cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2758
Views
0
Helpful
5
Replies

Basic syslog on FMC and sensor

ebng
Level 1
Level 1

I'm trying to setup my FMC 1000 and FP 7030 sensor to send syslogs to an external server.  All I really want for now is anything that gets populated under System->Monitoring->Syslog.  I don't really care about intrusion alerts or things like that for now.  I tried following the steps under "Sending Health Alerts" from the link below, but that didn't seem to get me anything (and I believe may be just for the sensor anyway):

 

https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118464-configure-firesight-00.html#anc5

 

Any help would be appreciated.

5 Replies 5

babiojd01
Level 1
Level 1

What syslog data are you looking for? Why don't we start with what data you do want sent to syslog. Security Intelligence, SNORT alerts, Fireamp, or Audit data from FMC?

Security Intel is syslog sent from the FTD/FP device itself. Snort Alerts can come through syslog via impact alerts from FMC as well as Network Fireamp.

What I'd like to see is successful and failed logins, logouts, temperature warnings, crash info, things like that, for both my Firepower 7030 sensor and FMC 1000. 

To set up syslog for the FTD appliances go to Devices > Platform Settings > Syslog.

I have attached the configuration I use in my home lab FTD.  Keep in mind that the FTD sends a lot more messages than an ASA does, so you may need to rate limit the messages.  At a client had to rate limit to 4000 messages per second to get it to work properly. This is dependent on which syslog server you are using so check the specifications of your syslog server.

--
Please remember to select a correct answer and rate helpful posts

Hmmm...I'm seeing something different from my FMC.  See attached.  The first screenshot is from Devices->Platform Settings.  The second is after I click the pencil icon next to my policy.  I guess this is because I'm using a "legacy" sensor?

Which version are you running?

--
Please remember to select a correct answer and rate helpful posts
Review Cisco Networking for a $25 gift card