cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5521
Views
15
Helpful
3
Replies

Reporting for firepower and log retention

marine253
Level 1
Level 1

Hello , 

My customer is planning to purchase 2 Cisco Firepower 4120 with IPS. 

 

I got confused regarding logging/reporting. We need to store logs for 1 year because of compliance.

 

We need reporting for the firepower ( IPS,firewall -Allow/Deny,Malware etc..).

 

Is the Firepower management center enough for the above? Or is another product required?

 

Thanks

1 Accepted Solution

Accepted Solutions

You get reports from the FMC, you set up the report you need and the FMC will generate that. 

 

But as firewalls generate a lot of log I would recommend to send it of to a syslog server for storage. FMC is not really suitable for log storage over time.

 

Plus side with sending syslog to a log server is that if you use for example spunk it is easier to correlate with other products that would send logs there as well. 

 

HTH

View solution in original post

3 Replies 3

You get reports from the FMC, you set up the report you need and the FMC will generate that. 

 

But as firewalls generate a lot of log I would recommend to send it of to a syslog server for storage. FMC is not really suitable for log storage over time.

 

Plus side with sending syslog to a log server is that if you use for example spunk it is easier to correlate with other products that would send logs there as well. 

 

HTH

thanks. Will look into the syslog option too.

AlexPi
Level 1
Level 1

As far as I am aware you cannot add within a time frame how long back the logs go, you can specify by number of events, per type. Also the local database is limited as to how many events per type it can hold, depending on the device: 
https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118012-troubleshoot-firesight-00.html

https://www.cisco.com/c/en/us/td/docs/security/firesight/541/user-guide/FireSIGHT-System-UserGuide-v5401/System-Policy.html#pgfId-801...

 

Note that if you go close to the limits or surpass them it can cause the FMC to slow down as well, in some cases.

 

Ideally you would want to use an external database and a third party logging tool (Splunk, etc.).

 

Hope this helps.

------------------------------------------------------------------
If this was helpful, please vote as helpful by clicking on the star icon below.
-------------------------------------
Review Cisco Networking for a $25 gift card