cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
925
Views
0
Helpful
3
Replies

FireSight logs

kashifglobal12
Level 1
Level 1

Hello All,

I have one fmc on which 5 sourcefire is added. My question is how many logs can fmc Store from each sourcefire. And if we have external syslog server which retrieve logs from fmc does this effect reporting on fmc because all the events like user activity, malware and etc will be maintain in external syslog server?

 

Thank you.... 

3 Replies 3

mikael.lahtela
Level 4
Level 4

Hi,

FMC has a shared database for different logging.
You can find the number of event logged under System>Configuration>Database.
Here you can find the limitations:
https://www.cisco.com/c/en/us/products/collateral/security/firesight-management-center/datasheet-c78-736775.html?cachemode=refresh

 

Not sure about what you are thinking about the syslog vs reporting, can you elaborate on that?


br, Mikael

Hi Mikael,

What i thinking is that fmc make reports(Dashboard, overview) on basis of
logs created as events. right ! So if we maintain logs or events on
external syslog server will this effect reporting or dashboard information
because logs are maintaining not on fmc but on external syslog server?

Hi,

The reports will only show what is logged in the fmc database.
It will not keep track on what has been sent to an external syslog.

br, Mikael
Review Cisco Networking for a $25 gift card