cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1952
Views
10
Helpful
4
Replies

Firepower rule (connection) logging to Syslog question

corpengineer818
Level 1
Level 1

Firepower rule (connection) logging to Syslog:  When configuring a rule and 'Send Connection Events to', and Syslog is selected, what is source IP of the host sending the Syslog message?  Is it the IP of the Firepower Management Center, or the source IP from the connection itself being logged?

Thank you.

4 Replies 4

Marvin Rhoads
Hall of Fame
Hall of Fame

Your FirePOWER Management Center interface sensor's address will be the source IP in the syslog message header. The body of the message should have the addresses specific to the connection record.

I think its actually the sensor that will forward the connection event via syslog. I checked this in the lab with 6.2.0 and saw that syslog was sent directly and not from the FMC.

Thanks for the correction Oliver. An ounce of data is more valuable than a pound of conjecture.

I updated my earlier reply accordingly. 

corpengineer818
Level 1
Level 1

That makes a lot more sense (that the source is the device/sensor).  Wasn't seeing anything logged from the FMC.  I'll adjust my firewall rules to allow the sensor, and this should work now. 

Thank you.

Review Cisco Networking for a $25 gift card