03-30-2022 01:48 AM
Sorry for the perhaps obvious question but I got slightly lost. What is the difference between the syslog configuration set under FMC-Devices-Platform Settings and the one that is done under FMC-Policies-Logging?
My goal is to get the Policies log like on the old ASA firewalls. Is a stupid question but I don't understand the scope of a multiple settings.
FMC v. 7.1.0.1 FTD v. 7.0.1.84
Solved! Go to Solution.
03-30-2022 02:38 AM
Logging option under policies is meant to generate connections events. These events in turn are visible when using "search" events on FMC for historical data/actions taken by FTD etc.
Syslog in the platform settings on the other hand is meant to send device, system or network delated information to a centralised server.
Here's a guide to setting up syslog on FTD via FMC - https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200479-Configure-Logging-on-FTD-via-FMC.html
03-30-2022 02:38 AM
Logging option under policies is meant to generate connections events. These events in turn are visible when using "search" events on FMC for historical data/actions taken by FTD etc.
Syslog in the platform settings on the other hand is meant to send device, system or network delated information to a centralised server.
Here's a guide to setting up syslog on FTD via FMC - https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200479-Configure-Logging-on-FTD-via-FMC.html
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide