02-12-2024 09:39 AM
As the title asks - I'm not referring to the FTD sending traffic (I know it does), I am wondering if there is a way for the FMC to relay the connection events in its internal buffer?
I see Audit Logs allow my to forward syslog messages. I can't seem to figure it out for traffic though.
02-12-2024 10:06 AM
When creating the Access Polocy that has option to log - that you can send the logs to external.
or you looking once the logs send to FMC, from FMC you like to send all the logs to external ?
you can do from FMC platform settings to send logs to External
02-12-2024 10:07 AM
02-12-2024 10:23 AM
Both these responses show the FTD sending the event traffic directly to the siem/syslog. In my example, I am wondering if the FMC can relay connection event logs directly to the siem.
02-12-2024 11:57 AM
Not over syslog. You can send over eStreamer protocol and this is a pull model, i.e. external eStreamer client can pull connection and other events from FMC:
FTD (SNORT) -> FTD Unified File -> sftunnel -> FMC SFDataCorrelator -> FMC Database -> Pruning (Retention)
|
+----> eStreamer archive files <--- pull --- eStreamer client
02-12-2024 12:03 PM
Are you sure fmc can send event directly to syslog ?
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide