cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1580
Views
0
Helpful
2
Replies

Cisco ASA 5500x Firepower IPS Logging

Ralphy006
Level 1
Level 1

Anyone know how Cisco ASA 5500x firepower logging works?

Based on the cisco manuals: " For ASA FirePOWER-related syslog messages, see the syslog messages guide. ASA FirePOWER syslog messages start with message number 434001"

That suggests it just talks syslog.

Anyone know if that's all it does? Or does it do SDEE like the old Cisco IPS modules?

2 Replies 2

Marvin Rhoads
Hall of Fame
Hall of Fame

Firepower logging is to a Firesight management center (FMC) via https. It does not use SDEE.

Just like the old IPS, syslog messages are only about the module status, not about actual IPS events.

Thanks Marvin, do you know what the data retention is on the FMC? Can it be set to unlimited? (assuming unlimited storage on the FMC server)

Review Cisco Networking for a $25 gift card