Connection Event Send to External Syslog Server
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-24-2020 01:41 AM
Can anyone help me on connection event's on FTD 6.4.0.We configured the eStremer and selected connection events as well but on external server i am not getting connection event log , only received IPS logs.I need complete log like source ip , destinatiopn ip , port no. , deny or allow web application , url.
How to send our connection event log to external syslog server ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
06-24-2020 04:57 AM
eStreamer is not syslog but rather a unique messaging format. If you want to send syslogs for connection events externally then you need to define your syslog server and related settings under Devices > Platform Settings > Syslog. Then in your Access Control Policy choose to send events as syslog either globally for the ACP or for individual entries.
