08-22-2018 10:03 PM - edited 03-12-2019 06:54 AM
Hello ,
My customer is planning to purchase 2 Cisco Firepower 4120 with IPS.
I got confused regarding logging/reporting. We need to store logs for 1 year because of compliance.
We need reporting for the firepower ( IPS,firewall -Allow/Deny,Malware etc..).
Is the Firepower management center enough for the above? Or is another product required?
Thanks
Solved! Go to Solution.
08-22-2018 11:17 PM
You get reports from the FMC, you set up the report you need and the FMC will generate that.
But as firewalls generate a lot of log I would recommend to send it of to a syslog server for storage. FMC is not really suitable for log storage over time.
Plus side with sending syslog to a log server is that if you use for example spunk it is easier to correlate with other products that would send logs there as well.
HTH
08-22-2018 11:17 PM
You get reports from the FMC, you set up the report you need and the FMC will generate that.
But as firewalls generate a lot of log I would recommend to send it of to a syslog server for storage. FMC is not really suitable for log storage over time.
Plus side with sending syslog to a log server is that if you use for example spunk it is easier to correlate with other products that would send logs there as well.
HTH
08-23-2018 05:27 AM
thanks. Will look into the syslog option too.
08-23-2018 02:21 AM - edited 08-23-2018 02:22 AM
As far as I am aware you cannot add within a time frame how long back the logs go, you can specify by number of events, per type. Also the local database is limited as to how many events per type it can hold, depending on the device:
https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118012-troubleshoot-firesight-00.html
https://www.cisco.com/c/en/us/td/docs/security/firesight/541/user-guide/FireSIGHT-System-UserGuide-v5401/System-Policy.html#pgfId-801...
Note that if you go close to the limits or surpass them it can cause the FMC to slow down as well, in some cases.
Ideally you would want to use an external database and a third party logging tool (Splunk, etc.).
Hope this helps.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide