no such option to edit multiple rules in a single shot, as mentioned by Abheesh. We have the ENH below for the same:

"https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe32569

"ENH: Add option to enable Syslog on all Access Control Policies rules"

 
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card