09-01-2016 08:15 AM - edited 03-10-2019 06:40 AM
Dears
I have Cisco AMP 8150(5.4.0.1) + Virtual Firepower Management Center Data(5.4.0-763)
When I apply to device,and complete. my syslog server success received log.
But short time,mybe 1min,10min,30min...my syslog server not received log.
untill I apply to device and complete again......
Please HELP Me....
Thanks a lot
09-04-2016 07:56 PM
If the syslog server is running with linux , you could use tcpdump command to make sure , is sourcefire not sending syslog , or the server syslog deamon not work?
if it's running with windows, you could use wireshark for figure out.
09-04-2016 08:32 PM
In fact,I have two syslog.
one syslog server run HP arcsight.
another run 3CDaemon on windows is for test.
Two syslog server situation are same.....
09-05-2016 07:59 PM
Could you see the log from connection and intrusion analysis?
if it work , accroding to your pic, i think your are config fine.
just make sure you've deploy the policy , and no firewall between sensor and syslog server,
or open nessery port.
if you do so , and still no log, i think you should open a case for troubleshooting.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide