Ensure 'logging buffered severity ' is greater than or equal to '3'

Information

Determines which syslog messages should be temporary stored in the local buffer so they can be checked by the administrator

Rationale:

The internal log buffer serves as a temporary storage location, thus allowing the administrator performing a health check on the system to locally have the last logs generated. Given that the size of the buffer is limited, it is better to have a specific set of syslog messages to be kept therein.

Solution

Firepower Management Center:

Devices > Platform settings > Syslog > Logging setup

See Also

https://www.cisco.com/c/en/us/td/docs/security/firepower/623/configuration/guide/fpmc-config-guide-v623.html

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-12

Plugin: Cisco

Control ID: e8ebb6c14ca977c141d80b07483db10d8eb9afbca87efbcbec7301fa1e3634ac