Ensure email logging is configured for critical to emergency

Information

Enables logs to be sent to an email recipient for critical to emergency logs' severity s

Rationale:

In some cases, the notifications of the Syslog server or the NMS system can be delayed by the time taken to process the logs and build the reports. Some system's events require an immediate intervention of the administrator and it in this case, the logs generated should be directly sent to the administrator email address.

Solution

Firepower Management Center:

Devices > Platform settings > Syslog > Logging setup

See Also

https://www.cisco.com/c/en/us/td/docs/security/firepower/640/hardening/ftd/FTD_Hardening_Guide_v64.html

Item Details

Category: AUDIT AND ACCOUNTABILITY

References: 800-53|AU-5(2)

Plugin: Cisco_Firepower

Control ID: a03d94ecb812ac59a7c2b4a06d4672699637a1f7977b940f5abc255dc0ef5449