cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1491
Views
0
Helpful
1
Replies

Firepower management center and non-standard syslog ports for audit logs and Intrusion events

mbisko
Level 1
Level 1

Hi,

I'm trying to figure out how to log audit logs [System->Configuration-Audit log] and IPS policy alerts [Intrusion policy->Advanced->Syslog Alerting] to external syslog using non-standard syslog ports or more sysolog servers.

Namely in audit logs section I cannot specify more then one syslog server and cannot specify non-standard IPS port. Is there any way how to accomplish this?

Thanks for help.

Martin

1 Reply 1

Oliver Kaiser
Level 7
Level 7

This is not possible at the moment. A feature request exists for this issue (CSCvb61559). A possible workaround is listed for IPS logging. 

Review Cisco Networking for a $25 gift card