cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
655
Views
0
Helpful
4
Replies

Firepower syslog alerts > Elastic SEIM

Praveen Kumar
Level 1
Level 1

 

I am currently working on sending Syslog alerts (events from the FTD rules) to Elastic SIEM, and I've been tasked with using TCP for this purpose. However, I couldn't find the TCP option in the FMC settings.

I thoroughly checked the official Cisco documentation at the following link: Cisco Documentation, specifically in Step 5 under "Creating a Syslog Alert Response" where you define the port number. Unfortunately, the documentation does not provide information on whether TCP is an available option.

I would greatly appreciate your assistance in clarifying whether TCP is indeed an option for Syslog alerts and, if so, how to configure it. Your insights and guidance on this matter would be invaluable.

Thank you in advance for your help.

 

 

4 Replies 4

@Praveen Kumar hi, check this guide. when you adding syslog server, select the protocol.

Configure Logging on FTD via FMC - Cisco

Please rate this and mark as solution/answer, if this resolved your issue
Good luck
KB

Sorry, the link in my post was broken which I have already fixed. You can check that document then it will make more sense. These settings are for the firewall rules and not the platform. Thanks for your response.

 

Are you trying to send syslog from the FMC or from the FTD?  If you are sending from FTD then the configuration is in platform settings  under the syslog tab.  When setting up syslog server destination there you will have the option to choose UDP or TCP for transport.

--
Please remember to select a correct answer and rate helpful posts

Sorry, the link in my post was broken which I have already fixed. You can check that document then it will make more sense. These settings are for the firewall rules and not the platform. Thanks for your response.

Review Cisco Networking for a $25 gift card