cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1324
Views
0
Helpful
3
Replies

How to extract FMC Logs

MSJ1
Level 1
Level 1

Is it possible to extract FMC Logs to a different system ?

3 Replies 3

balaji.bandi
Hall of Fame
Hall of Fame

You mean from FMC to other system - yes possible check by login to FMC and $sudo su give you access to Linux access.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

But what will be the Log file name  I should look for ?

 

Just to be clear , i am referring to the all kind of events ( like Connection events , Intrusion events etc ) I can see from FMC.

As per i know in terms of events they are stored in DB (PostgreSQL- i guess), you can backup them as per the below guide :

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Backup_and_Restore.html

 

You can configure Syslog to an external server to offload them.

 

Most of the other logs stored /var/log

 

 

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Review Cisco Networking products for a $25 gift card