cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2140
Views
10
Helpful
7
Replies

cisco sourcefire device

Hi all,

i would like to know how a cisco sourcefire device fetches the syslog itself to another syslog server?

thanks

1 Accepted Solution

Accepted Solutions

It may be a language issue in your question, but the Sourcefire device does not (and cannot) "fetch logs from a syslog server". It can send log messages to a syslog server.

The link Balaji provided describes how to do that. Any syslog server will work as long as it accepts RFC 5424 standard syslog messages.

As far as how it works, the appliance will simply encapsulate the messages in IP packets with destination address of the configured syslog server and destination port of udp/514.

View solution in original post

7 Replies 7

balaji.bandi
Hall of Fame
Hall of Fame

if i understand correctly you looking offload the logs to syslog from sourcefire device (if not please correct me)

 

below guide help you to offload the load to external syslog server :

 

https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118464-configure-firesight-00.html

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi,

i just want the process on how the cisco sourcefire device fetch the log from a syslog server

Hi,

i just want the process on how the cisco sourcefire device fetch the log from a syslog server

 

thanks

which syslog server, can you give more explanation ?

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi ,

the syslog server can be apache linux server or splunk server

It may be a language issue in your question, but the Sourcefire device does not (and cannot) "fetch logs from a syslog server". It can send log messages to a syslog server.

The link Balaji provided describes how to do that. Any syslog server will work as long as it accepts RFC 5424 standard syslog messages.

As far as how it works, the appliance will simply encapsulate the messages in IP packets with destination address of the configured syslog server and destination port of udp/514.

Hi Marvin,

 

thanks you very much of your explanation

Review Cisco Networking for a $25 gift card