cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1732
Views
15
Helpful
2
Replies

Can we use FMC as a syslog server for managed sensors?

matty-boy
Level 1
Level 1

Hi all,

 

We have a customer with an FMC/FTD deployment. They currently have no central syslog service to send syslogs from the FTDs.

 

FMC is good at storing security related logs but what about infrastructure logs generated by FTDs (routing peer or physical link up/down, admin made a config change, etc)? Is there any way we can send these sorts of logs to the FMC as a central syslog server?

 

Thanks in advance,

Matt.

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

I don't think so.

 

Normally, events sent from the sensors get to FMC via the eventing interface which uses TLS over tcp/8302.

 

Syslog would require the FMC to be listening on udp/514 (which it does not) and be able to store, parse and display syslog message format.

View solution in original post

2 Replies 2

Marvin Rhoads
Hall of Fame
Hall of Fame

I don't think so.

 

Normally, events sent from the sensors get to FMC via the eventing interface which uses TLS over tcp/8302.

 

Syslog would require the FMC to be listening on udp/514 (which it does not) and be able to store, parse and display syslog message format.

Thank you for confirming my suspicion Marvin. 

Review Cisco Networking for a $25 gift card