04-27-2022 07:15 AM - edited 04-27-2022 07:15 AM
Dear Community,
We have IPS (Inspection) enabled on several of our rules in our Access Control Policy. Eventhough we can see the intrusion events in Analysis -> Intrusions-> Events, we do not see any of these intrusion events in our syslog files. I was doing some reading and came across this article which intimates that the syslog settings are set under the intrusion policy itself:
However, when I look at the intrusion policy, I don't have an "Advanced option" or see anywhere I can enable syslog alerting for intrusion events.
Where do I need to go in the FMC to make sure intrusion events are sent to syslog? We are already sending Connection Events to syslog and have syslog enabled under the platform settings.
Thank you.
04-27-2022 09:49 AM
check below :
04-27-2022 10:17 AM
Balaji,
Thank you for the response. For the life of me I cannot find this section. Can you tell me the exact path of where to find the advanced setting? I am looking at the Advanced settings of the ACP but cannot find this option. I am also not seeing any Advanced settings in the Intrusion Policy either. Running code 7.0.1.1.
Thank you.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide