01-30-2019 12:29 PM - edited 02-21-2020 08:43 AM
Hi all,
We have a customer with an FMC/FTD deployment. They currently have no central syslog service to send syslogs from the FTDs.
FMC is good at storing security related logs but what about infrastructure logs generated by FTDs (routing peer or physical link up/down, admin made a config change, etc)? Is there any way we can send these sorts of logs to the FMC as a central syslog server?
Thanks in advance,
Matt.
Solved! Go to Solution.
01-31-2019 08:47 AM
I don't think so.
Normally, events sent from the sensors get to FMC via the eventing interface which uses TLS over tcp/8302.
Syslog would require the FMC to be listening on udp/514 (which it does not) and be able to store, parse and display syslog message format.
01-31-2019 08:47 AM
I don't think so.
Normally, events sent from the sensors get to FMC via the eventing interface which uses TLS over tcp/8302.
Syslog would require the FMC to be listening on udp/514 (which it does not) and be able to store, parse and display syslog message format.
01-31-2019 09:58 AM
Thank you for confirming my suspicion Marvin.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide