cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4184
Views
7
Helpful
5
Replies

Enable logging using ftd 2100 cli

vishal77
Level 1
Level 1

Hello All,

 

Can anyone help me how can I enable logging using Ssh So that I can collect/view debug logs for real time logs and previous logs like 3-4 days before.

 

Below is the output of my ftd cli

 

firepower# show logging 
Syslog logging: disabled
    Facility: 20
    Timestamp logging: disabled
    Hide Username logging: enabled
    Standby logging: disabled
    Debug-trace logging: disabled
    Console logging: disabled
    Monitor logging: disabled
    Buffer logging: disabled
    Trap logging: disabled
    Permit-hostdown logging: disabled
    History logging: disabled
    Device ID: disabled
    Mail logging: disabled
    ASDM logging: disabled
    FMC logging: list MANAGER_VPN_EVENT_LIST, 99 messages logged
firepower# 

 

5 Replies 5

Hi,

You can do this using FMC or FDM depending on how you manage your unit. You
can't do it directly from FTD CLI.

here are some guides

https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200479-Configure-Logging-on-FTD-via-FMC.html
https://www.cisco.com/c/en/us/td/docs/security/firepower/640/fdm/fptd-fdm-config-guide-640/fptd-fdm-system.html

**** please remember to rate useful posts

Hi,

When enabling logging in FDM (Device Manager not FMC) 'console logging' is enabled and not 'monitor logging'
------------------------------

Syslog logging: enabled
Facility: 20
Timestamp logging: enabled
Timezone: disabled
Hide Username logging: enabled
Standby logging: disabled
Debug-trace logging: disabled
Console logging: level warnings, 2062 messages logged
Monitor logging: disabled
Buffer logging: level warnings, 2062 messages logged
-----------------------------------------------------------------
How can i enable 'monitor logging' via FDM?

When enabling loging in FMC for SSH settings then 'monitor logging' gets enabled.

Did you even do this via CLI?

What about for a 2100 via FMC or CLI I can't find documentation for it?

For all Firepower hardware we can do this via the platform settings in the managing FMC. You can use platform settings for all your managed devices (most common) or have varying ones for different devices if you prefer.

Just follow the link provided earlier by @Mohammed al Baqari or go here directly:

https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200479-Configure-Logging-on-FTD-via-FMC.html#anc11

Review Cisco Networking products for a $25 gift card