12-17-2023 04:08 PM - edited 12-19-2023 03:21 PM
I am currently working on sending Syslog alerts (events from the FTD rules) to Elastic SIEM, and I've been tasked with using TCP for this purpose. However, I couldn't find the TCP option in the FMC settings.
I thoroughly checked the official Cisco documentation at the following link: Cisco Documentation, specifically in Step 5 under "Creating a Syslog Alert Response" where you define the port number. Unfortunately, the documentation does not provide information on whether TCP is an available option.
I would greatly appreciate your assistance in clarifying whether TCP is indeed an option for Syslog alerts and, if so, how to configure it. Your insights and guidance on this matter would be invaluable.
Thank you in advance for your help.
12-17-2023 04:35 PM - edited 12-17-2023 04:35 PM
@Praveen Kumar hi, check this guide. when you adding syslog server, select the protocol.
Configure Logging on FTD via FMC - Cisco
12-19-2023 03:24 PM
Sorry, the link in my post was broken which I have already fixed. You can check that document then it will make more sense. These settings are for the firewall rules and not the platform. Thanks for your response.
12-18-2023 05:50 AM
Are you trying to send syslog from the FMC or from the FTD? If you are sending from FTD then the configuration is in platform settings under the syslog tab. When setting up syslog server destination there you will have the option to choose UDP or TCP for transport.
12-19-2023 03:25 PM
Sorry, the link in my post was broken which I have already fixed. You can check that document then it will make more sense. These settings are for the firewall rules and not the platform. Thanks for your response.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide