Sourcefire 's log didn't send to syslog server

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-01-2016 08:15 AM - edited 03-10-2019 06:40 AM
Dears
I have Cisco AMP 8150(5.4.0.1) + Virtual Firepower Management Center Data(5.4.0-763)
When I apply to device,and complete. my syslog server success received log.
But short time,mybe 1min,10min,30min...my syslog server not received log.
untill I apply to device and complete again......
Please HELP Me....
Thanks a lot
- Labels:
-
IPS and IDS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-04-2016 07:56 PM
If the syslog server is running with linux , you could use tcpdump command to make sure , is sourcefire not sending syslog , or the server syslog deamon not work?
if it's running with windows, you could use wireshark for figure out.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-04-2016 08:32 PM
In fact,I have two syslog.
one syslog server run HP arcsight.
another run 3CDaemon on windows is for test.
Two syslog server situation are same.....
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
09-05-2016 07:59 PM
Could you see the log from connection and intrusion analysis?
if it work , accroding to your pic, i think your are config fine.
just make sure you've deploy the policy , and no firewall between sensor and syslog server,
or open nessery port.
if you do so , and still no log, i think you should open a case for troubleshooting.
