cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
701
Views
10
Helpful
4
Replies

FTD's Syslog

Hello all,

Would anyone know, if the Syslog message for 430001 to 430005 can be tuned in the FTD/FMC ?

I want to stop sending logging for some of the Connection Event Fields.

Thanks

4 Replies 4

balaji.bandi
Hall of Fame
Hall of Fame

Can you confirm tuned means you do not like to send or you like to send ?

You can only send certain message to syslog Look below :

https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200479-Configure-Logging-on-FTD-via-FMC.html

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hello,

Correct, I want to keep IDs 430001 to 430005 but tune out some the noise, so it's not sending everything via those log's

On your link - I have seen and read this too, that's what I realised. 

Thanks anyway.  

Sure now you know how to do, goog stuff..!

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

dp@sig4
Level 1
Level 1

What are logging to? Syslog does indeed create a lot of noise. If you are using Splunk, it is not recommended to use syslog. Use eStreamer.