cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1066
Views
0
Helpful
2
Replies

appl logging to multiple rules

stuart.rock
Level 1
Level 1

Hi,

looking for some help.

i am working on a firewall with 750 rules. most of these rules are not set to log.

is there any way to apply logging (at end) to a select bunch of rules in one hit. or am i looking at clicking 750 rules one at a time to switch logging on.

also when logging is enabled (to event viewer) is this held in FMC? i want to send all rule hits to a syslog server - do i need to enable this per rule - as above? or will FMC do that for me?

thanks in advance

2 Replies 2

Abheesh Kumar
VIP Alumni
VIP Alumni
Hi,
There is no such option to edit multiple rules in a single shot. You need to edit each rule and enable logging.
You can configure syslog server from the Device > Platform Setting > Threat Defense Policy > Syslog
https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200479-Configure-Logging-on-FTD-via-FMC.html

Thanks,
Abheesh
PS: Please don't forget to rate and select as validated answer if this answered your question.

iabualna
Cisco Employee
Cisco Employee

There is no such option to edit multiple rules in a single shot, as mentioned by Abheesh. We have the ENH below for the same:

"https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwe32569

"ENH: Add option to enable Syslog on all Access Control Policies rules"

 
Review Cisco Networking for a $25 gift card