cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1108
Views
0
Helpful
5
Replies

Can the FMC be configured to forward connection events/traffic logs

guacamoley
Level 1
Level 1

As the title asks - I'm not referring to the FTD sending traffic (I know it does), I am wondering if there is a way for the FMC to relay the connection events in its internal buffer?

 

I see Audit Logs allow my to forward syslog messages. I can't seem to figure it out for traffic though.

5 Replies 5

balaji.bandi
Hall of Fame
Hall of Fame

When creating the Access Polocy that has option to log - that you can send the logs to external.

or you looking once the logs send to FMC, from FMC you like to send all the logs to external ?

you can do from FMC platform settings to send logs to External

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

guacamoley
Level 1
Level 1

Both these responses show the FTD sending the event traffic directly to the siem/syslog. In my example, I am wondering if the FMC can relay connection event logs directly to the siem.

Not over syslog. You can send over eStreamer protocol and this is a pull model, i.e. external eStreamer client can pull connection and other events from FMC:

FTD (SNORT) -> FTD Unified File -> sftunnel -> FMC SFDataCorrelator -> FMC Database -> Pruning (Retention)
|
+----> eStreamer archive files <--- pull --- eStreamer client

 https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/admin/710/management-center-admin-71/analysis-external-tools.html

 

Are you sure fmc can send event directly to syslog ?

MHM

Review Cisco Networking for a $25 gift card