04-02-2020 09:51 AM
HI Community, i am curious how everyone else is handling the realtime logging of FTD traffic to assist in troubleshooting a deployment? We already have a siem but I am more interested in the immediate feedback like ASDM gave you. My initial thought was local syslog server installed on your pc. I then thought it might be easier to use a central server that everyone has access to in order to see real time logs.
04-02-2020 10:29 AM
How are you managing FTD using FMC, if your Access rule enabled the Logging, you can view real time on FMC ?
you can also do with FDM :
04-02-2020 11:27 AM
I meant more so that permit deny behavior that ASDM gave you in the asdm log viewer. It would be managed by an FMC not FDM.
04-03-2020 07:23 AM
From FMC you can view the Log events, not as expected like ASDM, it was small delay that was designed to work for now.
04-02-2020 12:42 PM
Hi,
I think this is a very good question, even if it's true that there are other options to inspect logs it's also true that these methods are not as immediate as ASDM real time view is.
Also connection events in FMC are not realtime and FMC is much slower than ASDM and the question is about troubleshooting so it means you need something fast like 1...2...3 check :)
I wish there would be an option for local log view directly on the FTD, just to offload the FMC
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide