Configuring a Cisco Firewall Management Center (FMC) to Send Syslogs (2024)

If you want to collect usage from Cisco Firewall Threat Defense (FTD) devices managed by an FMC, you can configure a policy in the FMC to send syslogs to SecureTrack. This configuration will apply to all the policy's rules that send syslogs to SecureTrack.

Configuring the FMC comprises the following stages:

  1. Enable Syslog in FMC (Accountability)
  2. Enable a Syslog Device ID on the FTDs (Data Usage)
  3. Create a new Syslog alert
  4. Edit an FMC policy to send syslogs using the new alert

Enable Syslog in FMC (Accountability)

  1. In the FMC, navigate to the System > Configuration tab.
  2. Select Audit Log.

    Configuring a Cisco Firewall Management Center (FMC) to Send Syslogs (1)

  3. Configure the following parameters:

    • Set Send Audit Log to Syslog to Enabled.

    • In the Host field, enter the IP address of the syslog VIP.

    • Set Facility to LOCAL7.

    • Set Severity to NOTICE.

    • In the Tag field, enter the Log Tag defined in the Syslog Authentication window (Stage 3 of 5) when the device was configured.
      This tag will be used in SecureTrack under “Syslog Authentication” as the Tag ID. The tag must be unique per FMC device.

  4. Click Save.

Enable a Syslog Device ID on the FTDs (Data Usage)

After the FMC device is configured, in SecureTrack, you can configure the device to collect usage data.

  1. In the FMC, navigate to the Devices > Platform Settings tab.

  2. Configuring a Cisco Firewall Management Center (FMC) to Send Syslogs (2)

  3. To create a new policy:(If you are configuring an existing policy, skip to step 3)

    1. Click New Policy > Threat Defense Settings.

    2. Configuring a Cisco Firewall Management Center (FMC) to Send Syslogs (3)

      The New Policy dialog box appears.

      Configuring a Cisco Firewall Management Center (FMC) to Send Syslogs (4)

    3. In the Name field, enter a name for the new policy.

    4. Select an FTD device to add to the policy, and click Add to Policy.

    5. Click Save.

  4. In the row of the policy you want to configure, click the Edit(Configuring a Cisco Firewall Management Center (FMC) to Send Syslogs (5)) button.

  5. In the navigation pane, select Syslog.

  6. Configuring a Cisco Firewall Management Center (FMC) to Send Syslogs (6)

  7. Select the Syslog Settings tab.

  8. Configuring a Cisco Firewall Management Center (FMC) to Send Syslogs (7)

    1. Select the Enable Syslog Device ID option.
    2. From the drop-down menu, select User Defined ID.
    3. Enter an ID for the device syslogs. This ID will be used when configuring the device in SecureTrack.
  9. In the FMC for the required domain, navigate to the Policies > Access Control >RULE_IN_THE_POLICY >Logging tab.

    Configuring a Cisco Firewall Management Center (FMC) to Send Syslogs (8)

    1. Select one of these options:
      • Log at Beginning of Connection
      • Log at End of Connection
    2. Select Syslog Server.
  10. Click Save.

Create a new Syslog alert

  1. In the FMC, navigate to Policies > Actions > Alerts.

  2. Configuring a Cisco Firewall Management Center (FMC) to Send Syslogs (9)

  3. Click Create Alert > Create Syslog Alert.

  4. Configuring a Cisco Firewall Management Center (FMC) to Send Syslogs (10)

    The Edit Syslog Configuration dialog box appears.

    Configuring a Cisco Firewall Management Center (FMC) to Send Syslogs (11)

    1. In the Name field, enter a name for the new alert.

    2. In the Host field, enter the IP address of the syslog VIP.

    3. In the Facility field, select Syslog.

    4. Click Save.

  5. In the Enable column, enable the alert.

  6. Configuring a Cisco Firewall Management Center (FMC) to Send Syslogs (12)

Edit an FMC policy to send syslogs using the new alert

  1. In the FMC, navigate to Policies.

  2. Configuring a Cisco Firewall Management Center (FMC) to Send Syslogs (13)

  3. In the row of the policy which you want to use to send syslog alerts to SecureTrack, click the Edit (Configuring a Cisco Firewall Management Center (FMC) to Send Syslogs (14)) button.

  4. Go to the Logging tab.

  5. Configuring a Cisco Firewall Management Center (FMC) to Send Syslogs (15)

  6. Select Send using specific syslog alert.

  7. In the Syslog alert field, select the new syslog alert you created.

  8. Click Save.

Configuring a Cisco Firewall Management Center (FMC) to Send Syslogs (2024)
Top Articles
Coin-Operated Amusem*nt Machines Taxes and Fees
How to buy Bitcoin - All you need before starting | Ledger
Wordscapes Level 6030
Pinellas County Jail Mugshots 2023
Summit County Juvenile Court
Amtrust Bank Cd Rates
Skip The Games Norfolk Virginia
Sunday World Northern Ireland
Nier Automata Chapter Select Unlock
Valentina Gonzalez Leak
Michaels W2 Online
Fool’s Paradise movie review (2023) | Roger Ebert
Craftology East Peoria Il
Craiglist Tulsa Ok
Find Such That The Following Matrix Is Singular.
Equibase | International Results
Virginia New Year's Millionaire Raffle 2022
Nine Perfect Strangers (Miniserie, 2021)
Cta Bus Tracker 77
Conscious Cloud Dispensary Photos
Best Sports Bars In Schaumburg Il
Cain Toyota Vehicles
Toothio Login
How to Make Ghee - How We Flourish
Skycurve Replacement Mat
Drying Cloths At A Hammam Crossword Clue
Weathervane Broken Monorail
11526 Lake Ave Cleveland Oh 44102
FAQ's - KidCheck
Lindy Kendra Scott Obituary
Ncal Kaiser Online Pay
Sinfuldeed Leaked
Mkvcinemas Movies Free Download
Netherforged Lavaproof Boots
Mississippi State baseball vs Virginia score, highlights: Bulldogs crumble in the ninth, season ends in NCAA regional
Tamilyogi Ponniyin Selvan
Arcane Odyssey Stat Reset Potion
World History Kazwire
Philadelphia Inquirer Obituaries This Week
Devotion Showtimes Near The Grand 16 - Pier Park
Htb Forums
Lovein Funeral Obits
Questions answered? Ducks say so in rivalry rout
Electric Toothbrush Feature Crossword
Energy Management and Control System Expert (f/m/d) for Battery Storage Systems | StudySmarter - Talents
Cocorahs South Dakota
Craigslist Central Il
6576771660
Dicks Mear Me
Gelato 47 Allbud
Jesus Calling Oct 6
Latest Posts
Article information

Author: Errol Quitzon

Last Updated:

Views: 5660

Rating: 4.9 / 5 (59 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Errol Quitzon

Birthday: 1993-04-02

Address: 70604 Haley Lane, Port Weldonside, TN 99233-0942

Phone: +9665282866296

Job: Product Retail Agent

Hobby: Computer programming, Horseback riding, Hooping, Dance, Ice skating, Backpacking, Rafting

Introduction: My name is Errol Quitzon, I am a fair, cute, fancy, clean, attractive, sparkling, kind person who loves writing and wants to share my knowledge and understanding with you.