cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1107
Views
0
Helpful
3
Replies

Sourcefire 's log didn't send to syslog server

Bill_Yang1227
Level 1
Level 1

Dears

I have Cisco AMP 8150(5.4.0.1) + Virtual Firepower Management Center Data(5.4.0-763)

When I apply to device,and complete. my syslog server success received log.

But short time,mybe 1min,10min,30min...my syslog server not received log.

untill I apply to device and complete again......

Please HELP Me....

Thanks a lot

 

 

3 Replies 3

Hoyeh Tsai
Level 1
Level 1

If the syslog server is running with linux , you could use tcpdump command to make sure , is sourcefire not sending syslog , or the server syslog deamon not work?

if it's running with windows, you could use wireshark for  figure out. 

In fact,I have two syslog.

one syslog server run HP arcsight.

another run 3CDaemon on windows is for test.

Two syslog server situation are same.....

Could you see the log from connection and intrusion analysis? 

if it work , accroding to your pic, i think your are config fine. 

just make sure you've deploy the policy , and no firewall between sensor and syslog server,

or open nessery port.

if you do so , and still no log, i think you should open a case for troubleshooting.

Review Cisco Networking products for a $25 gift card